Static analysis of open source ROS2 C++ packages

I’ve also been playing around with using clang static analysis locally. It should be possible to automate the scanning and integrate reporting into CI, but it will take some effort.