For the complete documentation index, see llms.txt. This page is also available as Markdown.

Sto Supported Ingestion Formats

Static Analysis Results Interchange Format (SARIF) is an open JSON format supported by many scan tools, especially tools available as GitHub Actions. Harness STO can ingest SARIF 2.1.0 data from any tool that supports this format.

Harness recommends that you publish and ingest using the scanner-specific JSON format when available, because it tends to include more useful information.

  • Anchore Enterprise — JSON

  • Aqua Security — JSON

  • Aqua Trivy — JSON (recommended), SARIF

  • AWS ECR — JSON

  • AWS Security Hub — JSON

  • Bandit — JSON (recommended), SARIF

  • Black Duck Hub — JSON

  • Brakeman — JSON

  • Burp — XML

  • Traceable — JSON

  • Checkmarx — XML, SARIF

  • CheckmarxOne — JSON

  • CodeQL — SARIF

  • Coverity — XML

  • Data Theorem — JSON

  • Docker Content Trust — JSON

  • Fortify — JSON

  • Fortify on Demand — JSON

  • Fossa — JSON

  • Gitleaks — JSON (recommended), SARIF

  • GitHub Advanced Security — SARIF

  • HQL AppScan — XML

  • Grype — JSON

  • Mend (formerly Whitesource) — JSON

  • ModelScan — JSON

  • Nessus — XML

  • Nexus — JSON

  • Nikto — XML

  • Nmap — XML

  • OpenVAS — JSON

  • OWASP Dependency Check — JSON

  • Prisma Cloud — JSON

  • Prowler — JSON

  • Qualys — XML

  • Reapsaw — JSON

  • Semgrep — SARIF

  • Snyk — JSON (recommended), SARIF

  • SonarQube — JSON

  • Sysdig — JSON

  • Tenable — JSON

  • Veracode — XML

  • JFrog Xray — JSON

  • Wiz - JSON (recommended), SARIF

  • Zed Attack Proxy (ZAP) — JSON

  • Checkov - JSON, SARIF

Last updated

Was this helpful?