Supported Languages and Frameworks

Overview

This article contains a table of programming languages supported by Mend SAST.

Mend SAST employs two detection engines:

  • Gen 2 engines are the latest generation of Mend SAST engines. They offer improved precision (fewer false positives), better performance, AI-based remediation suggestions, and support for scan profiles with toggleable low-probability findings.

  • Gen 1 engines are the previous generation. They are actively maintained till the deprecation date, which is one year after the general availability of the corresponding Gen 2 engine. After that, the Gen 1 engine can still be used to preserve consistency, but bugs will no longer be fixed.

Note: Not all programming languages currently benefit from the Gen 2 detection engine, although Mend.io is gradually migrating all languages to Gen 2.

When Mend.io introduces a new detection engine generation, the previous generation remains the default for existing customers to keep results consistent. The engine generation parameters support a gradual rollout, letting you validate the new generation on selected projects before enabling it as the default across the organization. See Configure the Mend CLI for SAST for setting which engine generation to use.

Note: To make a new engine generation the default for an organization, reach out to Mend Support or Customer Success.

Supported Languages Tables

For a list of supported frameworks, CWEs and file extensions per language, please visit the individual language pages.

Gen 2 Engines

Language

Version

Configuration Options

Android Java (coming soon)


Contact your CSM to become a design partner and get early access

C/C++

1.0

up to latest version

  • Custom taint sources/sinks/sanitizers

  • Custom protocols

  • Scan Profiles

  • Toggleable Low Probability Findings

C#

1.0

up to latest version

  • Custom taint sources/sinks/sanitizers

  • Custom protocols

  • Scan Profiles

  • Toggleable Low Probability Findings

Go

1.0

up to latest version

  • Custom taint sources/sinks/sanitizers

  • Custom protocols

  • Scan Profiles

  • Toggleable Low Probability Findings

Java

1.2

up to latest version

  • Custom taint sources/sinks/sanitizers

  • Custom protocols

  • Scan Profiles

  • Toggleable Low Probability Findings

JavaScript / Node.js

ECMAScript 3-2018

up to latest version

  • Custom taint sources/sinks/sanitizers

  • Custom protocols

  • Scan Profiles

  • Toggleable Low Probability Findings

Kotlin

(coming soon)


Contact your CSM to become a design partner and get early access

Kotlin Mobile (coming soon)


Contact your CSM to become a design partner and get early access

PHP
(coming soon)


Contact your CSM to become a design partner and get early access

Python

2.7.0, 3.0

up to latest versions

  • Custom taint sources/sinks/sanitizers

  • Custom protocols

  • Scan Profiles

  • Toggleable Low Probability Findings

Ruby

1.0

up to latest version

  • Custom taint sources/sinks/sanitizers

  • Custom protocols

  • Scan Profiles

  • Toggleable Low Probability Findings

Rust

1.0

up to latest version

  • Custom taint sources/sinks/sanitizers

  • Custom protocols

  • Scan Profiles

  • Toggleable Low Probability Findings

Scala

1.0

up to latest version

  • Custom taint sources/sinks/sanitizers

  • Custom protocols

  • Scan Profiles

  • Toggleable Low Probability Findings

Swift
(coming soon)


Contact your CSM to become a design partner and get early access

TypeScript

1.0

up to latest version

  • Custom taint sources/sinks/sanitizers

  • Custom protocols

  • Scan Profiles

  • Toggleable Low Probability Findings

Gen 1 Engines (Gen 2 Available)

Gen 1 engines for languages that already have a Gen 2 version. These are kept for backwards compatibility and remain the default for existing customers until opting in to Gen 2.

Language

Version

Configuration Options

Deprecation Date

C/C++

1.0

up to latest version

  • Depth settings

  • Custom taint sources/sinks/sanitizers

  • Toggleable predefined taint sources

End of 2026

C#

1.0

up to latest version

  • Depth settings

  • Custom taint sources/sinks/sanitizers

  • Toggleable predefined taint sources

End of 2026

Go

1.0

up to latest version

  • Depth settings

  • Custom taint sources/sinks/sanitizers

  • Toggleable predefined taint sources

May 2027

Java

1.2

up to latest version

  • Depth settings

  • Custom taint sources/sinks/sanitizers

  • Toggleable predefined taint sources

End of 2026

JavaScript / Node.js

ECMAScript 3-2018

up to latest version

  • Depth settings

  • Custom taint sources/sinks/sanitizers

  • Toggleable predefined taint sources

End of 2026

Python

2.7.0, 3.0

up to latest versions

  • Depth settings

  • Custom taint sources/sinks/sanitizers

  • Toggleable predefined taint sources

End of 2026

Ruby

1.0

up to latest version

  • Depth settings

  • Custom taint sources/sinks/sanitizers

  • Toggleable predefined taint sources

August 2027

TypeScript

1.0

up to latest version

  • Depth settings

  • Custom taint sources/sinks/sanitizers

  • Toggleable predefined taint sources

End of 2026

Gen 1 Only

Language

Version

Configuration Options

ABAP

1.0

up to latest version

  • Depth settings

  • Custom taint sources/sinks/sanitizers

  • Toggleable predefined taint sources

Android Java

1.2

up to latest version

  • Depth settings

  • Custom taint sources

APEX

1.0

up to latest version

  • Depth settings

  • Custom taint sources/sinks/sanitizers

  • Toggleable predefined taint sources

ASP Classic/VB Basic/VBScript

1.0

up to latest version

  • Depth settings

  • Custom taint sources/sinks/sanitizers

  • Toggleable predefined taint sources

COBOL

1.0

up to latest version

  • Depth settings

  • Custom taint sources

ColdFusion

1.0

up to latest version

  • Depth settings

  • Custom taint sources/sinks/sanitizers

  • Toggleable predefined taint sources

Groovy

1.0

up to latest version

  • Depth settings

  • Custom taint sources/sinks/sanitizers

  • Toggleable predefined taint sources

iOS Objective C

1.0

up to latest version

  • Depth settings

  • Custom taint sources

Kotlin

1.0

up to latest version

  • Depth settings

  • Custom taint sources/sinks/sanitizers

  • Toggleable predefined taint sources

Kotlin Mobile

1.0

up to latest version

  • Depth settings

  • Custom taint sources/sinks/sanitizers

  • Toggleable predefined taint sources

PHP

2.0

up to latest version

  • Depth settings

  • Custom taint sources/sinks/sanitizers

  • Toggleable predefined taint sources

PLSQL

1.0

up to latest version

  • Depth settings

  • Custom taint sources

R

1.0

up to latest version

  • Depth settings

  • Custom taint sources/sinks/sanitizers

  • Toggleable predefined taint sources

Swift

1.0

up to latest version

  • Depth settings

  • Custom taint sources

VB.Net

1.0

up to latest version

  • Depth settings

  • Custom taint sources/sinks/sanitizers

  • Toggleable predefined taint sources

VBScript

1.0

up to latest version

  • Depth settings

  • Custom taint sources/sinks/sanitizers

  • Toggleable predefined taint sources

Visual Basic

1.0

up to latest version

  • Depth settings

  • Custom taint sources/sinks/sanitizers

  • Toggleable predefined taint sources

Xamarin C#

1.0

up to latest version

  • Depth settings

  • Custom taint sources/sinks/sanitizers

  • Toggleable predefined taint sources