GitHub's CodeQL incremental analysis now runs up to 20% faster on pull requests across five major programming languages, with larger repos seeing biggest gains. (GitHub's CodeQL incremental analysis now runs up to 20% faster on pull requests across five major programming languages, with larger repos seeing biggest gains. (

GitHub CodeQL Gets Major Speed Boost for Pull Request Security Scans

2026/03/24 22:38
2 min read
For feedback or concerns regarding this content, please contact us at crypto.news@mexc.com

GitHub CodeQL Gets Major Speed Boost for Pull Request Security Scans

Luisa Crawford Mar 24, 2026 14:38

GitHub's CodeQL incremental analysis now runs up to 20% faster on pull requests across five major programming languages, with larger repos seeing biggest gains.

GitHub CodeQL Gets Major Speed Boost for Pull Request Security Scans

GitHub has rolled out significant performance improvements to CodeQL, its open-source static analysis engine, making security scans on pull requests substantially faster for developers working in C#, Java, JavaScript/TypeScript, Python, and Ruby.

The update, announced March 24, 2026, builds on incremental analysis capabilities GitHub introduced last year. Rather than scanning entire codebases with each pull request, CodeQL now generates a separate database for new or changed code and combines it with a cached database of the existing codebase.

GitHub tested the improvements across more than 100,000 repositories, grouping them by typical scan duration. The results? Larger, more complex repositories—those taking over seven minutes for non-incremental scans—saw the most dramatic improvements. Repositories in the three-to-seven minute range also benefited meaningfully, while smaller projects under three minutes showed modest gains.

The timing matters for development teams. Slow security scans create friction in pull request workflows, and developers sometimes skip them entirely when deadlines loom. Faster scans mean security checks actually get run.

What's Actually Changing

The incremental analysis is enabled by default for projects using the build mode none extraction mechanism in both default and advanced setup configurations on github.com. If you're running the CodeQL CLI locally, you'll need to wait—GitHub says support for incremental scanning in the CLI is coming later.

One catch: the speed improvements only apply to repositories using GitHub's default CodeQL query suite. Custom query configurations won't see the same benefits yet.

Part of a Bigger Push

This update follows a busy stretch for CodeQL development. Just last week, GitHub announced expanded application security coverage using AI-powered detections alongside CodeQL. And on March 18, CodeQL version 2.24.3 shipped with Java 26 support plus updated taint tracking and framework coverage.

GitHub has also been pairing CodeQL with Copilot to offer automated fix suggestions—essentially letting AI propose patches for the vulnerabilities CodeQL finds. For development teams juggling security requirements with shipping deadlines, faster scans combined with AI-assisted remediation could meaningfully change the economics of secure coding.

The incremental analysis improvements are live now for eligible repositories on github.com.

Image source: Shutterstock
  • github
  • codeql
  • devsecops
  • code security
  • developer tools
Market Opportunity
Major Logo
Major Price(MAJOR)
$0.06281
$0.06281$0.06281
-2.27%
USD
Major (MAJOR) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact crypto.news@mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

Dogecoin Price Climbs as Crypto Market Rebounds

Dogecoin Price Climbs as Crypto Market Rebounds

The post Dogecoin Price Climbs as Crypto Market Rebounds appeared on BitcoinEthereumNews.com. The cryptocurrency market moved higher on Tuesday morning as risk
Share
BitcoinEthereumNews2026/03/25 02:34
‘Missed the Bitcoin Bus’ With 600 BTC 16 Years Ago and Satoshi Around: $42.7 Million Now

‘Missed the Bitcoin Bus’ With 600 BTC 16 Years Ago and Satoshi Around: $42.7 Million Now

The post ‘Missed the Bitcoin Bus’ With 600 BTC 16 Years Ago and Satoshi Around: $42.7 Million Now appeared on BitcoinEthereumNews.com. “Missed the Bitcoin bus”
Share
BitcoinEthereumNews2026/03/25 01:48
VanEck Targets Stablecoins & Next-Gen ICOs

VanEck Targets Stablecoins & Next-Gen ICOs

The post VanEck Targets Stablecoins & Next-Gen ICOs appeared on BitcoinEthereumNews.com. Welcome to the US Crypto News Morning Briefing—your essential rundown of the most important developments in crypto for the day ahead. Grab a coffee because the firms shaping crypto’s future are not just building products, but also trying to reshape how capital flows. Crypto News of the Day: VanEck Maps Next Frontier of Crypto Venture Investing VanEck, a Wall Street player known for financial “firsts,” is pushing that legacy into Web3. The firsts include pioneering US gold funds and launching one of the earliest spot Bitcoin ETFs. Sponsored Sponsored “Financial instruments have always been a kind of tokenization. From seashells to traveler’s checks, from relational databases to today’s on-chain assets. You could even joke that VanEck’s first gold mutual funds were the original ‘tokenized gold,’” Juan C. Lopez, General Partner at VanEck Ventures, told BeInCrypto. That same instinct drives the firm’s venture bets. Lopez said VanEck goes beyond writing checks and brings the full weight of the firm. This extends from regulatory proximity to product experiments to founders building the next phase of crypto infrastructure. Asked about key investment priorities, Lopez highlighted stablecoins. “We care deeply about three questions: How do we accelerate stablecoin ubiquity? What will users want to do with them once highly distributed? And what net new assets can we construct now that we have sophisticated market infrastructure?” Lopez added. However, VanEck is not limiting itself to the hottest narrative, acknowledging that decentralized finance (DeFi) is having a renaissance. The VanEck executive also noted that success will depend on new approaches to identity and programmable compliance layered on public blockchains. Backing Legion With A New Model for ICOs Sponsored Sponsored That compliance-first angle explains VanEck Ventures’ recent co-lead of Legion’s $5 million seed round alongside Brevan Howard. Legion aims to reinvent token fundraising by making early-stage access…
Share
BitcoinEthereumNews2025/09/18 03:52