Is there a recommended approach to do SAST (Static application security testing ) and/or SCA ( software composition testing ) over the dbt code or packages used ?

For large scale use of dbt cloud , it will be important to have automatic way to test the code for security vulnerabilities in code and also in the packages used , is there is a recommended approach here ?