- The Java extractor no longer supports the
SEMMLE_DISTlegacy environment variable.
- The predicate
isAndroidfrom the modulesemmle.code.java.security.AndroidCertificatePinningQueryhas been deprecated. Usesemmle.code.java.frameworks.android.Android::inAndroidApplication(File)instead.
- Kotlin support is now out of beta, and generally available
- Kotlin versions up to 2.0.2x are now supported.
- Added a path-injection sink for
hudson.FilePath.exists(). - Added summary models for
org.apache.commons.io.IOUtils.toByteArray. - Java build-mode
noneanalyses now only report a warning on the CodeQL status page when there are significant analysis problems-- defined as 5% of expressions lacking a type, or 5% of call targets being unknown. Other messages reported on the status page are downgraded from warnings to notes and so are less prominent, but are still available for review.