check and the scanners can produce, and the languages
and file types MergeGuide checks.
Check output formats
mergeguide check supports these formats via --format:
Scanner output formats
mergeguide scan vuln and mergeguide scan iac support text, json, and
sarif:
SBOM formats
mergeguide sbom generate produces these SBOM formats:
See SBOM export.
Supported languages
MergeGuide checks source files in a range of common languages, including:Infrastructure-as-code
The IaC scanner (scan iac) supports Terraform, CloudFormation,
Kubernetes, and Helm. See Running scans.
Language and IaC support evolves. If a language you need isn’t listed, confirm
current coverage against the running CLI before relying on it.
Next steps
Running scans
Produce these outputs.
CI/CD patterns
Feed SARIF into your pipeline.