For the complete documentation index, see llms.txt. This page is also available as Markdown.

SAST and SCA

Explore planned SAST and SCA capabilities and enhancements.

This page tracks planned capabilities and enhancements for SAST and SCA.

SaaS release status: GA, SMP release status: GA

Now

Q3 2026, Aug 2026 - Oct 2026

AI Automation

Security AI Agents

Enable AI-powered agents to detect, triage, and remediate security issues through automated or on-demand workflows.

Reporting Visibility

AppSec Metrics Dashboard

Deliver dashboards to track findings, remediation progress, and security trends.

SCA Visibility

Improved Transitive Dependency Visibility

Enhance visibility into transitive dependencies and associated vulnerabilities.

SAST Language Support

T-SQL Language Support (Beta)

Add native SAST scanning support for T-SQL.

Integrations SAST

Bitbucket Data Center Support

Enable Autofix workflows for repositories hosted on Bitbucket Data Center.

SCA AI

Slopsquatting Detection

Detect potentially malicious or hallucinated package dependencies introduced by AI-generated code.

Platform Visibility

CI Source Visibility

Show the CI source associated with scans for better visibility and traceability.

AI Risk Remediation

AI Risk Autofix

Provide automated remediation recommendations and fixes for detected AI Risks.

AI Risk Compliance

AI Risk OWASP Mapping

Map detected AI risks to relevant OWASP Agent Skills categories.

Integrations Ticketing

Multiple Azure Boards Support

Support creating and managing security tickets across multiple Azure Boards projects.

Platform IDE

Windows + ARM Support

Enable support for Windows on ARM environments.

SCA Artifact Security

Package Scanning Support

Extend SCA scanning to non-OCI packages and artifacts across supported package ecosystems.

Governance Policy

Policy Management Through UI

Allow users to configure and manage application security policies directly through the UI.

SCA SBOM

SBOM Support for Spinnaker

Enable reliable SBOM generation for Spinnaker applications and dependencies.

Platform Developer Experience

Check-Analysis Validation Enhancements

Improve check-analysis validation behavior for more flexible CI/CD security workflows.

SAST IaC

Azure Bicep Support

Add security scanning support for infrastructure defined using Azure Bicep.

SCA Container Security

Deep Container Analysis

Differentiate base image and application-layer vulnerabilities to improve container risk prioritization.

Secure AI Coding IDE

Secure AI Coding for VS Code

Bring Secure AI Coding capabilities directly into VS Code to detect and remediate security issues as developers write code.

SCA Language Support

CPE identifiers support

Expand SCA vulnerability detection to include CPE identifiers.

Next

Q4 2026, Nov 2026 - Jan 2027

AI SAST Detection

AI-Enhanced SAST V2

Advance AI-powered SAST with deeper contextual reasoning, improved detection accuracy, validation, and risk prioritization.

SAST Language Support

Rust Language Support (GA)

Add native SAST scanning support for Rust.

SAST Language Support

Objective-C Support (Beta)

Add SAST scanning and vulnerability detection support for Objective-C applications.

SCA Dependency Management

SCA Package Upgrade Validation

Validate package upgrades to identify security issues and potential risks before adoption.

SCA Remediation

OSS Risk Autofix

Provide automated fixes and upgrade recommendations for open-source dependency risks.

IDE SAST SCA

Visual Studio Extension Support

Provide Visual Studio extensions to run Harness SAST and SCA scans directly within the IDE.

Platform Deployment

SMP + FIPS Support

Enable Harness SAST and SCA support for air-gapped deployments on the Self-Managed Platform.

Visibility Reporting

Detailed Reporting

Deliver richer, more granular reporting for insights across scans and projects.

Integration GitHub

GitHub App Based Auto Repository Onboarding

Automatically onboard selected GitHub repositories and newly added repositories via a single App installation.

Later

Q1 2027+, February 2027 & beyond

AI Integration Developer Experience

Emergent AI Integration

Serve as the native security integration for Emergent AI to ship secure code by default.

AI Integration Developer Experience

Replit Integration

Serve as the native security integration for Replit to ship secure code by default.

Integration Ticketing

ServiceNow Integration

Provide native integration for ticketing and workflow automation.

SAST Language Support

Perl Language Support (Beta)

Add native SAST scanning support for Perl.

SCA Binary Analysis

Expanded Binary Analysis

Extend binary scanning support across additional binary formats and package types.

