We can consider implementing https://github.com/apps/sonarcloud, which is free for OSS projects. The CNCF doesn't seem to provide any free SAST tools.