Bring the tools you already run
Vulnetix is not a replacement for your scanners. It is the layer above them. Publish SARIF, CycloneDX or SPDX from any tool and Vulnetix normalises it, attributes it to the tool that produced it, and correlates the findings with exploit intelligence, reachability, EOL status and malware signals.
- Software composition: Trivy, Grype, Syft, OSV-Scanner, OWASP Dependency-Check, npm audit, cdxgen, Dependabot, Snyk Open Source and more.
- Static analysis: Semgrep, CodeQL, gosec, govulncheck, Bandit, Brakeman, PMD, SpotBugs, SonarQube, Checkmarx, Veracode, Fortify.
- Containers & images: Trivy, Grype, Dockle, Hadolint, Clair, Docker Scout, Aqua, Sysdig, Kubescape.
- Infrastructure as code: Checkov, KICS, tfsec, Terrascan, cfn-lint, cfn-nag, Pulumi Policy, Regula.
- Secrets: Gitleaks, TruffleHog, detect-secrets, GitGuardian, GitHub secret scanning.
- Licenses, SBOM & quality: ScanCode, FOSSA, FOSSology, the CycloneDX generators, golangci-lint, ESLint, RuboCop, Ruff, Clippy.
- Compilers & cloud: GCC, Clang, MSVC and rustc diagnostics; Prowler, Wiz, ScoutSuite, Orca and Steampipe posture findings.
Each tool has a ready-made pipeline snippet for every CI/CD platform Vulnetix documents. GitHub Actions, GitLab CI/CD, Bitbucket, Azure DevOps, Jenkins, CircleCI, Buildkite, Drone, Tekton, Argo, AWS CodeBuild, Google Cloud Build, Harness, Codefresh, TeamCity, Bamboo, Docker, Podman, Kubernetes and more.
Live StatusSee what is actually running
Once signed in, every integration shows its real state read from your own scan history: how long since its last snapshot, how many runs in the last 30 days, how many repositories it covers, and whether it runs on every push, daily, or only at release time. Nothing is marked connected because a box was ticked.
Source ControlLink the repositories you scan
Install the Vulnetix GitHub App to link repositories, enrich them with upstream metadata, and write results back where developers work. Installation status is verified against GitHub on every page load, so a revoked or suspended install is visible immediately. GitLab support is coming.
Notification ProvidersFour channels, one workflow
Vulnetix VDB delivers vulnerability finding digests to the tools your team already uses. Connect any combination of the providers below, then decide what gets sent where with notification rules.
Slack
Connect a Slack workspace with a single OAuth authorisation, no webhook URLs to copy or rotate. Vulnetix posts upload digests straight into the channel you authorise.
- One-click OAuth install
- Per-channel routing
- Rich finding summaries
Discord
Paste a Discord channel webhook URL and Vulnetix will deliver finding digests to that channel after each scan upload. Ideal for community and engineering servers.
- Incoming webhook setup
- Channel-scoped delivery
- Formatted digest messages
Google Chat
Add a Google Chat space webhook to receive upload digests in your Google Workspace. Keep security findings visible alongside the rest of your team's conversations.
- Space webhook setup
- Workspace-native delivery
- Formatted digest cards
GitHub Issues
Install the Vulnetix GitHub App and have findings opened as GitHub Issues in the repositories you choose, so remediation lands in the same backlog your developers already track.
- GitHub App install
- Per-repository scope
- Issues created from findings
Decide exactly what gets sent, and where
Connecting a provider is only half of it. Notification rules let you control which findings reach which channels after every scan upload, so the right people see the right risk without alert fatigue.
- Filtered digests: Each rule sends a digest of findings filtered to what matters, delivered automatically after a scan upload completes.
- Flexible scope: Apply a rule org-wide, or scope it down to a single application, a specific version, or an individual upload.
- Multi-provider targeting: One rule can fan out to several connected providers at once, for example, a Slack channel for triage and a GitHub repository for tracking.
- Upload-triggered: Rules evaluate on every new scan result, so your channels always reflect the latest state of your supply chain.
Connect your channels in minutes
Sign in to the Vulnetix VDB to authorise Slack, add Discord or Google Chat webhooks, and configure notification rules. To open findings as GitHub Issues, install the Vulnetix GitHub App on the repositories you want covered. Chat delivery, notification rules, cloud posture and the commercial vendor platforms are Pro features; the scanner catalog and GitHub App status are available on every plan.