CodeQL 2.16.2: New Android queries and improved precision
Summary
CodeQL 2.16.2 is now available to users of GitHub code scanning on github.com, and all new functionality will also be included in GHES 3.13. Users of GHES 3.12 or older…
CodeQL 2.16.2 is now available to users of GitHub code scanning on github.com, and all new functionality will also be included in GHES 3.13. Users of GHES 3.12 or older can upgrade their CodeQL version.
Important changes in this release include:
We added two new Java / Android queries (java/android/sensitive-text
and java/android/sensitive-notification
) to detect sensitive data exposure via text fields and notifications.
We have improved the precision of several C/C++ queries.
We now recognize collection expressions introduced in C# 12 (e.g. [1, y, 4, .. x]
).
For a full list of changes, please refer to the complete changelog for version 2.16.2