GitHub code scanning is a developer-first, GitHub-native approach to easily find security vulnerabilities before they reach production. It scans code as its created and surfaces actionable security reviews within pull requests and other GitHub experiences you use everyday. This helps ensure vulnerabilities never make it to production in the first place. CodeQL is powered by CodeQL, the world’s most powerful code analysis engine. It’s free for public repositories and is a GitHub Advanced Security feature for GitHub Enterprise. Weve scanned over 12,000 repositories 1.4 million times, and found more than 20,000 security issues.”]
Source: https://github.blog/2020-09-30-code-scanning-is-now-available/

