Before pushing changes to a repository, developers need security, secret, dependency and lint checks on the lines they changed, plus review conclusions they can verify.
The current approach is manual code review, or separate SAST, secret and dependency scanners whose findings a person judges one by one.
Manual review easily misses leaked secrets and dependency risks, and problems found after release cost more to fix; public material gives no false-positive or miss-rate data.