GitHub's CodeQL incremental analysis now runs up to 20% faster on pull requests across five major programming languages, with larger repos seeing biggest gains. (GitHub's CodeQL incremental analysis now runs up to 20% faster on pull requests across five major programming languages, with larger repos seeing biggest gains. (

GitHub CodeQL Gets Major Speed Boost for Pull Request Security Scans

2026/03/24 22:38
2 min read
For feedback or concerns regarding this content, please contact us at crypto.news@mexc.com

GitHub CodeQL Gets Major Speed Boost for Pull Request Security Scans

Luisa Crawford Mar 24, 2026 14:38

GitHub's CodeQL incremental analysis now runs up to 20% faster on pull requests across five major programming languages, with larger repos seeing biggest gains.

GitHub CodeQL Gets Major Speed Boost for Pull Request Security Scans

GitHub has rolled out significant performance improvements to CodeQL, its open-source static analysis engine, making security scans on pull requests substantially faster for developers working in C#, Java, JavaScript/TypeScript, Python, and Ruby.

The update, announced March 24, 2026, builds on incremental analysis capabilities GitHub introduced last year. Rather than scanning entire codebases with each pull request, CodeQL now generates a separate database for new or changed code and combines it with a cached database of the existing codebase.

GitHub tested the improvements across more than 100,000 repositories, grouping them by typical scan duration. The results? Larger, more complex repositories—those taking over seven minutes for non-incremental scans—saw the most dramatic improvements. Repositories in the three-to-seven minute range also benefited meaningfully, while smaller projects under three minutes showed modest gains.

The timing matters for development teams. Slow security scans create friction in pull request workflows, and developers sometimes skip them entirely when deadlines loom. Faster scans mean security checks actually get run.

What's Actually Changing

The incremental analysis is enabled by default for projects using the build mode none extraction mechanism in both default and advanced setup configurations on github.com. If you're running the CodeQL CLI locally, you'll need to wait—GitHub says support for incremental scanning in the CLI is coming later.

One catch: the speed improvements only apply to repositories using GitHub's default CodeQL query suite. Custom query configurations won't see the same benefits yet.

Part of a Bigger Push

This update follows a busy stretch for CodeQL development. Just last week, GitHub announced expanded application security coverage using AI-powered detections alongside CodeQL. And on March 18, CodeQL version 2.24.3 shipped with Java 26 support plus updated taint tracking and framework coverage.

GitHub has also been pairing CodeQL with Copilot to offer automated fix suggestions—essentially letting AI propose patches for the vulnerabilities CodeQL finds. For development teams juggling security requirements with shipping deadlines, faster scans combined with AI-assisted remediation could meaningfully change the economics of secure coding.

The incremental analysis improvements are live now for eligible repositories on github.com.

Image source: Shutterstock
  • github
  • codeql
  • devsecops
  • code security
  • developer tools
Market Opportunity
Major Logo
Major Price(MAJOR)
$0.06347
$0.06347$0.06347
-1.24%
USD
Major (MAJOR) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact crypto.news@mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

Siren Token Sheds 70% as Analysts Question Supply Structure

Siren Token Sheds 70% as Analysts Question Supply Structure

The post Siren Token Sheds 70% as Analysts Question Supply Structure appeared on BitcoinEthereumNews.com. The Siren (SIREN) token plunged nearly 70% on Tuesday,
Share
BitcoinEthereumNews2026/03/25 01:00
ArtGis Finance Partners with MetaXR to Expand its DeFi Offerings in the Metaverse

ArtGis Finance Partners with MetaXR to Expand its DeFi Offerings in the Metaverse

By using this collaboration, ArtGis utilizes MetaXR’s infrastructure to widen access to its assets and enable its customers to interact with the metaverse.
Share
Blockchainreporter2025/09/18 00:07
Why The Green Bay Packers Must Take The Cleveland Browns Seriously — As Hard As That Might Be

Why The Green Bay Packers Must Take The Cleveland Browns Seriously — As Hard As That Might Be

The post Why The Green Bay Packers Must Take The Cleveland Browns Seriously — As Hard As That Might Be appeared on BitcoinEthereumNews.com. Jordan Love and the Green Bay Packers are off to a 2-0 start. Getty Images The Green Bay Packers are, once again, one of the NFL’s better teams. The Cleveland Browns are, once again, one of the league’s doormats. It’s why unbeaten Green Bay (2-0) is a 8-point favorite at winless Cleveland (0-2) Sunday according to betmgm.com. The money line is also Green Bay -500. Most expect this to be a Packers’ rout, and it very well could be. But Green Bay knows taking anyone in this league for granted can prove costly. “I think if you look at their roster, the paper, who they have on that team, what they can do, they got a lot of talent and things can turn around quickly for them,” Packers safety Xavier McKinney said. “We just got to kind of keep that in mind and know we not just walking into something and they just going to lay down. That’s not what they going to do.” The Browns certainly haven’t laid down on defense. Far from. Cleveland is allowing an NFL-best 191.5 yards per game. The Browns gave up 141 yards to Cincinnati in Week 1, including just seven in the second half, but still lost, 17-16. Cleveland has given up an NFL-best 45.5 rushing yards per game and just 2.1 rushing yards per attempt. “The biggest thing is our defensive line is much, much improved over last year and I think we’ve got back to our personality,” defensive coordinator Jim Schwartz said recently. “When we play our best, our D-line leads us there as our engine.” The Browns rank third in the league in passing defense, allowing just 146.0 yards per game. Cleveland has also gone 30 straight games without allowing a 300-yard passer, the longest active streak in the NFL.…
Share
BitcoinEthereumNews2025/09/18 00:41