GitHub Security Lab brings together security researchers, maintainers, and companies across the industry who share our belief that the security of open source is important for everyone. The team has already had over 100 CVEs issued for security vulnerabilities it has found. CodeQL is a tool many security research teams around the world use to perform semantic analysis of code, and weve used it ourselves to find over 100 reported CVEs in some of the most popular open source projects. Were also launching the GitHub Advisory Database, a public database of advisories created on GitHub.”]
Source: https://github.blog/2019-11-14-announcing-github-security-lab-securing-the-worlds-code-together/

