> For the complete documentation index, see [llms.txt](https://developer.harness.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://developer.harness.io/security-testing-orchestration/use-sto/sto-scanner-configuration/shared/sto-supported-ingestion-formats.md).

# Sto Supported Ingestion Formats

{% hint style="info" %}
Static Analysis Results Interchange Format (SARIF) is an open JSON format supported by many scan tools, especially tools available as GitHub Actions. Harness STO can [ingest SARIF 2.1.0 data](/security-testing-orchestration/use-sto/sto-custom-scanning-and-ingestion/ingest-sarif-data.md) from any tool that supports this format.

Harness recommends that you publish and ingest using the scanner-specific JSON format when available, because it tends to include more useful information.
{% endhint %}

* **Anchore Enterprise** — JSON
* **Aqua Security** — JSON
* **Aqua Trivy** — JSON *(recommended)*, SARIF
* **AWS ECR** — JSON
* **AWS Security Hub** — JSON
* **Bandit** — JSON *(recommended)*, SARIF
* **Black Duck Hub** — JSON
* **Brakeman** — JSON
* **Burp** — XML
* **Traceable** — JSON
* **Checkmarx** — XML, SARIF
* **CheckmarxOne** — JSON
* **CodeQL** — SARIF
* **Coverity** — XML
* **Data Theorem** — JSON
* **Docker Content Trust** — JSON
* **Fortify** — JSON
* **Fortify on Demand** — JSON
* **Fossa** — JSON
* **Gitleaks** — JSON *(recommended)*, SARIF
* **GitHub Advanced Security** — SARIF
* **HQL AppScan** — XML
* **Grype** — JSON
* **Mend&#x20;*****(formerly Whitesource)*** — JSON
* **ModelScan** — JSON
* **Nessus** — XML
* **Nexus** — JSON
* **Nikto** — XML
* **Nmap** — XML
* **OpenVAS** — JSON
* **OWASP Dependency Check** — JSON
* **Prisma Cloud** — JSON
* **Prowler** — JSON
* **Qualys** — XML
* **Reapsaw** — JSON
* **Semgrep** — SARIF
* **Snyk** — JSON *(recommended)*, SARIF
* **SonarQube** — JSON
* **Sysdig** — JSON
* **Tenable** — JSON
* **Veracode** — XML
* **JFrog Xray** — JSON
* **Wiz** - JSON *(recommended)*, SARIF
* **Zed Attack Proxy (ZAP)** — JSON
* **Checkov** - JSON, SARIF
