ci: add CodeQL, Dependabot, and dependency review #3
ci/security-workflows was force-pushed and no longer has any new commits.
Pushing new commits will allow the pull request to be re-opened.
Pushing new commits will allow the pull request to be re-opened.