Weβre very proud to announce the next major release of CAST Highlight, the software intelligence product that enables you to take command of your software portfolio. This version introduces new innovations including: Ask CAST, pre-defined License Risk templates, inferred CVE exclusion, Survey Bulk Import, and many other new capabilities.

Ask CAST – MCP server
Unlock direct, secure access to insights across your software portfolio via your AI of choice with Ask CAST. Powered by MCP, this new capability allows AI assistants and enterprise LLM tools to interact with CAST Highlight data in real time – turning static dashboards into actionable, conversational intelligence.

Survey Bulk Import
Speed up application survey completion by exporting survey questions into a pre-formatted Excel file and re-importing completed answers in bulk. This new capability significantly reduces manual data entry, streamlines collaboration with centralized teams, and makes it easier to enrich code-level insights with the organizational and portfolio context collected through surveys.

Include/Exclude inferred CVEs
Increase vulnerability detection accuracy with a new option to include / exclude CVEs that are inferred. Inferred CVEs are vulnerabilities automatically associated with a component based on name matching against a public software taxonomy (NVD). Because this matching is approximate, results may include CVEs that don’t actually affect your software. They complement Verified CVEs, which come directly from security advisories and are tied to a specific, confirmed version of a component.

Maven native integration
Increase accuracy of SCA results with the Maven package manager now natively supported by the Code Reader and the CLI.

New context-based license risk profiles
Streamline license risk classification with five new customizable, out of the box license risk profiles based on the type of software. New risk profiles include: SaaS, internal applications, mobile apps, and more.

SCA Insights for Rust Third-Party Components (Cargo/Crates.io)
Increase SCA results accuracy with newly added detection of 230K+ components from the crates.io forge. The Code Reader has also been improved to now support dependency detection from the Cargo package manager.

Many other feature improvements
The product team also took the opportunity with this new release to introduce many additional enhancements such as: API endpoints to export reports such as SBOMs, CVE notification filters for advisories only, and much more.