For new projects, you may have to set up CodeQL Security scanning. These are the steps to do it.
- Open project on GitHub
- Click on Security Tab
- Click Code Scanning on left side toolbar
- Click Configure Scanning Tool button
- Scroll down to Tools > CodeQL Analysis > click Set Up dropdown > Choose Default
- Enable CodeQL
- You should see a message bar at the top of the page that says “…setup might take a while…”