For the complete documentation index, see llms.txt. This page is also available as Markdown.

Security Testing Orchestration

Explore planned Security Testing Orchestration capabilities and enhancements.

This page tracks planned capabilities and enhancements for Security Testing Orchestration.

Now

Q3 2026, Aug 2026 - Oct 2026

AST

App & Target Vuln View for Code Repository & Artifacts Target view grouped by apps and teams.

IntegrationJenkinsGitHub Actions

Non Harness CI (Jenkins & GHA Support) Native onboarding for Non Harness CI - Jenkins and GitHub Actions.

AITriage

Triage Agent AI-powered agent that determines if a finding is a likely false positive or likely true positive by leveraging LLMs to understand real-world risk beyond CVSS scores.

OnboardingGet Started

Get Started A new Get Started workflow to onboard third-party integrations - Github Actions, Jenkins.

AIOrchestration

LLM as a Scanner Orchestration Orchestrate LLM-based scanners natively in STO pipelines.

AIRemediation

Remediation Agent AI-powered agent that remediates security findings with suggested fixes and automated workflows.

SBOMCompliance

SBOM & Compliance Visibility Add SBOM and Compliance Tabs in the Target view page

RuntimeVisibility

Code to Runtime Visibility End-to-end vulnerability traceability from code to runtime, powered by the Security Graph.

IntegrationCheckmarxMend

Bi-directional Support for Checkmarx and Mend Manage Checkmarx and Mend scans and findings from STO while keeping source projects in sync, and reduce duplicate workflows across tools.

DeduplicationScanner

Scanner Deduplication Roll up findings from multiple scanners into a single issue so the same vulnerability is not tracked more than once.

Next

Q4 2026, Nov 2026 - Jan 2027

Data Handling

Target Deletion Allows deletion of unwanted targets/artifacts vulnerability data to reduce noise.

RuntimeVisibility

Code to CD Inventory Graph with Runtime Signals Extend the Code to CD Inventory Graph with runtime signals so teams overlay live service health and exposure data on the code-to-deploy graph and prioritize production fixes.

AIRemediationSCA

Auto PRs for SCA Remediation Create PRs for SCA issues using AI suggestions for direct dependency upgrades (JS/TS, Python, Java). Transitives excluded.

Integration

Orca Integration Native integration with Orca.

Risk ScoringPrioritization

Harness Risk Scoring Combine severity, exploitability, reachability, and environment data into a single score so security teams can prioritize the riskiest issues across services.

ReachabilityRuntime

Runtime Reachability via STO Distinguish vulnerabilities that are actually reachable at runtime from theoretical issues so teams apply risk-based remediation and more focused policies.

Later

Q1 2027, Feb 2027 & Beyond

SASTDASTCorrelation

SAST to DAST Correlation Correlate SAST and DAST findings so teams see how a single underlying flaw manifests in code and at runtime.

IntegrationServiceNow

Exemption Management via ServiceNow Native ServiceNow integration for exemption management.

ReachabilityVulnerability Prioritization

Reachability based Vulnerability Prioritization Prioritize vulnerabilities on Harness risk score - formualted on CVSS, EPSS, static and runtime Reacability, etc.

VisibilityAppSec

Issues List - Org/Account A centralized, prioritized vulnerability list for the AppSec persona at the Org/Account scope.

IntegrationDastardly

Dastardly Integration Support Dastardly with Orchestration, Extraction, and Ingestion modes, with Built-in scanner workflow step under DAST.

IntegrationCrowdStrike

CrowdStrike Integration Native integration with CrowdStrike.

VulnerabilityGovernance

Extraction and Ingestion mode support for Base Image detection Ability to see base image vs. app layer vulnerabilities and govern pipelines.

SAST.NET

Native .NET Scanning Support Scan .NET services natively in STO without relying on external tooling.

Released

What has been released

AIRemediationGitLabBitbucket

Auto PR Support for GitLab and Bitbucket Create pull requests from Harness AI remediation for GitLab and Bitbucket.

TicketingIntegrationExemption

Auto Create Jira Ticket on Exemption Request Automatically create a Jira ticket on exemption request using a configured template.

IntegrationCortex Cloud

Cortex Cloud Integration Native Integration with Cortex Cloud.

Analytics

Product Usage Analytics A centralized analytics dashboard showing STO usage trends, adoption, and engagement across all security scans.

Exemption

Exemption Workflow Revamp Revamp the exemption workflow with configurable rules based on severity, customizable exemption periods per severity level.

AI SKills

AI Skills for AI-powered IDEs Expose STO capabilities as AI-powered skills via the Harness MCP Server, enabling security workflow automation directly from AI-powered IDEs.

VisibilityAppSec

Open and Remediated Issues Trend Visibility into active and remediated issues trend across Targets in a Project.

Infrastructure

Linux ARM64 Support Adds Linux ARM64 infrastructure support for all STO steps, enabling broader platform compatibility and flexibility.

FedRAMP

Support Nexus scanner in FedRAMP Add native ingestion-mode support for the Nexus scanner in FedRAMP environments.

FedRAMP

Support Prisma Cloud scanner in FedRAMP Add native ingestion-mode support for the Prisma Cloud scanner in FedRAMP environments.

VisibilityDashboard

Project level Security Dashboard Redesigned STO overview page to get security posture across the Project via graphs, trends, summary.

Delegate

Delegate 3.0 Support Extend STO steps to execute on Delegate 3.0.

Override Severity

Manually override severity Ability to manually override the severity of an issue across all the targets at Project scope.

EPSS

Exploit Protection Scoring System (EPSS) Provide EPSS score in addition to CVSS score for better vulnerability prioritization.

IntegrationQwiet AI

Native Integration with Qwiet AI Native integration with Qwiet.ai scanners aka Harness Secruity Scanners for SAST/SCA/Secret.

External Policy FailuresSeverity

Map External Policy Failures to severity Map external policy failures ingested from 3rd party scanners to a severity instead of INFO level issues.

UsabilityFiltering

Filters on Exemption page Provide filters for users to narrow down exemptions based on all the supported criteria.

VulnerabilityGovernance

Base image vs App layer vulnerability Ability to see base image vs. app layer vulnerabilities and govern pipelines.

VisibilityPlatform

Fix: Handle vulnerabilities for Aborted/Resume executions Aggregate security scan results from all stages/executions including aborted, resumed pipeline executions.

NotificationsPlatform

Exemption Notifications Notify developers and AppSec teams via email, Slack, Microsoft Teams, or a custom webhook about pending, approved, and expired exemption requests.

PlatformRBAC

Download Issues Data as CSV from Vulnerabilities Tab Enable RBAC-honoring download of issues CSV from Vulnerabilities Tab, add API, and deep-link to Pipeline Execution Summary Dashboard with execution ID.

AIVisibility

AppSec Chatbot AI chatbot to help with STO use cases.

VisibilityAppSec

Issues List - Project Centralized, prioritized vulnerability list for AppSec persona with ticket creation for tracking at Project scope.

Cross Module

Native support in IDP Native STO support via the Harness IDP module score-cards.

RBAC

STO support in Harness Resource Group Ability to configure granular access to security test results within the pipeline view via the Harness Resource Group.

Exemption Management

Approval/Rejection comment Enable AppSec users to add contextual comments when approving or rejecting an exemption request.

FIPSCompliance

FIPS support for STO Ability to leverage STO steps in Harness Pipeline within FIPS enabled SMP environment.

PlatformExemption

Exemption at Occurrence Level Exempt specific occurrences of issues without exempting the entire STO issue.

Last updated

Was this helpful?