"Devs don't like having to run SASTs and having to do a lot of stuff, you need to give them just the small things that they need to really do to pass their security audit."
This sounds like encouraging the very wrong practice of security by boxticking and it's a very bad message to send out. #DevSecCon