Language
|
Extension(s)
|
Reason |
ABAP
|
.abap, .sap
|
Reason under evaluation (RUE)
|
ActionScript
|
.as
|
RUE |
Apex
|
.cls
|
RUE |
ASP
|
.asp
|
RUE |
ASP.NET
|
.aspx, .cshtml, .vbhtml
|
RUE
|
APEX (Oracle)
|
.sql, .xml
|
RUE
|
ASP (aka Classic ASP) / VB
|
.asp, .asa
|
RUE
|
C++
|
.cpp, .hpp, .cxx, .hxx
|
Not for application development
|
CDS (SAP)
|
.cds
|
Not for application development
|
Clojure
|
.clj, .cljs, .cljc
|
RUE
|
COBOL
|
.cbl, .cob |
Not for application development
|
ColdFusion
|
.cfm, .cfc
|
RUE
|
CoffeeScript
|
.coffee
|
RUE
|
Elixir
|
.ex, .exs
|
RUE
|
Fortran
|
.f, .f90, .f95
|
Not for application development |
F#
|
.fs, .fsi, .fsx
|
Not for application development
|
Groovy
|
.groovy, .gvy
|
RUE
|
JSP
|
.jsp, .jspx
|
RUE
|
Node.js
|
.mjs, .cjs
|
RUE
|
Objective-C
|
.m, .mm
|
Not for application development
|
Perl
|
.pl, .pm |
RUE
|
PL/SQL
|
.pls, .sql, .pck
|
Not for application development
|
RPG
|
.rpgle, .rpg, .sqlrpgle
|
Not for application development
|
Rust
|
.rs
|
RUE
|
Scala
|
.scala
|
RUE
|
Transact-SQL
|
.sql
|
Not for application development
|
VB.NET
|
.vb
|
RUE
|
VBScript
|
.vbs
|
Not for application development
|
Visual Basic
|
.vb, .bas, .frm
|
Not for application development
|
Package manager
|
Language/OS/platform
|
Extension(s)/file(s)
|
Reason
|
APT
|
Linux (Debian/Ubuntu)
|
.deb |
Not prioritized
|
Bower
|
JavaScript (Frontend)
|
bower.json
|
Not prioritized
|
Buck
|
Multi-language build tool
|
BUCK
|
Not prioritized
|
Cabal
|
Haskell
|
cabal.project, cabal.project.freeze
|
Not prioritized
|
Carthage
|
iOS (Swift/Objective-C)
|
Cartfile, Cartfile.resolved
|
Not prioritized
|
Chocolatey
|
Windows
|
.nupkg
|
Not prioritized
|
Conda
|
Python, R
|
environment.yml
|
Not prioritized
|
DUB
|
D or dlang
|
dub.json, dub.selections.json
|
Not prioritized
|
Flatpak
|
Linux (Universal Package)
|
.flatpak
|
Not prioritized
|
Homebrew
|
macOS, Linux
|
Formulae, casks
|
Not prioritized
|
Nix
|
NixOS
|
default.nix, shell.nix
|
Not prioritized
|
OPAM
|
OCaml
|
opam
|
Not prioritized
|
Paket
|
.NET/C#
|
paket.dependencies, paket.lock
|
Not prioritized
|
Portage
|
Gentoo Linux
|
ebuild
|
Not prioritized
|
RPM
|
Linux (RedHat/Fedora)
|
.rpm
|
Not prioritized
|
Snap
|
Linux (Universal Package)
|
.snap
|
Not prioritized
|
Spack
|
HPC, Linux
|
Not applicable
|
Not prioritized
|
Stack
|
Haskell
|
stack.yaml, stack.lock
|
Not prioritized
|
Vcpkg
|
C++
|
CONTROL, vcpkg.json
|
Not prioritized
|
Zypper
|
openSUSE, SUSE Linux
|
.rpm
|
Not prioritized
|
Technology
|
Extensions
|
Reason
|
Ansible
|
.yml, .yaml
|
Reason under evaluation (RUE)
|
Azure Blueprints
|
.json, .yaml
|
RUE
|
Helm
|
.yaml, .tpl
|
RUE
|
Technique |
Reason
|
ADR (application detection and response)
|
Reason under evaluation (RUE)
|
Container runtime security
|
RUE
|
Dependency confusion
|
Prone to reporting false positives
|
IAST (interactive application security testing) |
RUE
|