What is SARIF?
The SARIF (Static Analysis Results Interchange Format) parser in AppGuard accepts output from any security tool that produces SARIF-compliant output. This covers hundreds of additional scanners beyond the natively supported ones, including tools from Microsoft, GitHub, and many commercial vendors. AppGuard auto-detects and normalizes SARIF results into unified findings.
OASIS SARIF standard supportHundreds of compatible toolsAuto-detection and normalizationNo custom parser neededCI/CD pipeline integration
Integrate SARIF with AppGuard
1
Generate SARIF output
Run your SARIF-compatible tool and output to a .sarif file.
# Example with a SARIF-compatible tool your-tool --sarif -o results.sarif
2
Push to AppGuard
Send the SARIF file to AppGuard.
curl -X POST "$APPGUARD_PUBLIC_URL/api/ingest" \ -H "X-Api-Token: $API_TOKEN" \ -F "[email protected]"
What AppGuard adds to SARIF
Auto-detection
servasec automatically identifies SARIF format and normalizes findings.
Unified dashboard
View SARIF findings alongside native scanner results in one place.
Cross-tool correlation
Correlate SARIF findings with results from other scanners.