SCA Framework Support

Extended Framework Support

Extend SCA framework support to include additional frameworks and libraries.

Released

What has been released

SCA Reachability

Deep Code Reachability

Provide function-level reachability evidence to identify exploitable vulnerable dependencies.

AI Governance

Skills & MCP Security Scanner (AI Risk)

Detect malicious patterns and security risks in AI agent Skills and MCP configurations.

SCA Language Support

Export SBOM via CLI

Export SBOM via CLI for SCA.

SCA Language Support

Support for TOML config files

Scan TOML configuration files in SCA.

Standards Compliance

OWASP 2025 Support

Extend detection coverage for vulnerabilities aligned with OWASP 2025.

Remediation SCA

Autofix for OSS Vulnerabilities

Extend Autofix capabilities to address open-source vulnerabilities.

Governance Risk Management

Contextual Severity and Severity Override

Allow super admins to adjust application risk severity based on key contextual factors.

Visibility Platform

Enhanced Scan Logging

Improve scan logging to provide clearer status and actionable feedback.

SAST AI

AI-Enhanced SAST

Extend SAST coverage and reduce false positives through AI-enhanced vulnerability detection.

AI IDE

Security Skills

Provide guided security operations through reusable AI-powered Skills.

Integration IDE AI

MCP Integration for IDEs

Integrate with Harness MCP to support SAST/SCA scanning and actions directly from IDEs.

Visibility SAST SCA

Scan Summary Enhancements

Refine scan summaries to show only actionable findings.

Integration IDE AI

Secure Vibe Coding

Use predefined hooks in AI-native IDEs and CLIs (Cursor, Windsurf, Gemini) to scan code as it's generated, securing code at the source.

AI Integration IDE

Claude Plugin Support

Extend support for Claude plugins to enable security workflows through Skills and the Harness SAST and SCA MCP.

SCA OSS Risk

OSS Risk Detection

Identify OSS risks such as end-of-life, unmaintained, malicious, abandoned, hijackable, and typosquatted packages.

SAST Language Support

Groovy Language Support

Add native SAST scanning support for Groovy.

Governance CLI

CLI-Based Finding Exemption

Enable suppression of findings via CLI when predefined comments are present.

Visibility UX

Application Scan Listing

Provide a unified view of scans across all sources at the application level.

Platform Governance

Organization Configuration API Enhancements

Provide granular update support for organization configuration APIs.

Integration Jira

Jira Forge Support

Add compatibility with the Jira Forge framework.

Integration Platform

Integration with STO

Native integration with STO, enabling Qwiet's SAST/SCA/Secrets engines to run as first-class Harness Security Scanners.

Notifications Platform

Improved Webhook Notifications

Failed webhook deliveries now retry with exponential backoff and queue on persistent failure.

SAST Language Support

Realtime SCA & Secrets in IDE

Automatically detect hardcoded secrets and OSS vulnerabilities on code save directly within IDEs.

SAST Language Support

Swift Language Support

Introduce native SAST scanning support for Swift.

Integration IDE

Cursor & Windsurf IDE Support

Enable SAST/SCA scanning within AI-native IDEs like Cursor and Windsurf.

IDE Performance Multi-Language

IDE Plugin Enhancements

Improve plugin performance and expand multi-language scanning support.

Remediation Automation

Automated PR Fixes for HCR

Enable automated fix-based pull requests within the Harness Code Repository.

AI Remediation GitHub

GitHub AI Autofix Enhancements

Enhance GitHub Autofix with PR tracking, user actions, interactive comments, and bot responses.

Integration Cloud Security Visibility

Wiz Integration

Enrich the Wiz Security Graph and findings with application security context.

Remediation Automation SCM

AutoFix Pull Requests for Bitbucket

Create automated fix-based pull requests in Bitbucket with parity to existing SCM integrations.

Reporting Data Export Platform

Nightly Data Export

Export findings and related data nightly with rolling retention for 30 days.

Governance Policy CLI

Build Rules v2 Enhancements

Extend build rules with negative rules and additional filters to refine enforcement based on exploitability, AI assistance, and fix availability.

Governance Policy CLI

Webhook Notifications

Send authenticated webhook notifications for scan completion and failure events.

SAST Language Support

Support for Go 1.25

Add analysis support for applications written in Go 1.25.

Reporting

SARIF Export via API

Generate SARIF exports for application findings via API.

Integration Ticketing

Azure Boards Integration

Create and track security findings directly in Azure Boards.

Last updated

Was this helpful?