Update to sast/sast@2
This MR updates the python/qa meta-component to use sast/sast
v2, adds some new related inputs, and overrides the needs
for the SAST jobs to prevent it pulling in any dependencies.
This should remove bogus vulnerabilities from Sphinx output, for example.