CodeQL 2.27.2 improves C++, Go, Rust, and JavaScript analysis
UpdateyesterdayUnverifiedAdded Oct 10, 2026
CodeQL 2.27.2 is now available, adding a C++ regular-expression parser and analysis improvements across several languages. CodeQL is the static analysis engine behind GitHub code scanning, which helps you find and remediate security issues in your code. The Default suite runs 498 security queries covering 170 CWEs.
Topics: SQL, Streaming, Security, Developer tools
More GitHub Advanced Security releases
Every GitHub Advanced Security releaseCode scanning AI Scan enablement status in security overview
Organization and enterprise administrators can now see AI Scan for pull requests enablement status in the security overview coverage view. The code scanning summary shows enabled and not enabled repository counts, while repository rows show each repository’s effective AI Scan enablement.
Secret scanning adds detectors for Lovable, Supabase, and more
Secret scanning now detects new secret types from Lovable Labs, Pydantic Services Inc., and Supabase. New secret scanning partner The following provider joined the secret scanning partnership program.
New fields for SecurityAdvisory GraphQL API
You can now read more of the GitHub Advisory Database directly from the GraphQL API without falling back to the REST API. The SecurityAdvisory object gained five new fields: cveId : The advisory’s CVE identifier. sourceCodeLocation : A link to the affected source code relevant to the advisory. githubReviewedAt : When GitHub reviewed the advisory.
Confidential comments on repository security advisories
You can now post confidential comments on repository security advisories. Confidential comments are visible only to people with write access to the repository, so you can discuss a report with your team without the reporter or other invited collaborators seeing it.
Repository security advisory comments API in public preview
You can now read, add, and edit comments on repository security advisories using the REST API, including advisories created from private vulnerability reports. Until now, the discussion on an advisory was only reachable in the web UI, even though it often holds the most useful triage context on a vulnerability report.
Unvalidated npm trusted publishing configurations now expire
Unvalidated npm trusted publishing configurations now expire 48 hours after creation and can no longer authorize publishing. This limits the risk of trusting a repository or project name that changes ownership. Your configuration becomes validated and exempt from expiry after its first successful publish.
npm staged publishing now supports creating new packages
You can now create a new npm package with npm stage publish , using a local session or a granular access token, including a stage-only token. This lets you create packages from your automated workflows without a manual first publish. This works for public scoped and unscoped packages, and private scoped packages.
Rate limits for private vulnerability reports
Open source maintainers are receiving more low-quality and automated vulnerability reports, which can bury the reports that matter. Rate limits cap how many new reports a single account can submit in a day, both to your repository and across GitHub. This helps protect you from bulk and automated submissions, while legitimate researchers can still reach you.
Also shipped on Oct 9, 2026
GitHub in October 2026Google Workspace connector is available in Beta
The managed Google Workspace connector is now available in Beta in Databricks Lakeflow Connect. Use the connector to ingest audit activity from Google Workspace applications and services into Databricks. The connector uses OAuth user authorization and supports incremental ingestion.
Agentic Marketplace Discovery (Public preview)
Agentic Marketplace Discovery is now available in public preview. On the public Snowflake Marketplace Discover page in Snowsight, you can switch between Agentic discovery and Marketplace search . Describe what you need to CoCo to find and compare matching listings, or search for providers and listings directly.
All AI Gateway models with prepaid credits, backend features with your coding agent, and new ways to send feedback release - Oct 09, 2026
All AI Gateway models now available with prepaid credits. You don't need to request access to frontier models in the Neon AI Gateway anymore. If you're on a pai...
Use request tags in Unity Gateway service policies (Beta)
Custom service policies in Unity Gateway can now check caller-supplied request tags, such as requiring a tag before a model request or MCP tool call proceeds. See Request tags .
Use OpenJev as the evaluator for LLM-as-a-judge service policies (Beta)
You can now select OpenJev (Qwen3.5 4B) as the evaluator model service of a custom LLM-as-a-judge service policy. OpenJev classifies content without generating output tokens, so it typically responds faster than a chat evaluator. See Use OpenJev as the evaluator .
Code execution in Genie One (Public Preview)
Genie One can now run code in a secure, isolated sandbox to take on work that goes beyond SQL, such as more advanced analyses. Code runs on your behalf using your existing permissions, so Unity Catalog governance and data access controls continue to apply. See Code execution in Genie One .