Data and AI releases

This month801Companies169

801 this month · 169 companies

CodeQL 2.27.2 improves C++, Go, Rust, and JavaScript analysis

UpdateyesterdayUnverifiedAdded Oct 10, 2026

CodeQL 2.27.2 is now available, adding a C++ regular-expression parser and analysis improvements across several languages. CodeQL is the static analysis engine behind GitHub code scanning, which helps you find and remediate security issues in your code. The Default suite runs 498 security queries covering 170 CWEs.

Topics: SQL, Streaming, Security, Developer tools

GitHub's release notes

More GitHub Advanced Security releases

Every GitHub Advanced Security release
Updateunverified

Code scanning AI Scan enablement status in security overview

Organization and enterprise administrators can now see AI Scan for pull requests enablement status in the security overview coverage view. The code scanning summary shows enabled and not enabled repository counts, while repository rows show each repository’s effective AI Scan enablement.

Updateunverified

New fields for SecurityAdvisory GraphQL API

You can now read more of the GitHub Advisory Database directly from the GraphQL API without falling back to the REST API. The SecurityAdvisory object gained five new fields: cveId : The advisory’s CVE identifier. sourceCodeLocation : A link to the affected source code relevant to the advisory. githubReviewedAt : When GitHub reviewed the advisory.

Updateunverified

Confidential comments on repository security advisories

You can now post confidential comments on repository security advisories. Confidential comments are visible only to people with write access to the repository, so you can discuss a report with your team without the reporter or other invited collaborators seeing it.

Previewunverified

Repository security advisory comments API in public preview

You can now read, add, and edit comments on repository security advisories using the REST API, including advisories created from private vulnerability reports. Until now, the discussion on an advisory was only reachable in the web UI, even though it often holds the most useful triage context on a vulnerability report.

Updateunverified

Unvalidated npm trusted publishing configurations now expire

Unvalidated npm trusted publishing configurations now expire 48 hours after creation and can no longer authorize publishing. This limits the risk of trusting a repository or project name that changes ownership. Your configuration becomes validated and exempt from expiry after its first successful publish.

Updateunverified

npm staged publishing now supports creating new packages

You can now create a new npm package with npm stage publish , using a local session or a granular access token, including a stage-only token. This lets you create packages from your automated workflows without a manual first publish. This works for public scoped and unscoped packages, and private scoped packages.

Updateunverified

Rate limits for private vulnerability reports

Open source maintainers are receiving more low-quality and automated vulnerability reports, which can bury the reports that matter. Rate limits cap how many new reports a single account can submit in a day, both to your repository and across GitHub. This helps protect you from bulk and automated submissions, while legitimate researchers can still reach you.

Also shipped on Oct 9, 2026

GitHub in October 2026
Betaunverified

Google Workspace connector is available in Beta

The managed Google Workspace connector is now available in Beta in Databricks Lakeflow Connect. Use the connector to ingest audit activity from Google Workspace applications and services into Databricks. The connector uses OAuth user authorization and supports incremental ingestion.