CodeQL 2.27.1 adds C and C++ query and Kotlin 2.4.20 support

CodeQL 2.27.1 introduces new security queries, data flow models for C and C++ and Go, Kotlin 2.4.20 support, and query accuracy improvements. The release updates extractors and adds analysis capabilities for multiple languages, improving detection accuracy while reducing false positives in existing scans across supported developer platforms.

CodeQL 2.27.1 was released, extending the static‑analysis engine with new security queries and data‑flow models for C/C++ and Go, and adding support for Kotlin 2.4.20. The update also upgrades the Rust extractor to rust‑analyzer version 0.0.347 and ships the latest extractor changes for JavaScript/TypeScript, C#, and other languages. GitHub automatically rolls the new version out to code‑scanning users on github.com, while GitHub Enterprise Server 3.24 will include it by default. The added taint‑flow models for Boost.Asio, BloombergLP, and Protocol Buffers improve detection of vulnerable data paths in C/C++ projects, and the expanded Go models cover a range of standard‑library APIs such as bytes.CutLast and net/url.Values.Clone. Kotlin support reduces false positives in queries that involve the K2 compiler, and the new C/C++ ambiguous‑assignment query helps catch logic errors that could be exploited. Together, these changes raise the accuracy of automated security reviews and lower the noise that developers must triage. It is not yet clear how the new data‑flow models will affect overall false‑positive rates across all repositories, and the impact of the Rust path‑resolution fix on existing analyses remains uncertain. The GitHub blog notes that private NuGet registries with the Replaces base option now replace default feeds, but the practical implications for large enterprise setups have not been quantified.