CodeQL 2.27.2 Says autobuild and manual Modes Won't Support Compiled Languages on macOS 27 and Rewrites the Go Control-Flow Graph in a Breaking Change
GitHub's CodeQL 2.27.2 changelog says autobuild and manual build modes will not be supported for compiled languages on macOS 27, and lists a breaking Go CFG rewrite.
Overview
GitHub published CodeQL 2.27.2 in a changelog post dated October 9, 2026. Two items in it can force action from users: a statement that the autobuild and manual build modes will not be supported for compiled languages on macOS 27, and a breaking rewrite of the Go control-flow graph (CFG) library.
What We Know
macOS 27 and Xcode 27
According to the GitHub Changelog, “with the release of macOS 27 and Xcode 27, Apple stopped shipping multi-architecture x86-64/arm64 binaries,” which CodeQL requires to perform traced analysis. As a result, the post says, the autobuild and manual build modes will not be supported for compiled languages on macOS 27 with any Xcode version, and on macOS 26 when Xcode 27 is selected. GitHub advises using at most macOS 26 and Xcode 26 with those modes, and says it is working on improving support for build mode none on macOS to help mitigate the limitation. The post gives no timeline for that work.
Go control-flow graph rewrite
The same post lists a “Go library breaking change”: the Go CFG now uses the shared CFG library. It adds nodes for constructs such as assignments, parameters and results, range statements and deferred calls, and excludes nodes that are not reachable from the entry point. GitHub says this changes CFG nodes, edges, locations, textual representations and basic-block boundaries, so queries relying on the previous representation may need updating.
The API changes listed are:
BasicBlocks::Cfgis removed.ControlFlow::EntryNode,ControlFlow::ExitNodeandSwitchStmt.getExprare added.IfStmt.getCondis deprecated in favor ofIfStmt.getCondition.- The return types of
IfStmt.getThenandLoopStmt.getBodychange toStmt. - Several IR instruction classes are consolidated. The CodeQL changelog names
ReadArgumentInstruction,InitResultInstruction,IncDecInstruction,EvalIncDecRhsInstruction,EvalImplicitOneInstruction,SelectInstructionandSendInstructionamong those removed or consolidated.
The go/ql/lib CHANGELOG.md in the CodeQL repository carries the same text under a 8.0.0 heading, in a “Breaking Changes” section.
Other changes
The post also lists, among other items:
std::regexparsing: regular expressions that use the ECMAScript grammar are now parsed.- Go modeling: CodeQL now models the
github.com/coder/websocketimport path alongsidenhooyr.io/websocket. - JavaScript/TypeScript: the Workflow SDK’s
"use workflow"and"use step"directives are recognized. - GitHub Actions: entries prefixed with
!, such as!github, can remove owners from the trusted set used by theactions/unpinned-tagquery, which lets users report unpinned tags for first-party owners. - CLI: messages on standard error now carry
ERROR:andWARNING:prefixes, while structured output, including logs and SARIF, is unchanged.codeql query compileaccepts--dil-constantswith--dump-dil.
The CodeQL changelog also describes a fix to YAML data extensions: integers outside the signed 32-bit range are now rejected and cause evaluation to fail, where some had previously been accepted and truncated.
The GitHub Changelog says the Default suite runs 498 security queries covering 170 CWEs and the Extended suite adds 131 queries covering 32 more CWEs. It adds that GitHub automatically deploys every new CodeQL version to users of GitHub code scanning on github.com, and that a future GitHub Enterprise Server release will include the functionality; older GHES users can upgrade CodeQL manually.
What We Don’t Know
- The GitHub post does not say how many users run
autobuildormanualmodes on macOS, or when build modenoneimprovements will land. - The post dated October 9, 2026 and the CodeQL changelog page, which is titled “CodeQL 2.27.2 (2026-10-07)”, carry different dates. Neither source explains the difference.
- The macOS 27 statement appears in the GitHub post; the CodeQL changelog page, as read for this article, does not mention it, so that claim rests on one source.
- The sources do not say how many public queries or libraries depend on the previous Go CFG representation, or which GHES release will include 2.27.2.
- The repository changelog excerpt read does not state the release date of the
8.0.0entry or which CLI version includes it beyond the matching text.