SAST and SCA
Explore planned SAST and SCA capabilities and enhancements.
This page tracks planned capabilities and enhancements for SAST and SCA.
SaaS release status: GA, SMP release status: GA
Now
Q3 2026, Aug 2026 - Oct 2026
AI Automation
Security AI Agents
Enable AI-powered agents to detect, triage, and remediate security issues through automated or on-demand workflows.
Reporting Visibility
AppSec Metrics Dashboard
Deliver dashboards to track findings, remediation progress, and security trends.
SCA Visibility
Improved Transitive Dependency Visibility
Enhance visibility into transitive dependencies and associated vulnerabilities.
SAST Language Support
T-SQL Language Support (Beta)
Add native SAST scanning support for T-SQL.
Integrations SAST
Bitbucket Data Center Support
Enable Autofix workflows for repositories hosted on Bitbucket Data Center.
SCA AI
Slopsquatting Detection
Detect potentially malicious or hallucinated package dependencies introduced by AI-generated code.
Platform Visibility
CI Source Visibility
Show the CI source associated with scans for better visibility and traceability.
AI Risk Remediation
AI Risk Autofix
Provide automated remediation recommendations and fixes for detected AI Risks.
AI Risk Compliance
AI Risk OWASP Mapping
Map detected AI risks to relevant OWASP Agent Skills categories.
Integrations Ticketing
Multiple Azure Boards Support
Support creating and managing security tickets across multiple Azure Boards projects.
Platform IDE
Windows + ARM Support
Enable support for Windows on ARM environments.
SCA Artifact Security
Package Scanning Support
Extend SCA scanning to non-OCI packages and artifacts across supported package ecosystems.
Governance Policy
Policy Management Through UI
Allow users to configure and manage application security policies directly through the UI.
SCA SBOM
SBOM Support for Spinnaker
Enable reliable SBOM generation for Spinnaker applications and dependencies.
Platform Developer Experience
Check-Analysis Validation Enhancements
Improve check-analysis validation behavior for more flexible CI/CD security workflows.
SAST IaC
Azure Bicep Support
Add security scanning support for infrastructure defined using Azure Bicep.
SCA Container Security
Deep Container Analysis
Differentiate base image and application-layer vulnerabilities to improve container risk prioritization.
Secure AI Coding IDE
Secure AI Coding for VS Code
Bring Secure AI Coding capabilities directly into VS Code to detect and remediate security issues as developers write code.
SCA Language Support
CPE identifiers support
Expand SCA vulnerability detection to include CPE identifiers.
Next
Q4 2026, Nov 2026 - Jan 2027
AI SAST Detection
AI-Enhanced SAST V2
Advance AI-powered SAST with deeper contextual reasoning, improved detection accuracy, validation, and risk prioritization.
SAST Language Support
Rust Language Support (GA)
Add native SAST scanning support for Rust.
SAST Language Support
Objective-C Support (Beta)
Add SAST scanning and vulnerability detection support for Objective-C applications.
SCA Dependency Management
SCA Package Upgrade Validation
Validate package upgrades to identify security issues and potential risks before adoption.
SCA Remediation
OSS Risk Autofix
Provide automated fixes and upgrade recommendations for open-source dependency risks.
IDE SAST SCA
Visual Studio Extension Support
Provide Visual Studio extensions to run Harness SAST and SCA scans directly within the IDE.
Platform Deployment
SMP + FIPS Support
Enable Harness SAST and SCA support for air-gapped deployments on the Self-Managed Platform.
Visibility Reporting
Detailed Reporting
Deliver richer, more granular reporting for insights across scans and projects.
Integration GitHub
GitHub App Based Auto Repository Onboarding
Automatically onboard selected GitHub repositories and newly added repositories via a single App installation.
Later
Q1 2027+, February 2027 & beyond
AI Integration Developer Experience
Emergent AI Integration
Serve as the native security integration for Emergent AI to ship secure code by default.
AI Integration Developer Experience
Replit Integration
Serve as the native security integration for Replit to ship secure code by default.
Integration Ticketing
ServiceNow Integration
Provide native integration for ticketing and workflow automation.
SAST Language Support
Perl Language Support (Beta)
Add native SAST scanning support for Perl.
SCA Binary Analysis
Expanded Binary Analysis
Extend binary scanning support across additional binary formats and package types.
SCA Framework Support
Extended Framework Support
Extend SCA framework support to include additional frameworks and libraries.
