Security Testing Orchestration
Explore planned Security Testing Orchestration capabilities and enhancements.
This page tracks planned capabilities and enhancements for Security Testing Orchestration.
Now
Q3 2026, Aug 2026 - Oct 2026
App & Target Vuln View for Code Repository & Artifacts Target view grouped by apps and teams.
Non Harness CI (Jenkins & GHA Support) Native onboarding for Non Harness CI - Jenkins and GitHub Actions.
Triage Agent AI-powered agent that determines if a finding is a likely false positive or likely true positive by leveraging LLMs to understand real-world risk beyond CVSS scores.
Get Started A new Get Started workflow to onboard third-party integrations - Github Actions, Jenkins.
LLM as a Scanner Orchestration Orchestrate LLM-based scanners natively in STO pipelines.
Remediation Agent AI-powered agent that remediates security findings with suggested fixes and automated workflows.
SBOM & Compliance Visibility Add SBOM and Compliance Tabs in the Target view page
Code to Runtime Visibility End-to-end vulnerability traceability from code to runtime, powered by the Security Graph.
Bi-directional Support for Checkmarx and Mend Manage Checkmarx and Mend scans and findings from STO while keeping source projects in sync, and reduce duplicate workflows across tools.
Scanner Deduplication Roll up findings from multiple scanners into a single issue so the same vulnerability is not tracked more than once.
Next
Q4 2026, Nov 2026 - Jan 2027
Target Deletion Allows deletion of unwanted targets/artifacts vulnerability data to reduce noise.
Code to CD Inventory Graph with Runtime Signals Extend the Code to CD Inventory Graph with runtime signals so teams overlay live service health and exposure data on the code-to-deploy graph and prioritize production fixes.
Auto PRs for SCA Remediation Create PRs for SCA issues using AI suggestions for direct dependency upgrades (JS/TS, Python, Java). Transitives excluded.
Orca Integration Native integration with Orca.
Harness Risk Scoring Combine severity, exploitability, reachability, and environment data into a single score so security teams can prioritize the riskiest issues across services.
Runtime Reachability via STO Distinguish vulnerabilities that are actually reachable at runtime from theoretical issues so teams apply risk-based remediation and more focused policies.
Later
Q1 2027, Feb 2027 & Beyond
SAST to DAST Correlation Correlate SAST and DAST findings so teams see how a single underlying flaw manifests in code and at runtime.
Exemption Management via ServiceNow Native ServiceNow integration for exemption management.
Reachability based Vulnerability Prioritization Prioritize vulnerabilities on Harness risk score - formualted on CVSS, EPSS, static and runtime Reacability, etc.
Issues List - Org/Account A centralized, prioritized vulnerability list for the AppSec persona at the Org/Account scope.
Dastardly Integration Support Dastardly with Orchestration, Extraction, and Ingestion modes, with Built-in scanner workflow step under DAST.
CrowdStrike Integration Native integration with CrowdStrike.
Extraction and Ingestion mode support for Base Image detection Ability to see base image vs. app layer vulnerabilities and govern pipelines.
Native .NET Scanning Support Scan .NET services natively in STO without relying on external tooling.
Released
What has been released
Auto PR Support for GitLab and Bitbucket Create pull requests from Harness AI remediation for GitLab and Bitbucket.
Auto Create Jira Ticket on Exemption Request Automatically create a Jira ticket on exemption request using a configured template.
Cortex Cloud Integration Native Integration with Cortex Cloud.
Product Usage Analytics A centralized analytics dashboard showing STO usage trends, adoption, and engagement across all security scans.
Exemption Workflow Revamp Revamp the exemption workflow with configurable rules based on severity, customizable exemption periods per severity level.
AI Skills for AI-powered IDEs Expose STO capabilities as AI-powered skills via the Harness MCP Server, enabling security workflow automation directly from AI-powered IDEs.
Open and Remediated Issues Trend Visibility into active and remediated issues trend across Targets in a Project.
Linux ARM64 Support Adds Linux ARM64 infrastructure support for all STO steps, enabling broader platform compatibility and flexibility.
Support Nexus scanner in FedRAMP Add native ingestion-mode support for the Nexus scanner in FedRAMP environments.
Support Prisma Cloud scanner in FedRAMP Add native ingestion-mode support for the Prisma Cloud scanner in FedRAMP environments.
Project level Security Dashboard Redesigned STO overview page to get security posture across the Project via graphs, trends, summary.
Delegate 3.0 Support Extend STO steps to execute on Delegate 3.0.
Manually override severity Ability to manually override the severity of an issue across all the targets at Project scope.
Exploit Protection Scoring System (EPSS) Provide EPSS score in addition to CVSS score for better vulnerability prioritization.
Native Integration with Qwiet AI Native integration with Qwiet.ai scanners aka Harness Secruity Scanners for SAST/SCA/Secret.
Map External Policy Failures to severity Map external policy failures ingested from 3rd party scanners to a severity instead of INFO level issues.
Filters on Exemption page Provide filters for users to narrow down exemptions based on all the supported criteria.
Base image vs App layer vulnerability Ability to see base image vs. app layer vulnerabilities and govern pipelines.
Fix: Handle vulnerabilities for Aborted/Resume executions Aggregate security scan results from all stages/executions including aborted, resumed pipeline executions.
Exemption Notifications Notify developers and AppSec teams via email, Slack, Microsoft Teams, or a custom webhook about pending, approved, and expired exemption requests.
Download Issues Data as CSV from Vulnerabilities Tab Enable RBAC-honoring download of issues CSV from Vulnerabilities Tab, add API, and deep-link to Pipeline Execution Summary Dashboard with execution ID.
AppSec Chatbot AI chatbot to help with STO use cases.
Issues List - Project Centralized, prioritized vulnerability list for AppSec persona with ticket creation for tracking at Project scope.
Native support in IDP Native STO support via the Harness IDP module score-cards.
STO support in Harness Resource Group Ability to configure granular access to security test results within the pipeline view via the Harness Resource Group.
Approval/Rejection comment Enable AppSec users to add contextual comments when approving or rejecting an exemption request.
FIPS support for STO Ability to leverage STO steps in Harness Pipeline within FIPS enabled SMP environment.
Exemption at Occurrence Level Exempt specific occurrences of issues without exempting the entire STO issue.
Last updated
Was this helpful?