I was recently looking at systemd's CI and came across this.
AFAICS it's a proprietary analysis but it looks useful.
We still have `clang-analyzer` for example for FOSS analysis.
--- /dev/null
+# See https://lgtm.com/
+extraction:
+ cpp:
+ prepare:
+ packages:
+ - "autoconf-archive"
+ - "libcurl4-openssl-dev"
+ - "libjson-c-dev"
+ - "libssl-dev"
+ - "acl"
+ - "attr"
+ - "bison"
+ - "cpio"
+ - "debhelper"
+ - "dh-autoreconf"
+ - "dh-systemd"
+ - "docbook-xml"
+ - "docbook-xsl"
+ - "e2fslibs-dev"
+ - "elfutils"
+ - "fuse"
+ - "gjs"
+ - "gnome-desktop-testing"
+ - "gobject-introspection"
+ - "gtk-doc-tools"
+ - "libarchive-dev"
+ - "libattr1-dev"
+ - "libcap-dev"
+ - "libfuse-dev"
+ - "libgirepository1.0-dev"
+ - "libglib2.0-dev"
+ - "libgpgme11-dev"
+ - "liblzma-dev"
+ - "libmount-dev"
+ - "libselinux1-dev"
+ - "libsoup2.4-dev"
+ - "libcurl4-openssl-dev"
+ - "procps"
+ - "zlib1g-dev"
+ - "python3-yaml"