1. Scan files with codeql during CI 2. report results 3. gate further CI actions based on result (stop on errors) 4. full integration into GitHub's native security functionality