CodeQL 2.26.4 explained: 2026 GitHub Actions detections and Go 1.27

GitHub shipped CodeQL 2.26.4 on 3 September: Go 1.27, more precise Rust alert locations, and stricter Actions actor checks plus unpinned reusable-workflow detection.

On 3 September 2026 the GitHub Changelog shipped CodeQL 2.26.4. CodeQL is the static analysis engine behind GitHub code scanning.

The note adds Go 1.27, tighter Rust data-flow alert locations, and accuracy work on C#, Java/Kotlin, and GitHub Actions.

ChangelogLanguage modelsActions queries

What the public note prints

2.26.4
CodeQL version
9/3
Changelog date
Go 1.27
New language support
ItemWhat GitHub wroteLimit
GoCodeQL now supports Go 1.27No package-by-package list
RustData-flow alerts use real source/sink nodesSome alerts will move
Java/KotlinSpring R2DBC sinks; valueOf taintOnly DatabaseClient and the SPI
ActionsActor fields, unpinned reusable workflows, EnvironmentCheckMay add ControlCheck alerts

How to read this patch

  1. 1

    This is an engine patch

    The headline is GitHub Actions security detections. The body also lists Go, Rust, C#, Java/Kotlin, JS/TS, and Python. Do not treat it as a new product launch.

  2. 2

    Rust alerts will relocate

    Locations now follow the real source and sink. GitHub says some alerts appear new while old locations close. That is not a fresh vulnerability batch.

  3. 3

    Actions checks get stricter

    Actor fields from the event payload count as protection only when that event fills them. actions/unpinned-tag now flags mutable references to reusable workflows. EnvironmentCheck can come from models-as-data.

  4. 4

    Cloud and GHES are not in lockstep

    code scanning on github.com updates automatically. GHES waits for a later release, or a manual CodeQL upgrade.

What else the same page lists

01

Java taint and R2DBC

New SQL-injection sinks for Spring R2DBC DatabaseClient and the R2DBC SPI. Taint flows through String.valueOf(Object) when the argument is a CharSequence.

02

JS/TS and Python

Regex d flag and the React Native Worklets worklet directive. list.extend and list.insert now match list.append for taint.

03

C# false-positive cuts

RequireAntiforgeryToken is recognized when antiforgery middleware is on. nameof is not a constructor virtual call. Fewer FPs in build-mode: none for two queries.

Limits

The note does not give a false-positive rate or a forced-upgrade deadline. Next step is the full changelog. If you only needed a short meeting without another account wall, wbstorm is a browser room ID — see also privacy without an account and create or join a room.

# Source
# GitHub Changelog, 2026-09-03
# CodeQL 2.26.4 improves GitHub actions security detections
Does github.com upgrade automatically?

GitHub writes that every new CodeQL version is automatically deployed to code scanning users on github.com.

Is 2.26.4 on GHES today?

The note says it will be in a future GHES release. Older GHES can upgrade CodeQL manually.

Is this a product how-to?

No. This article only checks the 3 September Changelog. It is not a scanning setup guide.

Create room