INTRODUCTION
OpenText Static Application Security Testing 26.1 is a structural release for enterprise AppSec programs. It expands language coverage, introduces AI-powered SAST, updates mobile and Python support, and changes how teams deploy and govern scanning infrastructure. For large organizations managing hundreds of applications, this release supports broader risk coverage, clearer governance, and better alignment between security tooling and modern delivery platforms.
WHY THIS RELEASE MATTERS FOR ENTERPRISE DEVSECOPS
Enterprise security leaders care about three outcomes: coverage, control, and delivery velocity. OpenText SAST 26.1 moves the platform forward on all three.
Strategic outcomes:
- Broader SAST coverage across modern, legacy, and scripting languages
- Improved governance and audit posture for mobile, IaC, and Ruby workloads
- Clearer separation of central and distributed scanning components
- Better alignment with current build tools and runtimes
EXPANDED LANGUAGE SUPPORT AND PYTHON 3.14
OpenText SAST 26.1 adds Python 3.14 support and expands coverage through its AI-powered engine.
Enterprise impact:
- Reduces blind spots in data pipelines, integration services, and internal tools
- Allows security testing to stay aligned with runtime upgrades
- Supports evidence-based risk approvals for platform modernization
Operational value:
- Developers upgrade Python without waiting on tooling changes
- CI pipelines remain stable during runtime transitions
- QA and DevSecOps teams avoid parallel pipelines per language version
AI-POWERED SAST FOR 12 ADDITIONAL LANGUAGES
The new AI-powered analyzer extends coverage to Ada, Bash, Delphi, Elixir, Erlang, Groovy, Lua, Perl, PowerShell, R, Ruby, and Rust.
Enterprise impact:
- Brings legacy and scripting code into formal SAST governance
- Improves board-level reporting on portfolio security coverage
- Reduces unscanned attack surface in admin and automation layers
Operational value:
- DevOps teams scan Bash, PowerShell, and Groovy pipelines using the same policies
- Data and analytics teams scan R and Python assets without separate tools
- Security teams centralize reporting and triage across mixed stacks
IOS AND MAC OS TOOLCHAIN ALIGNMENT
Support for xcodebuild 26.1.1 replaces older Xcode versions.
Enterprise impact:
- Keeps mobile security aligned with current Apple tooling
- Maintains audit-ready SAST evidence for mobile releases
- Avoids governance gaps during Xcode upgrades
Operational value:
- iOS teams update Xcode without breaking SAST
- CI teams standardize mobile build images
- Release managers maintain predictable mobile security gates
AI-POWERED SAST FOR RUBY AND DEPRECATION OF LOCAL ANALYSIS
Traditional Ruby analysis is deprecated in favor of AI-powered SAST.
Enterprise impact:
- Signals a long-term shift toward AI-based static analysis
- Requires governance updates for Ruby SDLC standards
- Introduces reporting differences that must be documented
Operational value:
- Better detection for dynamic Ruby patterns
- Simplified ruleset management after migration
- Centralized SAST workflows for Ruby services
OPERATIONAL CONSTRAINTS THAT AFFECT GOVERNANCE
Some languages require dependency downloads at scan time. Ruby snippets are not embedded in FPR files. Some Xcode builds may miss files due to architecture mismatches.
Enterprise impact:
- Requires network and dependency caching strategies
- Affects audit metrics such as file counts
- Demands standardized mobile build configurations
Operational value:
- More reliable IaC and smart contract scans
- Fewer incomplete scan results
- Clear expectations during findings triage
PRODUCT RENAMING AND DOCUMENTATION CHANGES
The Fortify portfolio is now branded as OpenText SAST, DAST, Core SCA, and Core Application Security.
Enterprise impact:
- Cleaner contract and vendor governance
- Easier mapping to internal control catalogs
- Improved upgrade and change planning
Operational value:
- Simpler documentation for platform teams
- Clearer product references in CI/CD pipelines
- Reduced confusion across delivery teams
SCANCENTRAL CLIENT SEPARATION
The ScanCentral SAST client is no longer bundled with the core installer.
Enterprise impact:
- Improves lifecycle control of distributed sensors
- Supports regulated and multi-tenant deployment models
- Enables independent upgrade cadences
Operational value:
- Smaller CI agent images
- Predictable rollout and rollback plans
- Cleaner separation of platform and build tooling
DEPRECATED BUILD TOOL SUPPORT
Support is removed for Ant 1.9.x and older xcodebuild versions.
Enterprise impact:
- Creates a vendor-backed case for modernization
- Reduces maintenance complexity
- Improves platform stability
Operational value:
- Standardized CI runners
- Fewer edge case failures
- Lower support overhead
WHAT THIS MEANS FOR C-LEVEL LEADERS
OpenText SAST 26.1 strengthens SAST as a business control, not just a developer tool.
Strategic value:
- Broader risk coverage across the application estate
- Stronger audit posture for mobile and scripting layers
- Clearer modernization roadmap for legacy pipelines
- Improved alignment between security investment and risk posture
HOW MERITO HELPS ENTERPRISES OPERATIONALIZE OPENTEXT SAST
Merito acts as a Value-Added Partner for enterprises adopting OpenText SAST.
Our focus areas:
- Portfolio-wide SAST architecture design
- AI-powered SAST rollout planning
- CI/CD and ScanCentral integration
- Governance and audit alignment
- SDLC policy updates
- Executive risk dashboards



