What we still need to verify : 2 points in this profile are not yet confirmed against vendor documentation.
- Current language coverage list: verify against vendor documentation
- Integration list and API surface: confirm with vendor
Treat these points as unconfirmed. They are open items in the catalog's verification queue, and this note stays until each is checked against the vendor's documentation.
What it does
CAST Highlight is built for breadth rather than depth. A local agent runs over an application's source tree, computes structural and technology metrics, extracts the component inventory from package manifests and dependency declarations, then uploads results to a hosted portal. The agent deliberately does not send source code, only derived measurements, which is how the vendor makes it palatable to run across dozens or hundreds of applications owned by teams that would never grant a central platform read access to their repositories.
The analysis produces several scores rather than a findings list. Software health covers complexity, documentation and resilience indicators. Open source risk combines vulnerability exposure in declared components with license classification and a view of component obsolescence, meaning how far behind current versions you are and how actively maintained the project is. Cloud readiness flags code patterns that block containerization or managed service migration, such as filesystem dependencies or hardcoded configuration. Those results are aggregated into a portfolio view that supports comparison across applications and business units.
Where it fits
This is not a pipeline tool and it is not aimed at developers. It sits with enterprise architecture, portfolio management, or a CIO office doing modernization planning, with open source risk as one dimension among several. Scans are campaign-based, run once per application on a quarterly or annual cadence, not on every commit. You need a real portfolio, someone who owns application-level decisions, and an appetite for comparative scoring rather than defect remediation.
Strengths
- Scans quickly and without sending source off site, which removes the biggest practical objection to portfolio-wide scanning.
- Covers legacy technologies such as COBOL and ABAP that modern developer-focused scanners ignore.
- Component obsolescence and maintenance signals answer a question pure vulnerability scanners do not: whether a dependency is dying even without a CVE.
- Output is framed for executives making modernization and rationalization decisions, not only for engineers.
Limitations
- Analysis depth is shallow by design. It will not replace a proper composition analysis tool for remediation work, and it does not do dataflow analysis.
- Component detection relies on declared manifests, so vendored or copied code goes uncounted.
- Scoring is comparative and relative. Deciding what an acceptable score is takes internal calibration before the numbers drive anything.
Who it suits
A good fit for large organizations that need to make investment decisions across a wide application estate and want open source risk expressed in the same frame as technical debt and cloud readiness. It is the wrong tool for a product team that needs actionable, per-commit dependency findings, and it will underwhelm an AppSec team looking for a remediation workflow.
Used CAST Highlight? Recommend it under your own name and title.
Recommend this tool