This repo's code scanning functionality suggests adding a static code analysis tool, eg https://codeql.github.com/