Supported scanners

servasec ingests results from the most popular open source and commercial security scanners. Push findings via API or CI/CD pipeline.

Semgrep•Trivy•Gitleaks•Grype•Snyk•Checkov•TruffleHog•Nuclei•Bandit•Gosec•Kube-bench•Kubescape•npm audit•OSV-Scanner•Tfsec•SARIF•Semgrep•Trivy•Gitleaks•Grype•Snyk•Checkov•TruffleHog•Nuclei•Bandit•Gosec•Kube-bench•Kubescape•npm audit•OSV-Scanner•Tfsec•SARIF•

How ingestion works

Push results

Send scan results to servasec via a simple curl command from your CI/CD pipeline.

Auto-detect scanner

servasec automatically detects the scanner type from file content. No manual configuration needed.

Centralize and track

Findings appear in the dashboard with severity, metadata, and version context.

Compatible formats

SARIFJSONCSV

Scanner categories

SASTSCASecretsContainerIaCKubernetesDAST

Start ingesting today

Self-host servasec and connect your scanners in minutes. AGPLv3 licensed, full data ownership.

Frequently Asked Questions