CodeQL
CodeQL is GitHub's semantic analysis engine and query language for multi-language databases, dataflow, and Actions scanning.
Why use it
Security teams write reusable rules and trace complex taint paths in pull requests.
Where it fits
Use testing, performance, accessibility, and diagnostic tools to remove problems players will notice.
What to check
CLI licensing limits commercial closed-source use, private repositories generally need GitHub Advanced Security, and queries require expertise.