Skip to content

chore: bump pinned CodeQL CLI to v2.27.1 and release v0.8.1 - #232

Merged
felickz merged 2 commits into
mainfrom
chore/update-codeql-cli-2.27.1
Sep 28, 2026
Merged

felickz merged 2 commits into
mainfrom
chore/update-codeql-cli-2.27.1

Conversation

@security-lab-bot

Copy link
Copy Markdown
Contributor

Automated CLI version bump, requested via the "Update CodeQL CLI Version"
workflow (workflow_dispatch, codeql_version: 2.27.1, release_bump: patch).

This PR:

  • Updates .codeqlversion to 2.27.1.

  • Pins every codeql/<lang>-all / codeql/<lang>-queries dependencies:
    entry across query/library qlpack.yml files (not */ext or
    */ext-library-sources, whose extensionTargets is intentionally left
    unconstrained and must never be auto-rewritten) to the exact version
    shipped in the official CodeQL Bundle for this CLI release (see
    .github/scripts/pin-codeql-library-versions.sh) - this keeps
    codeql pack upgrade from jumping those libraries to registry-latest instead
    of the version this CLI actually ships/tests against.

  • Runs codeql pack upgrade <dir> for every query/library pack directory (again
    excluding */ext and */ext-library-sources) to refresh its
    codeql-pack.lock.yml against the new CLI and pinned library versions.

  • Also bumps the repo release version (patch, via the same
    patch-release-me step update-release.yml uses) to 0.8.1,
    propagating it to every pack's own version: field, configs/*.yml
    references, and cross-pack -libs pins.

Merging this PR triggers the real batch publish - publish.yml's
auto-trigger fires on any push to main that changes .release.yml, which this
PR does. No separate "CodeQL Update Release" run is needed. That run's summary
job will create the matching GitHub Release as a full release
(release_prerelease: false).

Remaining steps (see CONTRIBUTING.md's "Updating the pinned CodeQL CLI/library
version" section):

  • Check CI on this PR - fix any compilation/test errors caused by upstream
    API changes. This is usually the hardest part; consider delegating it to a
    Copilot coding agent session pointed at this PR/branch.
  • Review and merge - this alone will trigger the real batch publish.

@felickz

felickz commented Sep 25, 2026

Copy link
Copy Markdown
Contributor

@copilot -

is this an expected change for Go in 2.27.1? Fix if it is expected and explain why, otherwise escalate back here.

  "expected": "/home/runner/work/CodeQL-Community-Packs/CodeQL-Community-Packs/go/test/security/CWE-078/cmdi.expected",
  "actual": "/home/runner/work/CodeQL-Community-Packs/CodeQL-Community-Packs/go/test/security/CWE-078/cmdi.actual",
  "diff": [
    "--- expected",
    "+++ actual",
    "@@ -1,6 +1,6 @@",
    " edges",
    "-| main.go:20:14:20:20 | selection of URL | main.go:20:14:20:28 | call to Query | provenance | Src:MaD:1968 MaD:2029 |",
    "-| main.go:20:14:20:28 | call to Query | main.go:27:22:27:28 | cmdName | provenance | Sink:MaD:2039 |",
    "+| main.go:20:14:20:20 | selection of URL | main.go:20:14:20:28 | call to Query | provenance | Src:MaD:2002 MaD:2064 |",
    "+| main.go:20:14:20:28 | call to Query | main.go:27:22:27:28 | cmdName | provenance | Sink:MaD:2075 |",
    " nodes",
    " | main.go:20:14:20:20 | selection of URL | semmle.label | selection of URL |",
    " | main.go:20:14:20:28 | call to Query | semmle.label | call to Query |"
    
    

https://codeql.github.com/docs/codeql-overview/codeql-changelog/codeql-cli-2.27.1/

Golang

Added or improved data flow models for the following Go standard-library APIs introduced or updated in Go 1.27:

bytes.CutLast, database/sql.ConvertAssign, database/sql/driver.RowsColumnScanner.ScanColumn, net/url.URL.Clone, net/url.Values.Clone and strings.CutLast.

The new encoding/json/jsontext package.

Added more data flow models for the strings package: strings.Clone, Cut, CutPrefix, CutSuffix, Fields, FieldsFunc, and Join; strings.Builder.String, Builder.WriteByte, and Builder.WriteRune; strings.Reader.ReadByte and Reader.ReadRune; and strings.Replacer.Replace and Replacer.WriteString.

Co-authored-by: felickz <1760475+felickz@users.noreply.github.com>

Copilot AI commented Sep 25, 2026

Copy link
Copy Markdown
Contributor

@copilot -

is this an expected change for Go in 2.27.1? Fix if it is expected and explain why, otherwise escalate back here.
...

Expected. Ran the test locally: source/sink locations (main.go:20 selection of URL -> Query, main.go:27 cmdName) are unchanged, only the internal MaD: model row IDs shifted (1968/2029/2039 -> 2002/2064/2075). Per the 2.27.1 changelog, new Go stdlib data flow models were added for net/url and strings, which shifts the row numbers of existing models defined later in the same MaD tables. No semantic change to the flow found by the query. Updated cmdi.expected in 6c7c8f7 (baseline regenerated, test now passes).

@felickz

felickz commented Sep 28, 2026

Copy link
Copy Markdown
Contributor

Closes: #233

@felickz
felickz merged commit d5eeab9 into main Sep 28, 2026
31 checks passed
@felickz
felickz deleted the chore/update-codeql-cli-2.27.1 branch September 28, 2026 14:26
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants