Content Quality: Well-structured News piece (Overview / What We Know / What We Don't Know), 657 words (News range 400-1200; same count with link URLs stripped). Title is exactly 150 characters, counted programmatically (len=150), at the cap and allowed (151 would be a violation); it is long but not a violation. Summary is 165 characters. Minor style note: the lead phrase 'can force action from users' is mildly interpretive but is supported by the blog's advice to use at most macOS 26/Xcode 26 and its warning that queries may need updating.
Source Verification: Read all three gunzipped snapshots; all exist, HTTP 200, and contain the full page body (not page chrome only). source-0.html.gz (github.blog changelog, October 9, 2026, titled 'CodeQL 2.27.2 improves C++, Go, Rust, and JavaScript analysis'): confirms verbatim 'With the release of macOS 27 and Xcode 27, Apple stopped shipping multi-architecture x86-64/arm64 binaries. These binaries are required by CodeQL to perform traced analysis.' and 'CodeQL's autobuild and manual build modes will not be supported for compiled languages on macOS 27 with any Xcode version, and on macOS 26 when Xcode 27 is selected. When using these build modes, please use at most macOS 26 and Xcode 26. We are also working on improving support for build mode none on macOS to help mitigate this limitation.' No date or timeline is given and the blog does not enumerate which languages are 'compiled'; the article does not enumerate them either. The article's other specifics match: 498 queries/170 CWEs, Extended +131/32 CWEs, the GHES/automatic deployment sentences, the std::regex ECMAScript parser, github.com/coder/websocket, Workflow SDK directives, actions/unpinned-tag '!' prefix, ERROR:/WARNING: prefixes, --dil-constants with --dump-dil. The 'Go library breaking change' section matches the article's API list. Title wording: 'Won't Support' is a faithful compression of 'will not be supported ... on macOS 27' (the title omits the macOS 26 + Xcode 27 case, acceptable; the body states it fully). source-1.html.gz (codeql.github.com CLI change log, titled 'CodeQL 2.27.2 (2026-10-07)'): zero mentions of macOS or Xcode, confirming the macOS 27 claim rests on the blog alone. It DOES list the Go CFG rewrite under CodeQL 2.27.2 > Language Libraries > Breaking Changes > Golang, so the title's attribution of the breaking change to 2.27.2 is supported by both the blog post and the docs change log, not only by the repository file. It names the removed or consolidated IR classes verbatim: ReadArgumentInstruction, InitResultInstruction, IncDecInstruction, EvalIncDecRhsInstruction, EvalImplicitOneInstruction, SelectInstruction, SendInstruction. It also states the YAML data-extension fix: 'all integers outside of the signed 32-bit range are rejected and will cause evaluation to fail' (previously integers outside the signed 64-bit range were quietly truncated; the article's 'some had previously been accepted and truncated' is a fair, slightly compressed paraphrase, matching the blog's 'silently truncating some values'). Date discrepancy confirmed: blog October 9 vs docs page 2026-10-07; the article flags it. source-2.html.gz (raw go/ql/lib/CHANGELOG.md): '## 8.0.0 / ### Breaking Changes' carries the same CFG text and API list including the same seven class names; no CLI version or date is attached to the 8.0.0 heading, as the article says. The article does not assert the repo changelog ties 8.0.0 to 2.27.2. suspicious_patterns is null for all three sources; no injection text found. No internal links in the body (only the three https source URLs, all in article.sources).
Factual Accuracy: All checked specifics trace to the cited sources and are attributed to GitHub / the CodeQL changelog. 'The post gives no timeline' for build mode none is correct. 'What We Don't Know' is accurate; its last bullet (repo changelog excerpt does not state the CLI version for 8.0.0) is true of that file, though the docs page does tie the change to 2.27.2. Minor imprecision only, no correction needed. Freshness: blog and docs are within days of 2026-10-11.
Overall Assessment: Accurate, well-attributed News article; every claim traces to the three snapshots, title claims are supported, and the one automated warning was resolved by allowlisting a vetted first-party host. Approve.