NNapatdev/ NewsNapatdev ↗
Napatdev News/Security

Security · 04 Aug 2026

CodeQL 2.26.2 เพิ่มการรองรับ Swift 6.3.3 และ Kotlin 2.4.10 สำหรับ Code Scanning

GitHub ออก CodeQL 2.26.2 พร้อมรองรับ Swift 6.3.3 และ Kotlin 2.4.10 ช่วยให้ security scanning ตามทัน toolchain รุ่นใหม่ ทีมที่อัปเกรด compiler ควรตรวจ CodeQL workflow และ custom query เพื่อให้แน่ใจว่าการวิเคราะห์ยังทำงานครบถ้วน

By Napat Pamornsut1 min readSource verified
CodeQL วิเคราะห์ source code ภาษา Swift และ Kotlin ใน CI pipeline
Original illustration by Napatdev News · Source: GitHub Changelog

เกิดอะไรขึ้น

GitHub Changelog วันที่ 4 สิงหาคม 2026 ประกาศ CodeQL 2.26.2 โดยเพิ่มการรองรับ Swift 6.3.3 และ Kotlin 2.4.10 CodeQL เป็น static analysis engine ที่ GitHub code scanning ใช้สร้างฐานข้อมูลจาก source code และรัน query เพื่อค้นหาปัญหาด้าน security และ correctness

รายละเอียดสำคัญ

การรองรับ language version สำคัญเพราะ extractor ต้องเข้าใจ syntax และ metadata ของ compiler ที่ codebase ใช้จริง หากทีมอัปเกรดภาษาเร็วกว่าตัว scanner การ build อาจผ่านแต่ analysis coverage อาจไม่เป็นไปตามที่คาด การเพิ่ม support จึงลดช่องว่างดังกล่าว

ทำไมคนสร้างซอฟต์แวร์ควรสนใจ

Swift และ Kotlin ถูกใช้ใน mobile และ backend จำนวนมาก การรักษา static analysis ให้ทัน compiler ช่วยให้ security gate ใน CI ไม่กลายเป็นขั้นตอนที่ดูเหมือนทำงานแต่มี blind spot กับ syntax ใหม่ โดยเฉพาะองค์กรที่มี custom query packs

สิ่งที่ควรทำต่อ

อัปเดต CodeQL action และ engine ตาม release ที่รองรับ ทดสอบ scan บน branch ที่ใช้ compiler ใหม่ เปรียบเทียบ alert ก่อนและหลังอัปเดต และรัน regression test สำหรับ custom queries หากจำนวน finding เปลี่ยนมากควรตรวจ extractor log ก่อนสรุปว่า codebase ดีขึ้นหรือแย่ลง

Source note

This article is an original summary and analysis. Facts are based on the linked primary source; performance figures remain vendor-reported where noted.

#codeql#swift#kotlin#code-scanning

Keep reading

More from Security