Context: https://github.com/google/brotli/security/code-scanning/4 Quick view on actions panel reveals that report is not true: https://github.com/google/brotli/actions/workflows/codeql.yml?query=branch%3Amaster