Codeql is a scanner like Coverity that Microsoft acquired from LQTM. It is possible to run it via github actions. It is free to use for all open source projects. Any interest in turning it on, not sure who maintainer of github actions is.