Supported Languages and Frameworks

Overview

This article contains a table of programming languages supported by Mend SAST.

Mend SAST employs two detection engines:

  • Gen2 engines are the latest generation of Mend SAST engines. They offer improved precision (fewer false positives), better performance, AI-based remediation suggestions, and support for scan profiles with toggleable low-probability findings.

  • Gen1 engines are the previous generation. They are still supported and actively maintained but use a different architecture. They support depth-based performance configuration.

Note: Not all programming languages currently benefit from the Gen 2 detection engine, although Mend.io is gradually migrating all languages to Gen 2.

When Mend.io introduces a new detection engine generation, the previous generation remains the default for existing customers to keep results consistent. The engine generation parameters support a gradual rollout, letting you validate the new generation on selected projects before enabling it as the default across the organization. See Configure the Mend CLI for SAST for setting which engine generation to use.

Note: To make a new engine generation the default for an organization, reach out to Mend Support or Customer Success.

Supported Languages Tables

For a list of supported frameworks, CWEs and file extensions per language, please visit the individual language pages.

Gen 2 Engines

Language

Version

Performance Configuration

Configurable Predefined Sources

C#

1.0

up to latest version

Scan Profiles, Toggleable Low Probability Findings

No

Go

1.0

up to latest version

Scan Profiles, Toggleable Low Probability Findings

No

Java

1.2

up to latest version

Scan Profiles, Toggleable Low Probability Findings

No

JavaScript / Node.js

ECMAScript 3-2018

up to latest version

Scan Profiles, Toggleable Low Probability Findings

No

PHP (coming soon)




Python

2.7.0, 3.0

up to latest versions

Scan Profiles, Toggleable Low Probability Findings

No

Ruby

1.0

up to latest version

Scan Profiles, Toggleable Low Probability Findings

No

Rust

1.0

up to latest version

Scan Profiles, Toggleable Low Probability Findings

No

Scala

1.0

up to latest version

Scan Profiles, Toggleable Low Probability Findings

No

TypeScript

1.0

up to latest version

Scan Profiles, Toggleable Low Probability Findings

No

Gen 1 Engines (Gen 2 Available)

Gen 1 engines for languages that already have a Gen 2 version. These are kept for backwards compatibility and remain the default for existing customers until opting in to Gen 2.

Language

Version

Performance Configuration

Configurable Predefined Sources

C/C++

1.0

up to latest version

Depth Settings

Yes

Go

1.0

up to latest version

Depth Settings

Yes

Java

1.2

up to latest version

Depth Settings

Yes

JavaScript / Node.js

ECMAScript 3-2018

up to latest version

Depth Settings

Yes

Ruby

1.0

up to latest version

Depth Settings

Yes

TypeScript

1.0

up to latest version

Depth Settings

Yes

Gen 1 Only

Language

Version

Performance Configuration

Configurable Predefined Sources

ABAP

1.0

up to latest version

Depth Settings

Yes

Android Java

1.2

up to latest version

Depth Settings

No

APEX

1.0

up to latest version

Depth Settings

Yes

ASP Classic/VB Basic/VBScript

1.0

up to latest version

Depth Settings

Yes

COBOL

1.0

up to latest version

Depth Settings

No

ColdFusion

1.0

up to latest version

Depth Settings

Yes

Groovy

1.0

up to latest version

Depth Settings

Yes

iOS Objective C

1.0

up to latest version

Depth Settings

No

Kotlin

1.0

up to latest version

Depth Settings

Yes

Kotlin Mobile

1.0

up to latest version

Depth Settings

Yes

PHP

2.0

up to latest version

Depth Settings

Yes

PLSQL

1.0

up to latest version

Depth Settings

No

R

1.0

up to latest version

Depth Settings

Yes

Swift

1.0

up to latest version

Depth Settings

No

VB.Net

1.0

up to latest version

Depth Settings

Yes

VBScript

1.0

up to latest version

Depth Settings

Yes

Visual Basic

1.0

up to latest version

Depth Settings

Yes

Xamarin C#

1.0

up to latest version

Depth Settings

Yes