Fetching from the wire…
Security2026-07-12 · source-backed
Released July 11, it adds static-analysis queries that flag prompt-injection vulnerabilities in JavaScript and TypeScript, plus Kotlin 2.4.0 support (GitHub). Treating untrusted-input-into-LLM flows as a first-class security defect class is the right call. If you're wiring LLM calls into a JS/TS app, you can now catch injection sinks in CI instead of at runtime. Turn it on.
Each link below shares sources, entities, or timing with this story.
CodeQL supports Kotlin / Shared entities / Same source / Shared topic / What happened next
Linked by a graph relationship (CodeQL supports Kotlin); both cover CodeQL, LLM; cite the same source (GitHub).
CodeQL supports Kotlin / Shared entities / Same source / What happened next
Linked by a graph relationship (CodeQL supports Kotlin); both cover CodeQL, GitHub; cite the same source (GitHub).
CodeQL supports Kotlin / Shared entities / Shared topic / Earlier coverage / Tension
Linked by a graph relationship (CodeQL supports Kotlin); both cover GitHub, Kotlin, TypeScript; overlapping topics (catch, kotlin).
CodeQL supports Swift / Shared entities / What happened next
Linked by a graph relationship (CodeQL supports Swift); both cover Kotlin, TypeScript; picks up the Kotlin thread on 2026-08-21.
CodeQL supports Kotlin / Shared entities / What happened next
Linked by a graph relationship (CodeQL supports Kotlin); both cover CodeQL, LLM; picks up the CodeQL thread on 2026-08-24.
Linked by a graph relationship (CodeQL supports Kotlin); both cover CodeQL, GitHub; picks up the CodeQL thread on 2026-08-15.
Simon Willison released LLM / Shared entity: LLM / Shared topic / What happened next
Linked by a graph relationship (Simon Willison released LLM); both cover LLM; overlapping topics (detection, flag).
Simon Willison released LLM / Shared entity: LLM / What happened next / Tension
Linked by a graph relationship (Simon Willison released LLM); both cover LLM; picks up the LLM thread on 2026-08-16.