We have a few high-profile projects using our automated code review (marketing people tell me I'm not allowed to call it 'PR integration' any more). One example is on the AMP Project, where we caught a regex injection vulnerability in a PR before a human looked at it: https://github.com/ampproject/amphtml/pull/13060
Our default analysis has found a few other vulnerabilities (remote buffer overflows due to misuse of snprintf in rsyslog and Icecast spring to mind) but, honestly, I think our strength lies in the fact that you can write custom queries that find bugs specific to a single codebase's foibles.
For example, my first ever CVE was for a vulnerability in ChakraCore. Google Project Zero found the original bug - type confusion caused by failure to check a flag indicating that the last element of a list should be cast to a different type - but we wrote a query to verify that code accessing that particular list always checked the flag. So when some new code got introduced with the same bug, we noticed as soon as we re-ran the query on the new commit.