Built-in scanners
Scan targets without scan tool licenses or configuration.
Built-in scanners in STO are supported scanners that require no additional setup or licensing. They use free or open-source versions of the tools. You do not need commercial scanner licenses.
STO configures built-in scanners automatically. Harness executions still incur billing charges. Built-in scanners reduce scanner setup and licensing requirements.
The following table lists built-in scanners by scan type. Select a scanner name to configure it. Go to Set up a built-in scanner to add one to a pipeline.
Static Application Security Testing (SAST)
Software Composition Analysis (SCA)
Secret Detection
Container Scanning
Dynamic Application Security Testing (DAST)
Infrastructure as Code (IaC)
Set up a built-in scanner
Set up a built-in scanner in any supported scan type. STO configures the scanner automatically.
In your Build or Security stage, click Add Step.
In the Security Tests category, select Built-in Scanners.
Select the scan type you want to run.

Click to view full size image Select a scanner for the scan type. If needed, expand the scan step and enter Additional CLI Flags.

Click to view full size image For Container or DAST steps, enter Container Information or Domain Information.
Click Add Scanner. STO automatically detects the target and variant.
To modify the step configuration, select the scan step in the pipeline. Log Level and Fail on Severity use their default values.
Last updated
Was this helpful?