GitHub has released CodeQL 2.27.0 with a native Linux ARM64 distribution. It also adds a Rust command-line injection query and improves modeling across Java, Kotlin, C# and C/C++ frameworks.

Quick answer

ChangeImpact
Linux ARM64 CLINative analysis on Arm runners and servers.
RustNew command-line injection detection.
MicronautModels for controllers, WebSockets, data and security.
libpqMore PostgreSQL functions treated as SQL sinks.

ARM64 joins the AppSec toolchain

Teams using Arm runners no longer need emulation or a separate x86 machine for the CLI. They should download the linux-arm64 assets, as GitHub plans to retire the generic all-platform archive later.

The support matters for Arm cloud infrastructure chosen for cost or energy efficiency. It narrows the gap between the build architecture and the security analysis environment.

Coverage closer to real applications

For Java and Kotlin, CodeQL now models Micronaut HTTP controllers, WebSockets, configuration injection, data access and security annotations. C# controller discovery better matches ASP.NET Core MVC runtime behavior, while data flow now covers OData action parameters.

In C and C++, PQexec, PQprepare and related libpq functions become recognized SQL injection sinks. Those models close blind spots without requiring application changes.

Expect some alert movement

An upgrade can produce additional findings. CodeQL also evaluates author-association checks in GitHub Actions more strictly: a condition is protective only when the event payload actually supplies the field. Previously quiet workflows may reveal ineffective checks.

Treat that as improved visibility, then triage findings in application context instead of disabling the query globally.

Preparing the upgrade

Run the bundle against a representative repository, compare time, memory and results, and pin the version on self-hosted runners. Review private registry access too: default code scanning can now use organization configurations when fetching custom queries and packs.

Native ARM64 support is not CodeQL's flashiest feature, but it lets security controls follow infrastructure that has already diversified. That is exactly what prevents static analysis from remaining tied to an older x86 fleet.