This patch adds two github workflows that will run on each commit, and also regularly: CodeQL and govulncheck.