Repository navigation
Kotlin 2.4.20 is about to be released - please prepare to be ready asap #22381
Description
Activity
- addedquestionFurther information is requestedFurther information is requested
on Aug 19, 2026 - marked Kotlin version 2.4.20-Beta1 is too recent. CodeQL currently supports versions below 2.4.20 codeql-action#4100 as a duplicate of this issue
on Aug 20, 2026 The advisory for reference: GHSA-r937-wjx7-w2jp
PR: #22404
Now it happened again... :-( Kotlin is out and every user is waiting for CodeQL to catch up. Why can't you enable CodeQL support on the RC versions of Kotlin, so that on release day people can use the latest Kotlin version without desperately waiting for CodeQL??
Reacted by Sigrid Andersson, Vadzim Kapichenka, Vernon Cuipers, Vegard Rognstad Smines, Øystein Kjærnet and 海蓝色的咕咕鸽@Zordid and others, first of all our sincerest apologies we didn't make it in time. While we started working on this in advance, unfortunately #22404 required some back and forth and then missed the release cut for CodeQL 2.27.0. This unfortunately means support will only land in 2.27.1, approximately two weeks from now.
We will still try to improve on this 🙌
If you are still really desperate to update, you can try using one of the nightly releases. The caveat is that we can't offer any kind of support if you do, and we rather recommend sitting tight and waiting for a stable release.
Reacted by Waffiq Aziz, Vadzim Kapichenka, Richard Seeton and George NicolaeReacted by Vernon CuipersReacted by Olaf Gottschalk and ChristianReacted by Bernard LadenthinIs there any chance you will find a solution to this ongoing problem? CodeQL is not free anymore, and to have this recurring problem every time a new kotlin-version is released is not ideal.
Reacted by Vadzim Kapichenka, Joakim Taule Kartveit, stephanprantl, Marc Rohlfs, Vernon Cuipers, George Nicolae, Hatsy Rei, Sebastian Kruschwitz, Arvin Khodabandeh, Vegard Rognstad Smines and 4 moreIs there a reason why CodeQL documentation claims Kotlin 2.4.20 support before it landed?
https://codeql.github.com/docs/codeql-overview/supported-languages-and-frameworks/
Reacted by Ilia Sretenskii and Øystein Kjærnet- added a commit that references this issue
on Sep 21, 2026 - added a commit that references this issue
on Sep 23, 2026 - added a commit that references this issue
on Sep 24, 2026 Is there a reason why CodeQL documentation claims Kotlin 2.4.20 support before it landed?
Apologies for this. Is has to do with the way we generate the documentation. I'll discuss internally whether we can avoid this out-of-sync behavior in the future.
Reacted by Hatsy ReiIs there any chance you will find a solution to this ongoing problem?
For some discussion on this see #21938. We would absolutely like to change this, but this is a substantial amount of work, so this is not going to happen overnight.
CodeQL is not free anymore, and to have this recurring problem every time a new kotlin-version is released is not ideal.
I'm not aware that our license has changed over the last 5+ years.
Closing this, as CodeQL 2.27.1 has been released.
- added a commit that references this issue
on Oct 4, 2026
Kotlin 2.4.20 is very close to release. Please do NOT wait until that day to update CodeQL. Use the available 2.4.20-RC today to adopt CodeQL, please.
As there is a security problem with Kotlin 2.4.10, we need to update quickly and cannot wait another month for CodeQL to adopt.
Thanks!