> For the complete documentation index, see [llms.txt](https://developer.harness.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://developer.harness.io/roadmap/sast-and-sca.md).

# SAST and SCA

Explore planned SAST and SCA capabilities and enhancements.

This page tracks planned capabilities and enhancements for SAST and SCA.

SaaS release status: GA, SMP release status: GA

### Now

Q3 2026, Aug 2026 - Oct 2026

<table data-column-title-hidden data-view="cards" data-search="true"><thead><tr><th>Tag</th><th>Title</th><th>Description</th></tr></thead><tbody><tr><td>AI<br>Automation</td><td><strong>Security AI Agents</strong></td><td>Enable AI-powered agents to detect, triage, and remediate security issues through automated or on-demand workflows.</td></tr><tr><td>Reporting<br>Visibility</td><td><strong>AppSec Metrics Dashboard</strong></td><td>Deliver dashboards to track findings, remediation progress, and security trends.</td></tr><tr><td>SCA<br>Visibility</td><td><strong>Improved Transitive Dependency Visibility</strong></td><td>Enhance visibility into transitive dependencies and associated vulnerabilities.</td></tr><tr><td>SAST<br>Language Support</td><td><strong>T-SQL Language Support (Beta)</strong></td><td>Add native SAST scanning support for T-SQL.</td></tr><tr><td>Integrations<br>SAST</td><td><strong>Bitbucket Data Center Support</strong></td><td>Enable Autofix workflows for repositories hosted on Bitbucket Data Center.</td></tr><tr><td>SCA<br>AI</td><td><strong>Slopsquatting Detection</strong></td><td>Detect potentially malicious or hallucinated package dependencies introduced by AI-generated code.</td></tr><tr><td>Platform<br>Visibility</td><td><strong>CI Source Visibility</strong></td><td>Show the CI source associated with scans for better visibility and traceability.</td></tr><tr><td>AI Risk<br>Remediation</td><td><strong>AI Risk Autofix</strong></td><td>Provide automated remediation recommendations and fixes for detected AI Risks.</td></tr><tr><td>AI Risk<br>Compliance</td><td><strong>AI Risk OWASP Mapping</strong></td><td>Map detected AI risks to relevant OWASP Agent Skills categories.</td></tr><tr><td>Integrations<br>Ticketing</td><td><strong>Multiple Azure Boards Support</strong></td><td>Support creating and managing security tickets across multiple Azure Boards projects.</td></tr><tr><td>Platform<br>IDE</td><td><strong>Windows + ARM Support</strong></td><td>Enable support for Windows on ARM environments.</td></tr><tr><td>SCA<br>Artifact Security</td><td><strong>Package Scanning Support</strong></td><td>Extend SCA scanning to non-OCI packages and artifacts across supported package ecosystems.</td></tr><tr><td>Governance<br>Policy</td><td><strong>Policy Management Through UI</strong></td><td>Allow users to configure and manage application security policies directly through the UI.</td></tr><tr><td>SCA<br>SBOM</td><td><strong>SBOM Support for Spinnaker</strong></td><td>Enable reliable SBOM generation for Spinnaker applications and dependencies.</td></tr><tr><td>Platform<br>Developer Experience</td><td><strong>Check-Analysis Validation Enhancements</strong></td><td>Improve check-analysis validation behavior for more flexible CI/CD security workflows.</td></tr><tr><td>SAST<br>IaC</td><td><strong>Azure Bicep Support</strong></td><td>Add security scanning support for infrastructure defined using Azure Bicep.</td></tr><tr><td>SCA<br>Container Security</td><td><strong>Deep Container Analysis</strong></td><td>Differentiate base image and application-layer vulnerabilities to improve container risk prioritization.</td></tr><tr><td>Secure AI Coding<br>IDE</td><td><strong>Secure AI Coding for VS Code</strong></td><td>Bring Secure AI Coding capabilities directly into VS Code to detect and remediate security issues as developers write code.</td></tr><tr><td>SCA<br>Language Support</td><td><strong>CPE identifiers support</strong></td><td>Expand SCA vulnerability detection to include CPE identifiers.</td></tr></tbody></table>

