Yes, so you pick "false positives" instead of "missing some leaks" and you build a way to mark code as "unsafe".
This is not fucking rocket science
> That's why an integrated language mechanism preventing such leaks is much better.
No categorical difference, except one is opt-in. You can even design your static analyzer so it analyses the code of dependencies that haven't opted in.