Scanning for security vulnerabilities To scan source code for security vulnerabilities, follow the steps in these topics. Configure a scan in AppScan 360° Configuring a scan using AppScan Go! Using the Static Analyzer Command Line Utility Setting up the Static Analyzer Command Line Utility Configuring IRX file generation with the CLI CLI command reference (Windows) CLI command reference (Linux and macOS) Language-specific features Generating an IRX for a .NET Core project Supported .NET source code attributes Parallel processing for Java applications Supported Java source code annotations Managing third-party Java and .NET exclusions SAST scan results Sample Trace Result Fix groups