Skip to main content
This page lists the formats check and the scanners can produce, and the languages and file types MergeGuide checks.

Check output formats

mergeguide check supports these formats via --format:

Scanner output formats

mergeguide scan vuln and mergeguide scan iac support text, json, and sarif:

SBOM formats

mergeguide sbom generate produces these SBOM formats: See SBOM export.

Supported languages

MergeGuide checks source files in a range of common languages, including:

Infrastructure-as-code

The IaC scanner (scan iac) supports Terraform, CloudFormation, Kubernetes, and Helm. See Running scans.
Language and IaC support evolves. If a language you need isn’t listed, confirm current coverage against the running CLI before relying on it.

Next steps

Running scans

Produce these outputs.

CI/CD patterns

Feed SARIF into your pipeline.