Running Flexelint was part of our CI chain and also part of the internal coding standard (e.g. definition of done). There was no other time in my life where I learned so much about secure coding as I did back then. Biggest challenge was agreeing about false positives and we had 1 guy in the team who maintained the official wiki document on when a lint warning needed to go on a whitelist with an agreed description of why. The initial overhead to become lint-clean got a lot of push-back but thanks to management support we got there and you could really see how things stayed at that level even after years.
It felt at times bureaucratic or like yak shaving, but in retrospect linting was what kept the code base at a quality I haven't seen ever again since. It also ensured everyone was on the same page. Taking linting seriously required a small learning curve though and lead to some discussions here or there. These discussions were really valuable since we got to really learn from another too.
When I left and went to another project it felt like a step back where we were chasing the same old bugs due to bad coding practices and it was a major step back in my career as a dev. I miss those days.
Really love that this becomes part of gcc.