After the GitHub Satellite talk on CodeQL scanning I rushed to try it on my machine, but I'm unable to start scanning as it's currently in an opt-in beta. Hope this issue helps folks who run into the same waitlist.

From the finding security vulnerabilities docs they mention the need to enable code scanning.
This is the waitlist.
Example build: https://github.com/moov-io/ach/runs/650387063