Overview
This article contains a table of programming languages supported by Mend SAST.
Mend SAST employs two detection engines:
-
Gen2 engines are the latest generation of Mend SAST engines. They offer improved precision (fewer false positives), better performance, AI-based remediation suggestions, and support for scan profiles with toggleable low-probability findings.
-
Gen1 engines are the previous generation. They are still supported and actively maintained but use a different architecture. They support depth-based performance configuration.
Note: Not all programming languages currently benefit from the Gen 2 detection engine, although Mend.io is gradually migrating all languages to Gen 2.
When Mend.io introduces a new detection engine generation, the previous generation remains the default for existing customers to keep results consistent. The engine generation parameters support a gradual rollout, letting you validate the new generation on selected projects before enabling it as the default across the organization. See Configure the Mend CLI for SAST for setting which engine generation to use.
Note: To make a new engine generation the default for an organization, reach out to Mend Support or Customer Success.
Supported Languages Tables
For a list of supported frameworks, CWEs and file extensions per language, please visit the individual language pages.
Gen 2 Engines
|
Language |
Version |
Performance Configuration |
Configurable Predefined Sources |
|---|---|---|---|
|
1.0 up to latest version |
Scan Profiles, Toggleable Low Probability Findings |
No |
|
|
1.0 up to latest version |
Scan Profiles, Toggleable Low Probability Findings |
No |
|
|
1.2 up to latest version |
Scan Profiles, Toggleable Low Probability Findings |
No |
|
|
ECMAScript 3-2018 up to latest version |
Scan Profiles, Toggleable Low Probability Findings |
No |
|
|
PHP (coming soon) |
|
|
|
|
2.7.0, 3.0 up to latest versions |
Scan Profiles, Toggleable Low Probability Findings |
No |
|
|
1.0 up to latest version |
Scan Profiles, Toggleable Low Probability Findings |
No |
|
|
1.0 up to latest version |
Scan Profiles, Toggleable Low Probability Findings |
No |
|
|
1.0 up to latest version |
Scan Profiles, Toggleable Low Probability Findings |
No |
|
|
1.0 up to latest version |
Scan Profiles, Toggleable Low Probability Findings |
No |
Gen 1 Engines (Gen 2 Available)
Gen 1 engines for languages that already have a Gen 2 version. These are kept for backwards compatibility and remain the default for existing customers until opting in to Gen 2.
|
Language |
Version |
Performance Configuration |
Configurable Predefined Sources |
|---|---|---|---|
|
1.0 up to latest version |
Depth Settings |
Yes |
|
|
1.0 up to latest version |
Depth Settings |
Yes |
|
|
1.2 up to latest version |
Depth Settings |
Yes |
|
|
ECMAScript 3-2018 up to latest version |
Depth Settings |
Yes |
|
|
1.0 up to latest version |
Depth Settings |
Yes |
|
|
1.0 up to latest version |
Depth Settings |
Yes |
Gen 1 Only
|
Language |
Version |
Performance Configuration |
Configurable Predefined Sources |
|---|---|---|---|
|
1.0 up to latest version |
Depth Settings |
Yes |
|
|
1.2 up to latest version |
Depth Settings |
No |
|
|
1.0 up to latest version |
Depth Settings |
Yes |
|
|
1.0 up to latest version |
Depth Settings |
Yes |
|
|
1.0 up to latest version |
Depth Settings |
No |
|
|
1.0 up to latest version |
Depth Settings |
Yes |
|
|
1.0 up to latest version |
Depth Settings |
Yes |
|
|
1.0 up to latest version |
Depth Settings |
No |
|
|
1.0 up to latest version |
Depth Settings |
Yes |
|
|
1.0 up to latest version |
Depth Settings |
Yes |
|
|
2.0 up to latest version |
Depth Settings |
Yes |
|
|
1.0 up to latest version |
Depth Settings |
No |
|
|
1.0 up to latest version |
Depth Settings |
Yes |
|
|
1.0 up to latest version |
Depth Settings |
No |
|
|
1.0 up to latest version |
Depth Settings |
Yes |
|
|
1.0 up to latest version |
Depth Settings |
Yes |
|
|
1.0 up to latest version |
Depth Settings |
Yes |
|
|
1.0 up to latest version |
Depth Settings |
Yes |