CodeQL should run on pull requests to avoid post-merge surprises. Signed-off-by: Kazuyoshi Kato <katokazu@amazon.com>