Released
What has been released
SCA Reachability
Deep Code Reachability
Provide function-level reachability evidence to identify exploitable vulnerable dependencies.
AI Governance
Skills & MCP Security Scanner (AI Risk)
Detect malicious patterns and security risks in AI agent Skills and MCP configurations.
SCA Language Support
Export SBOM via CLI
Export SBOM via CLI for SCA.
SCA Language Support
Support for TOML config files
Scan TOML configuration files in SCA.
Standards Compliance
OWASP 2025 Support
Extend detection coverage for vulnerabilities aligned with OWASP 2025.
Remediation SCA
Autofix for OSS Vulnerabilities
Extend Autofix capabilities to address open-source vulnerabilities.
Governance Risk Management
Contextual Severity and Severity Override
Allow super admins to adjust application risk severity based on key contextual factors.
Visibility Platform
Enhanced Scan Logging
Improve scan logging to provide clearer status and actionable feedback.
SAST AI
AI-Enhanced SAST
Extend SAST coverage and reduce false positives through AI-enhanced vulnerability detection.
AI IDE
Security Skills
Provide guided security operations through reusable AI-powered Skills.
Integration IDE AI
MCP Integration for IDEs
Integrate with Harness MCP to support SAST/SCA scanning and actions directly from IDEs.
Visibility SAST SCA
Scan Summary Enhancements
Refine scan summaries to show only actionable findings.
Integration IDE AI
Secure Vibe Coding
Use predefined hooks in AI-native IDEs and CLIs (Cursor, Windsurf, Gemini) to scan code as it's generated, securing code at the source.
AI Integration IDE
Claude Plugin Support
Extend support for Claude plugins to enable security workflows through Skills and the Harness SAST and SCA MCP.
SCA OSS Risk
OSS Risk Detection
Identify OSS risks such as end-of-life, unmaintained, malicious, abandoned, hijackable, and typosquatted packages.
SAST Language Support
Groovy Language Support
Add native SAST scanning support for Groovy.
Governance CLI
CLI-Based Finding Exemption
Enable suppression of findings via CLI when predefined comments are present.
Visibility UX
Application Scan Listing
Provide a unified view of scans across all sources at the application level.
Platform Governance
Organization Configuration API Enhancements
Provide granular update support for organization configuration APIs.
Integration Jira
Jira Forge Support
Add compatibility with the Jira Forge framework.
Integration Platform
Integration with STO
Native integration with STO, enabling Qwiet's SAST/SCA/Secrets engines to run as first-class Harness Security Scanners.
Notifications Platform
Improved Webhook Notifications
Failed webhook deliveries now retry with exponential backoff and queue on persistent failure.
SAST Language Support
Realtime SCA & Secrets in IDE
Automatically detect hardcoded secrets and OSS vulnerabilities on code save directly within IDEs.
SAST Language Support
Swift Language Support
Introduce native SAST scanning support for Swift.
Integration IDE
Cursor & Windsurf IDE Support
Enable SAST/SCA scanning within AI-native IDEs like Cursor and Windsurf.
IDE Performance Multi-Language
IDE Plugin Enhancements
Improve plugin performance and expand multi-language scanning support.
Remediation Automation
Automated PR Fixes for HCR
Enable automated fix-based pull requests within the Harness Code Repository.
AI Remediation GitHub
GitHub AI Autofix Enhancements
Enhance GitHub Autofix with PR tracking, user actions, interactive comments, and bot responses.
Integration Cloud Security Visibility
Wiz Integration
Enrich the Wiz Security Graph and findings with application security context.
Remediation Automation SCM
AutoFix Pull Requests for Bitbucket
Create automated fix-based pull requests in Bitbucket with parity to existing SCM integrations.
Reporting Data Export Platform
Nightly Data Export
Export findings and related data nightly with rolling retention for 30 days.
Governance Policy CLI
Build Rules v2 Enhancements
Extend build rules with negative rules and additional filters to refine enforcement based on exploitability, AI assistance, and fix availability.
Governance Policy CLI
Webhook Notifications
Send authenticated webhook notifications for scan completion and failure events.
SAST Language Support
Support for Go 1.25
Add analysis support for applications written in Go 1.25.
Reporting
SARIF Export via API
Generate SARIF exports for application findings via API.
Integration Ticketing
Azure Boards Integration
Create and track security findings directly in Azure Boards.
Last updated
Was this helpful?