Skip to content

v2.27.2

Latest

Choose a tag to compare

@codeql-ci-app codeql-ci-app released this 07 Oct 11:21
Immutable release. Only release title and notes can be modified.
be2e13d

Improvements

  • Error and warning messages printed to standard error are now labelled with an ERROR: or WARNING: prefix. Previously only diagnostics carried such a label, so the severity of other messages was not apparent in plain-text output. Structured output is unaffected: log files, SARIF, and stored diagnostics continue to record severity without the prefix.
  • The codeql query compile command now accepts the --dil-constants flag. When specified along with --dump-dil, the emitted DIL will include the values of predicates that have been optimized into constant tuple sets. Otherwise, these constants are omitted. This flag also enables pretty-printing of constant tuple sets for higher-level commands that involve query compilation.

Bug Fixes

  • Fixed a crash in codeql resolve queries (and other commands that resolve query suites) that reported a fatal internal error when a suite entry's qlpack: or from: value was not a valid QL pack name. Such input now produces a clear, user-facing error instead.
  • Fixed a bug in the handling of YAML data extensions that would quietly accept integers outside of the signed 64-bit range, truncating them to smaller values. (Values outside of the signed 32-bit range, but inside the signed 64-bit range, were correctly rejected.) Now, all integers outside of the signed 32-bit range are rejected and will cause evaluation to fail.

Miscellaneous

  • CLI commands that load data extensions, such as codeql database run-queries, previously emitted a warning for each file-pattern from the dataExtensions list of a qlpack.yml manifest that failed to match any extension files. This check has been relaxed, and will now only emit a warning if none of the patterns match any files (i.e. when there is at least one pattern but no extensions are found).

For more information about the changes included in this release, see the CodeQL CLI changelog.

You can download either the codeql-PLATFORM.zip for your platform, or the generic codeql.zip which covers Linux x64, Windows x64 and macOS (including Apple Silicon). Linux arm64 binaries are available as a per-platform codeql-linux-arm64.zip only. Please ignore the additional "source code" downloads below the .zip artifacts.

Warning

The generic codeql.zip (binaries for all x86-64 platforms) is deprecated and will be removed in a future release. Please download the codeql-PLATFORM.zip for your platform instead. Note that arm64 binaries are only available as a per-platform codeql-linux-arm64.zip.

This release is compatible with the CodeQL language packs from github/codeql@codeql-cli/v2.27.2.