GitHub's open-source CodeQL tool looks for security holes in real-time