觉
AI觉醒星球
Awakening is here
Knowledge File / AI技能杠杆
2026-07-11 5 浏览 免费阅读

CodeQL 2.26.0 新增 Kotlin 2.4.0 支持与 AI 提示注入检测

GitHub 发布 CodeQL 2.26.0,添加对 Kotlin 2.4.0 的支持,引入 JavaScript/TypeScript 系统提示注入查询,并提升多语言分析准确性。

SOURCE / AI技能杠杆 MIN / 9 ACCESS / 免费阅读 POST / 2026-07-11 04:40:56

原贴

查看原文
作者:Allison 来源站点:github.blog 原贴时间:

原文

CodeQL is the static analysis engine behind GitHub code scanning , which finds and remediates security issues in your code. We’ve recently released CodeQL 2.26.0 , which adds support for Kotlin 2.4.0, introduces a JavaScript and TypeScript query for system prompt injection, and improves analysis accuracy across multiple languages. Kotlin : CodeQL now supports Kotlin versions up to 2.4.0. C# : We’ve added Razor Page handler method parameters, such as parameters for OnGet , OnPost , and OnPostAsync , as remote flow sources. Security queries such as cs/sql-injection can now detect vulnerabilities involving these parameters in PageModel subclasses. Go : We’ve added models for the log/slog package introduced in Go 1.21. The go/log-injection and go/clear-text-logging queries can now detect issues in code that uses slog package functions and slog.Logger methods. JavaScript/TypeScript : We’ve added prompt injection sinks for additional OpenAI, Anthropic, and Google GenAI SDK APIs, including Sora prompts, OpenAI Realtime session instructions, Anthropic legacy completion prompts, and Google GenAI cached content and system instructions. We’ve added the js/system-prompt-injection query to detect when untrusted, user-provided values flow into an AI model’s system prompt, allowing an attacker to manipulate the model’s behavior. We’ve added the experimental javascript/ssrf-ipv6-transition-incomplete-guard query to detect server-side request forgery (SSRF) guards that reject private IPv4 ranges but can be bypassed with IPv6 transition address formats. The go/unhandled-writable-file-close query now produces fewer false positives. It no longer flags a deferred call to Close when every execution path first handles a call to Sync on the same file handle. The py/modification-of-locals query no longer flags modifications to a locals() dictionary after it has passed out of the scope where it was created, reducing false positives. We’ve improved CryptoKit modeling for the swift/weak-sensitive-data-hashing and swift/weak-password-hashing queries. These queries may now detect additional results. We’ve updated the actions/pr-on-self-hosted-runner query to recognize the latest standard runner labels, reducing false positives. We’ve corrected the name, description, and alert message for actions/untrusted-checkout/medium to clarify that it applies to a nonprivileged context.

中文翻译

CodeQL 是 GitHub 代码扫描背后的静态分析引擎,用于查找和修复代码中的安全问题。我们最近发布了 CodeQL 2.26.0,该版本新增了对 Kotlin 2.4.0 的支持,引入了一个用于系统提示注入的 JavaScript 和 TypeScript 查询,并提升了多种语言的分析准确性。

Kotlin:CodeQL 现在支持高达 2.4.0 的 Kotlin 版本。

C#:我们添加了 Razor 页面处理程序方法参数,例如 OnGet、OnPost 和 OnPostAsync 的参数,作为远程流来源。诸如 cs/sql-injection 之类的安全查询现在可以检测 PageModel 子类中涉及这些参数的漏洞。

Go:我们为 Go 1.21 中引入的 log/slog 包添加了模型。go/log-injection 和 go/clear-text-logging 查询现在可以检测使用 slog 包函数和 slog.Logger 方法的代码中的问题。

JavaScript/TypeScript:我们为额外的 OpenAI、Anthropic 和 Google GenAI SDK API 添加了提示注入接收器,包括 Sora 提示、OpenAI Realtime 会话指令、Anthropic 遗留完成提示以及 Google GenAI 缓存内容和系统指令。我们添加了 js/system-prompt-injection 查询,用于检测不受信任的用户提供的值何时流入 AI 模型的系统提示,从而允许攻击者操纵模型的行为。我们添加了实验性查询 javascript/ssrf-ipv6-transition-incomplete-guard,用于检测拒绝私有 IPv4 范围但可通过 IPv6 过渡地址格式绕过的服务器端请求伪造(SSRF)防护。

go/unhandled-writable-file-close 查询现在产生更少的误报。当每个执行路径首先处理对同一文件句柄的 Sync 调用时,它不再标记对 Close 的延迟调用。

py/modification-of-locals 查询不再标记在 locals() 字典传递出其创建范围后的修改,从而减少误报。

我们改进了 swift/weak-sensitive-data-hashing 和 swift/weak-password-hashing 查询的 CryptoKit 建模。这些查询现在可能检测到更多结果。

