For the complete documentation index, see llms.txt. This page is also available as Markdown.

Built-in scanners

Scan targets without scan tool licenses or configuration.

Built-in scanners in STO are supported scanners that require no additional setup or licensing. They use free or open-source versions of the tools. You do not need commercial scanner licenses.

STO configures built-in scanners automatically. Harness executions still incur billing charges. Built-in scanners reduce scanner setup and licensing requirements.

The following table lists built-in scanners by scan type. Select a scanner name to configure it. Go to Set up a built-in scanner to add one to a pipeline.

Scan type
Built-in scan supported scanners

Static Application Security Testing (SAST)

Software Composition Analysis (SCA)

Secret Detection

Dynamic Application Security Testing (DAST)

Infrastructure as Code (IaC)

Set up a built-in scanner

Set up a built-in scanner in any supported scan type. STO configures the scanner automatically.

  1. In your Build or Security stage, click Add Step.

  2. In the Security Tests category, select Built-in Scanners.

  3. Select the scan type you want to run.

    Built-in scanner options in the Security Tests category
    Click to view full size image
  4. Select a scanner for the scan type. If needed, expand the scan step and enter Additional CLI Flags.

    Built-in scanner configuration with Additional CLI Flags
    Click to view full size image
  5. For Container or DAST steps, enter Container Information or Domain Information.

  6. Click Add Scanner. STO automatically detects the target and variant.

To modify the step configuration, select the scan step in the pipeline. Log Level and Fail on Severity use their default values.

Last updated

Was this helpful?