CodeQL 2.26.3 Brings Enhanced Security Queries and JavaScript Analysis
GitHub has released CodeQL 2.26.3, an update to its static analysis engine that powers code scanning on GitHub.
The latest version of CodeQL introduces improved security queries for GitHub Actions workflows and advanced JavaScript/TypeScript modeling.
The update includes source and flow models for Vue's Composition API helpers, which enhance the tool's ability to detect vulnerabilities in modern JavaScript frameworks.
CodeQL 2.26.3 also broadens language support beyond JavaScript, including C/C++ with flow source models for Windows registry functions.