我们更新了 actions/pr-on-self-hosted-runner 查询以识别最新的标准运行器标签,从而减少误报。

我们修正了 actions/untrusted-checkout/medium 的名称、描述和警报消息,以明确其适用于非特权上下文。

核心信息

GitHub 发布 CodeQL 2.26.0,添加对 Kotlin 2.4.0 的支持,引入 JavaScript/TypeScript 系统提示注入查询,并提升多语言分析准确性。

  • GitHub 发布 CodeQL 2.26.0,添加对 Kotlin 2.4.0 的支持,引入 JavaScript/TypeScript 系统提示注入查询,并提升多语言分析准确性。
  • 原贴提到:CodeQL is the static analysis engine behind GitHub code scanning , which
  • 来源:github.blog

详细解读

这是什么信号? CodeQL 2.26.0 的发布标志着静态分析工具正快速跟上 AI 应用安全需求。新增的 Kotlin 支持反映移动端和跨平台开发(尤其是 Android)的持续增长,而系统提示注入检测则直接回应了 AI 模型对抗性攻击的兴起。

为什么重要? 随着企业将 AI 功能嵌入产品,系统提示(如聊天机器人的初始指令)成为关键攻击面。传统安全扫描未覆盖这类风险,而 CodeQL 的新查询能自动发现用户输入污染系统提示的漏洞,将 AI 安全纳入 CI/CD 流程。此外,对 Kotlin 2.4.0 的支持帮助开发者在不牺牲安全性的情况下使用最新语言特性。

对谁有价值? 主要面向使用 GitHub 的 DevSecOps 团队、AI 应用开发者、以及维护多语言代码库的组织。尤其对集成 OpenAI、Anthropic、Google GenAI SDK 的项目,可显著降低提示注入风险。Go 和 C# 开发者也能受益于更精准的注入检测和更少的误报。

可以怎么行动? 立即升级 CodeQL 到 2.26.0 版本并启用新的 system-prompt-injection 查询;对现有 AI 项目进行回溯扫描;在安全策略中增加“AI 配置变更需触发代码扫描”的规则;结合 SSRF 防护查询(javascript/ssrf-ipv6-transition-incomplete-guard)强化网络请求安全。

风险或限制: 新查询可能产生未预期的误报,需要人工验证;对国内开发者,GitHub Actions 网络延迟和合规性可能影响实践;实验性 SSRF 查询尚未稳定;对于使用未列在 SDK 中的自定义 AI API 的项目,检测能力有限。

信息差价值

这条内容的真正价值,不只是“有人发布了一个新功能”,而是它揭示了 github.blog 背后的产品方向、工作流变化或竞争信号。对 OPC 来说,这种信息可以转化成持续追踪的栏目选题。

如果把《CodeQL 2.26.0 新增 Kotlin 2.4.0 支持与 AI 提示注入检测》放到你的内容系统里,它最大的价值在于帮助读者更快看懂“为什么值得关注”,而不是只看到一条碎片化动态。

参考来源

AI SUMMARY

这篇文章回答了什么

CodeQL 2.26.0 新增 Kotlin 2.4.0 支持与 AI 提示注入检测主要讲什么?

GitHub 发布 CodeQL 2.26.0,添加对 Kotlin 2.4.0 的支持,引入 JavaScript/TypeScript 系统提示注入查询,并提升多语言分析准确性。

这篇文章最值得关注的要点是什么?

GitHub 发布 CodeQL 2.26.0,添加对 Kotlin 2.4.0 的支持,引入 JavaScript/TypeScript 系统提示注入查询,并提升多语言分析准确性。;原贴提到:CodeQL is the static analysis engine behind GitHub code scanning , which;来源:github.blog

这篇文章和哪些AI专题相关?

它适合放在Agent工作流、AI超级个体、AI工具专题里阅读。 关联原因:这篇内容命中「Agent、工作流」等主题信号。;这篇内容命中「技能」等主题信号。;这篇内容来自该专题长期覆盖的栏目。

阅读这篇文章建议先理解哪些关键词?

建议先理解AI工具、工具、自动化、模型、Cursor这些关键词,再结合正文判断工具、机会或风险是否值得进入自己的工作流。

上一篇 Ghost Font:一种人类能读懂但AI无法识别的反AI字体 下一篇 秘密扫描检测器类型名称更清晰
北竹游乐场 免费玩小游戏 免费玩