Tools like Sonar Qube are pretty shallow. Anecdotally, a robust development process will produce software that always reads clean on those scanners even if those scanners are not part of your development process. They detect defective development processes more than they detect defective code or designs.
Parts of the US DoD do have more rigorous testing that is considerably broader in scope than commercial linters and such, and evaluates for threats that commercial systems don't consider. Many of these tests reliably break open source software. It is unclear how thorough or exhaustive these audits or tests are -- it can be quite opaque. For good or bad, having been through several serious security audits by multiple organizations, my software always came back clean so it is difficult to calibrate their sensitivity from the outside.