CodeQL 2.26.4 explained: 2026 GitHub Actions detections and Go 1.27
GitHub shipped CodeQL 2.26.4 on 3 September: Go 1.27, more precise Rust alert locations, and stricter Actions actor checks plus unpinned reusable-workflow detection.
On 3 September 2026 the GitHub Changelog shipped CodeQL 2.26.4. CodeQL is the static analysis engine behind GitHub code scanning.
The note adds Go 1.27, tighter Rust data-flow alert locations, and accuracy work on C#, Java/Kotlin, and GitHub Actions.
What the public note prints
| Item | What GitHub wrote | Limit |
|---|---|---|
| Go | CodeQL now supports Go 1.27 | No package-by-package list |
| Rust | Data-flow alerts use real source/sink nodes | Some alerts will move |
| Java/Kotlin | Spring R2DBC sinks; valueOf taint | Only DatabaseClient and the SPI |
| Actions | Actor fields, unpinned reusable workflows, EnvironmentCheck | May add ControlCheck alerts |
How to read this patch
- 1
This is an engine patch
The headline is GitHub Actions security detections. The body also lists Go, Rust, C#, Java/Kotlin, JS/TS, and Python. Do not treat it as a new product launch.
- 2
Rust alerts will relocate
Locations now follow the real source and sink. GitHub says some alerts appear new while old locations close. That is not a fresh vulnerability batch.
- 3
Actions checks get stricter
Actor fields from the event payload count as protection only when that event fills them. actions/unpinned-tag now flags mutable references to reusable workflows. EnvironmentCheck can come from models-as-data.
- 4
Cloud and GHES are not in lockstep
code scanning on github.com updates automatically. GHES waits for a later release, or a manual CodeQL upgrade.
What else the same page lists
Java taint and R2DBC
New SQL-injection sinks for Spring R2DBC DatabaseClient and the R2DBC SPI. Taint flows through String.valueOf(Object) when the argument is a CharSequence.
JS/TS and Python
Regex d flag and the React Native Worklets worklet directive. list.extend and list.insert now match list.append for taint.
C# false-positive cuts
RequireAntiforgeryToken is recognized when antiforgery middleware is on. nameof is not a constructor virtual call. Fewer FPs in build-mode: none for two queries.
Limits
The note does not give a false-positive rate or a forced-upgrade deadline. Next step is the full changelog. If you only needed a short meeting without another account wall, wbstorm is a browser room ID — see also privacy without an account and create or join a room.
# Source
# GitHub Changelog, 2026-09-03
# CodeQL 2.26.4 improves GitHub actions security detectionsDoes github.com upgrade automatically?
GitHub writes that every new CodeQL version is automatically deployed to code scanning users on github.com.
Is 2.26.4 on GHES today?
The note says it will be in a future GHES release. Older GHES can upgrade CodeQL manually.
Is this a product how-to?
No. This article only checks the 3 September Changelog. It is not a scanning setup guide.