It would probably be better to send this kind of information privately to the developers. There is no need to post it publicly unless they ignore you. There is a list of developers and their emails on
www.bitcoin.org.
Thanks for your suggestion. I just tried to post these issues to generate a healthy discussion of the use of some robust static analysis tool for the bitcoin project.
I have raised these issues in the github bitcon.