### Next

Q4 2026, Nov 2026 - Jan 2027

<table data-column-title-hidden data-view="cards" data-search="true"><thead><tr><th>Tag</th><th>Title</th><th>Description</th></tr></thead><tbody><tr><td>AI SAST<br>Detection</td><td><strong>AI-Enhanced SAST V2</strong></td><td>Advance AI-powered SAST with deeper contextual reasoning, improved detection accuracy, validation, and risk prioritization.</td></tr><tr><td>SAST<br>Language Support</td><td><strong>Rust Language Support (GA)</strong></td><td>Add native SAST scanning support for Rust.</td></tr><tr><td>SAST<br>Language Support</td><td><strong>Objective-C Support (Beta)</strong></td><td>Add SAST scanning and vulnerability detection support for Objective-C applications.</td></tr><tr><td>SCA<br>Dependency Management</td><td><strong>SCA Package Upgrade Validation</strong></td><td>Validate package upgrades to identify security issues and potential risks before adoption.</td></tr><tr><td>SCA<br>Remediation</td><td><strong>OSS Risk Autofix</strong></td><td>Provide automated fixes and upgrade recommendations for open-source dependency risks.</td></tr><tr><td>IDE<br>SAST<br>SCA</td><td><strong>Visual Studio Extension Support</strong></td><td>Provide Visual Studio extensions to run Harness SAST and SCA scans directly within the IDE.</td></tr><tr><td>Platform<br>Deployment</td><td><strong>SMP + FIPS Support</strong></td><td>Enable Harness SAST and SCA support for air-gapped deployments on the Self-Managed Platform.</td></tr><tr><td>Visibility<br>Reporting</td><td><strong>Detailed Reporting</strong></td><td>Deliver richer, more granular reporting for insights across scans and projects.</td></tr><tr><td>Integration<br>GitHub</td><td><strong>GitHub App Based Auto Repository Onboarding</strong></td><td>Automatically onboard selected GitHub repositories and newly added repositories via a single App installation.</td></tr></tbody></table>

### Later

Q1 2027+, February 2027 & beyond

<table data-column-title-hidden data-view="cards" data-search="true"><thead><tr><th>Tag</th><th>Title</th><th>Description</th></tr></thead><tbody><tr><td>AI<br>Integration<br>Developer Experience</td><td><strong>Emergent AI Integration</strong></td><td>Serve as the native security integration for Emergent AI to ship secure code by default.</td></tr><tr><td>AI<br>Integration<br>Developer Experience</td><td><strong>Replit Integration</strong></td><td>Serve as the native security integration for Replit to ship secure code by default.</td></tr><tr><td>Integration<br>Ticketing</td><td><strong>ServiceNow Integration</strong></td><td>Provide native integration for ticketing and workflow automation.</td></tr><tr><td>SAST<br>Language Support</td><td><strong>Perl Language Support (Beta)</strong></td><td>Add native SAST scanning support for Perl.</td></tr><tr><td>SCA<br>Binary Analysis</td><td><strong>Expanded Binary Analysis</strong></td><td>Extend binary scanning support across additional binary formats and package types.</td></tr><tr><td>SCA<br>Framework Support</td><td><strong>Extended Framework Support</strong></td><td>Extend SCA framework support to include additional frameworks and libraries.</td></tr></tbody></table>

