I hope it’s an improvement on their current PR review code scanning, which alerts on code that only looks possibly vulnerable in isolation, without looking at the context. I guess I assumed it was an LLM being extremely lazy, but maybe it’s just static analysis. Anyway it’s pretty annoying.
Alerts on test fixtures, so suspect it is doing nothing new.