GitHub CodeQL scanning can be enabled from Security tab for each repository. It can be configured to run on each commit/pull request or specific action. It should be done some test in order to get the results of this GitHub feature