Overview
This article contains a table of programming languages supported by Mend SAST.
Mend SAST employs two detection engines:
-
Gen 2 engines are the latest generation of Mend SAST engines. They offer improved precision (fewer false positives), better performance, AI-based remediation suggestions, and support for scan profiles with toggleable low-probability findings.
-
Gen 1 engines are the previous generation. They are actively maintained till the deprecation date, which is one year after the general availability of the corresponding Gen 2 engine. After that, the Gen 1 engine can still be used to preserve consistency, but bugs will no longer be fixed.
Note: Not all programming languages currently benefit from the Gen 2 detection engine, although Mend.io is gradually migrating all languages to Gen 2.
When Mend.io introduces a new detection engine generation, the previous generation remains the default for existing customers to keep results consistent. The engine generation parameters support a gradual rollout, letting you validate the new generation on selected projects before enabling it as the default across the organization. See Configure the Mend CLI for SAST for setting which engine generation to use.
Note: To make a new engine generation the default for an organization, reach out to Mend Support or Customer Success.
Supported Languages Tables
For a list of supported frameworks, CWEs and file extensions per language, please visit the individual language pages.
Gen 2 Engines
|
Language |
Version |
Configuration Options |
|---|---|---|
|
Android Java (coming soon) |
|
Contact your CSM to become a design partner and get early access |
|
1.0 up to latest version |
|
|
|
1.0 up to latest version |
|
|
|
1.0 up to latest version |
|
|
|
1.2 up to latest version |
|
|
|
ECMAScript 3-2018 up to latest version |
|
|
|
Kotlin (coming soon) |
|
Contact your CSM to become a design partner and get early access |
|
Kotlin Mobile (coming soon) |
|
Contact your CSM to become a design partner and get early access |
|
PHP
|
|
Contact your CSM to become a design partner and get early access |
|
2.7.0, 3.0 up to latest versions |
|
|
|
1.0 up to latest version |
|
|
|
1.0 up to latest version |
|
|
|
1.0 up to latest version |
|
|
|
Swift
|
|
Contact your CSM to become a design partner and get early access |
|
1.0 up to latest version |
|
Gen 1 Engines (Gen 2 Available)
Gen 1 engines for languages that already have a Gen 2 version. These are kept for backwards compatibility and remain the default for existing customers until opting in to Gen 2.
|
Language |
Version |
Configuration Options |
Deprecation Date |
|---|---|---|---|
|
1.0 up to latest version |
|
End of 2026 |
|
|
C# |
1.0 up to latest version |
|
End of 2026 |
|
1.0 up to latest version |
|
May 2027 |
|
|
Java |
1.2 up to latest version |
|
End of 2026 |
|
JavaScript / Node.js |
ECMAScript 3-2018 up to latest version |
|
End of 2026 |
|
Python |
2.7.0, 3.0 up to latest versions |
|
End of 2026 |
|
1.0 up to latest version |
|
August 2027 |
|
|
TypeScript |
1.0 up to latest version |
|
End of 2026 |
Gen 1 Only
|
Language |
Version |
Configuration Options |
|---|---|---|
|
1.0 up to latest version |
|
|
|
1.2 up to latest version |
|
|
|
1.0 up to latest version |
|
|
|
1.0 up to latest version |
|
|
|
1.0 up to latest version |
|
|
|
1.0 up to latest version |
|
|
|
1.0 up to latest version |
|
|
|
1.0 up to latest version |
|
|
|
1.0 up to latest version |
|
|
|
1.0 up to latest version |
|
|
|
2.0 up to latest version |
|
|
|
1.0 up to latest version |
|
|
|
1.0 up to latest version |
|
|
|
1.0 up to latest version |
|
|
|
1.0 up to latest version |
|
|
|
1.0 up to latest version |
|
|
|
1.0 up to latest version |
|
|
|
1.0 up to latest version |
|