### Released

What has been released

<table data-column-title-hidden data-view="cards" data-search="true"><thead><tr><th>Tag</th><th>Title</th><th>Description</th></tr></thead><tbody><tr><td>SCA<br>Reachability</td><td><strong>Deep Code Reachability</strong></td><td>Provide function-level reachability evidence to identify exploitable vulnerable dependencies.</td></tr><tr><td>AI<br>Governance</td><td><strong>Skills &#x26; MCP Security Scanner (AI Risk)</strong></td><td>Detect malicious patterns and security risks in AI agent Skills and MCP configurations.</td></tr><tr><td>SCA<br>Language Support</td><td><strong>Export SBOM via CLI</strong></td><td>Export SBOM via CLI for SCA.</td></tr><tr><td>SCA<br>Language Support</td><td><strong>Support for TOML config files</strong></td><td>Scan TOML configuration files in SCA.</td></tr><tr><td>Standards<br>Compliance</td><td><strong>OWASP 2025 Support</strong></td><td>Extend detection coverage for vulnerabilities aligned with OWASP 2025.</td></tr><tr><td>Remediation<br>SCA</td><td><strong>Autofix for OSS Vulnerabilities</strong></td><td>Extend Autofix capabilities to address open-source vulnerabilities.</td></tr><tr><td>Governance<br>Risk Management</td><td><strong>Contextual Severity and Severity Override</strong></td><td>Allow super admins to adjust application risk severity based on key contextual factors.</td></tr><tr><td>Visibility<br>Platform</td><td><strong>Enhanced Scan Logging</strong></td><td>Improve scan logging to provide clearer status and actionable feedback.</td></tr><tr><td>SAST<br>AI</td><td><strong>AI-Enhanced SAST</strong></td><td>Extend SAST coverage and reduce false positives through AI-enhanced vulnerability detection.</td></tr><tr><td>AI<br>IDE</td><td><strong>Security Skills</strong></td><td>Provide guided security operations through reusable AI-powered Skills.</td></tr><tr><td>Integration<br>IDE<br>AI</td><td><strong>MCP Integration for IDEs</strong></td><td>Integrate with Harness MCP to support SAST/SCA scanning and actions directly from IDEs.</td></tr><tr><td>Visibility<br>SAST<br>SCA</td><td><strong>Scan Summary Enhancements</strong></td><td>Refine scan summaries to show only actionable findings.</td></tr><tr><td>Integration<br>IDE<br>AI</td><td><strong>Secure Vibe Coding</strong></td><td>Use predefined hooks in AI-native IDEs and CLIs (Cursor, Windsurf, Gemini) to scan code as it's generated, securing code at the source.</td></tr><tr><td>AI<br>Integration<br>IDE</td><td><strong>Claude Plugin Support</strong></td><td>Extend support for Claude plugins to enable security workflows through Skills and the Harness SAST and SCA MCP.</td></tr><tr><td>SCA<br>OSS<br>Risk</td><td><strong>OSS Risk Detection</strong></td><td>Identify OSS risks such as end-of-life, unmaintained, malicious, abandoned, hijackable, and typosquatted packages.</td></tr><tr><td>SAST<br>Language Support</td><td><strong>Groovy Language Support</strong></td><td>Add native SAST scanning support for Groovy.</td></tr><tr><td>Governance<br>CLI</td><td><strong>CLI-Based Finding Exemption</strong></td><td>Enable suppression of findings via CLI when predefined comments are present.</td></tr><tr><td>Visibility<br>UX</td><td><strong>Application Scan Listing</strong></td><td>Provide a unified view of scans across all sources at the application level.</td></tr><tr><td>Platform<br>Governance</td><td><strong>Organization Configuration API Enhancements</strong></td><td>Provide granular update support for organization configuration APIs.</td></tr><tr><td>Integration<br>Jira</td><td><strong>Jira Forge Support</strong></td><td>Add compatibility with the Jira Forge framework.</td></tr><tr><td>Integration<br>Platform</td><td><strong>Integration with STO</strong></td><td>Native integration with STO, enabling Qwiet's SAST/SCA/Secrets engines to run as first-class Harness Security Scanners.</td></tr><tr><td>Notifications<br>Platform</td><td><strong>Improved Webhook Notifications</strong></td><td>Failed webhook deliveries now retry with exponential backoff and queue on persistent failure.</td></tr><tr><td>SAST<br>Language Support</td><td><strong>Realtime SCA &#x26; Secrets in IDE</strong></td><td>Automatically detect hardcoded secrets and OSS vulnerabilities on code save directly within IDEs.</td></tr><tr><td>SAST<br>Language Support</td><td><strong>Swift Language Support</strong></td><td>Introduce native SAST scanning support for Swift.</td></tr><tr><td>Integration<br>IDE</td><td><strong>Cursor &#x26; Windsurf IDE Support</strong></td><td>Enable SAST/SCA scanning within AI-native IDEs like Cursor and Windsurf.</td></tr><tr><td>IDE<br>Performance<br>Multi-Language</td><td><strong>IDE Plugin Enhancements</strong></td><td>Improve plugin performance and expand multi-language scanning support.</td></tr><tr><td>Remediation<br>Automation</td><td><strong>Automated PR Fixes for HCR</strong></td><td>Enable automated fix-based pull requests within the Harness Code Repository.</td></tr><tr><td>AI<br>Remediation<br>GitHub</td><td><strong>GitHub AI Autofix Enhancements</strong></td><td>Enhance GitHub Autofix with PR tracking, user actions, interactive comments, and bot responses.</td></tr><tr><td>Integration<br>Cloud Security<br>Visibility</td><td><strong>Wiz Integration</strong></td><td>Enrich the Wiz Security Graph and findings with application security context.</td></tr><tr><td>Remediation<br>Automation<br>SCM</td><td><strong>AutoFix Pull Requests for Bitbucket</strong></td><td>Create automated fix-based pull requests in Bitbucket with parity to existing SCM integrations.</td></tr><tr><td>Reporting<br>Data Export<br>Platform</td><td><strong>Nightly Data Export</strong></td><td>Export findings and related data nightly with rolling retention for 30 days.</td></tr><tr><td>Governance<br>Policy<br>CLI</td><td><strong>Build Rules v2 Enhancements</strong></td><td>Extend build rules with negative rules and additional filters to refine enforcement based on exploitability, AI assistance, and fix availability.</td></tr><tr><td>Governance<br>Policy<br>CLI</td><td><strong>Webhook Notifications</strong></td><td>Send authenticated webhook notifications for scan completion and failure events.</td></tr><tr><td>SAST<br>Language Support</td><td><strong>Support for Go 1.25</strong></td><td>Add analysis support for applications written in Go 1.25.</td></tr><tr><td>Reporting</td><td><strong>SARIF Export via API</strong></td><td>Generate SARIF exports for application findings via API.</td></tr><tr><td>Integration<br>Ticketing</td><td><strong>Azure Boards Integration</strong></td><td>Create and track security findings directly in Azure Boards.</td></tr></tbody></table>

{% @harness-feedback/feedback module="roadmap" pagePath="roadmap/sast-and-sca" %}
