Integrate Aqua Security with Vulnetix. Use Trivy (Aqua's open-source scanner) or the Aqua Platform to scan containers, IaC, and code. Export SARIF or JSON findings for upload to Vulnetix.
Run Aqua Security in CI
Scan on every push and upload the report as a workflow artifact:
- name: Build image
run: docker build -t myapp:${{ github.sha }} .
- name: Trivy container scan
uses: aquasecurity/trivy-action@0.33.1
with:
image-ref: myapp:${{ github.sha }}
format: sarif
output: trivy.sarif
severity: CRITICAL,HIGH
- name: Upload report
uses: actions/upload-artifact@v6
with:
name: aqua-security
path: trivy.sarif
if-no-files-found: warnThen one publish job hands every artifact in the run to Vulnetix, recorded under Aqua Security's own name and version. Written once per workflow, however many scanners you run:
publish:
name: Publish to Vulnetix
runs-on: ubuntu-latest
needs: [scan] # every scanner job, or its report is never published
if: always() # or one failing scanner suppresses all the others
permissions:
contents: read
actions: read # required to list the run's artifacts
env:
VULNETIX_ORG_ID: ${{ secrets.VULNETIX_ORG_ID }}
VULNETIX_API_KEY: ${{ secrets.VULNETIX_API_KEY }}
steps:
- uses: actions/checkout@v5
- name: Install Vulnetix CLI
run: |
curl -fsSL https://cli.vulnetix.com/install.sh | sh -s -- --install-dir "$HOME/.local/bin"
echo "$HOME/.local/bin" >> "$GITHUB_PATH"
- name: Publish scanner reports
env:
GITHUB_TOKEN: ${{ github.token }}
run: vulnetix gha upload --org-id "$VULNETIX_ORG_ID" --jsonAfter the run, vulnetix gha status reports what was actually recorded.
How Vulnetix compares: better together
Vulnetix does not replace Aqua Security. Keep running it. Vulnetix sits on top of Aqua Security (and every other scanner you already own) turning disconnected tool outputs into one prioritised, fixable queue.
Aqua Security is strongest at its core category and also carries features in SCA, IaC & Cloud Configuration, Secret Scanning, SBOM Generation, License Compliance, Cloud Security & CSPM, SAST, just as Vulnetix spans categories.
| Capability | Vulnetix | Aqua Security |
|---|---|---|
| Security coverage | ||
| SAST (static code analysis) | ✓ Built-in rules + Semgrep augmentation | ~ SAST included in Universal Code Scanning, secondary to container/SCA core |
| SCA / dependencies | ✓ 40+ ecosystems, transitive graph | ✓ Trivy dependency scanning + Aqua package risk grading across ecosystems |
| DAST (dynamic testing) | ~ Ingests DAST results; no native dynamic engine | ✗ |
| Container & image | ✓ Image CVEs, base image, Dockerfile | ✓ Core: Trivy + Aqua image scanning, runtime CWPP, KSPM, DTA malware sandbox |
| IaC / misconfiguration | ✓ Terraform, k8s, CloudFormation | ✓ Trivy/Aqua misconfig scanning for Terraform, K8s, CloudFormation |
| Secret scanning | ✓ 1,000+ rules, source + binary + git history | ✓ Trivy + Aqua source and image secret detection |
| Cloud / CSPM | ✓ Cloud-posture findings, compliance tab | ✓ CSPM + KSPM, agentless cloud posture in the Aqua Platform |
| Mobile (MAST) | ~ Ingests mobile scanner output; no native mobile engine | ✗ |
| License compliance | ✓ SPDX, copyleft/AGPL/SSPL policy | ✓ Trivy license analysis in code and images |
| SBOM generation | ✓ CycloneDX 1.7 + SPDX 2.3, cosign-signable | ✓ Trivy generates CycloneDX/SPDX SBOMs; Aqua issues digitally signed SBOMs |
| Malware / supply-chain | ✓ De-duplicated corpus + install-time firewall (25+ registries) | ✓ Supply-chain malware scanning of source + Dynamic Threat Analysis sandbox for images |
| Network / infra vuln | ~ Ingests network scanner output; no native network scanner | ✗ |
| Fuzzing | ✗ Ingests fuzzing crashes; no native fuzzer | ✗ |
| Pentest / bug bounty | ✗ Ingests pentest/bug-bounty findings; not a testing service | ✗ |
| The Vulnetix orchestration layer | ||
| Cross-scanner dedup & one queue (ASPM) | ✓ Correlates every scanner into one prioritised queue with ownership routing | ~ Code-to-cloud correlation links code findings to runtime, but not a broad third-party-scanner ASPM aggregator |
| Exploit-intel prioritisation | ✓ EPSS, CISA KEV, Coalition ESS, CWSS, Vulnetix LEV | ~ Risk-based vulnerability prioritization; KEV/EPSS-style scoring in platform |
| Reachability analysis | ✓ Tree-sitter + CVEAffected; direct/transitive/semantic | ✗ |
| Versioned VEX + audit trail | ✓ Immutable OpenVEX/CycloneDX, cosign-signable | ✗ |
| Safe Harbour autofix | ✓ Resolves + applies the nearest safe version | ✗ |
| End-of-life policy | ✓ Flags/blocks past-EOL runtimes & packages | ✗ |
| SSVC / risk-based policy | ✓ SSVC v2 + CISA/FedRAMP/Essential-8 presets | ✗ |
✓ full · ~ partial · ✗ not covered
What Aqua Security does well
- Trivy is the de-facto open-source universal scanner (containers, IaC, secrets, SBOM, license, filesystem) embedded in thousands of CI/CD pipelines
- Agent-based runtime enforcement and CWPP (Tracee eBPF, Dynamic Threat Analysis sandbox), real runtime blocking, not just scanning
- Unified CNAPP tying code-phase findings to runtime context (CSPM/KSPM + supply-chain assurance) with signed SBOMs and pipeline integrity gates
- Universal Code Scanning across source: SCA package risk grading, SAST, IaC, secrets, license and malware detection with IDE/PR/CI alerts
Where Vulnetix adds to it: Vulnetix ingests Trivy/Aqua output (SCA, container, IaC, secrets, SBOM) and layers a cross-scanner dedup queue, exploit-intel prioritisation (EPSS, KEV, ESS, CWSS, LEV), reachability, immutable versioned VEX, Safe Harbour autofix, EOL and SSVC on top. It does not run Aqua's agent-based runtime enforcement or DTA sandbox, and complements rather than replaces the Aqua Platform.
No migration, no rip-and-replace. Aqua Security keeps doing what it does best; Vulnetix adds the orchestration, exploit-intelligence prioritisation and remediation layer built for the way AppSec works today.
Centralise Aqua Security results in Vulnetix
Upload Aqua Security SARIF, JSON, CycloneDX output to the Vulnetix platform to deduplicate findings, prioritise them with EPSS, CISA KEV and Coalition ESS exploit intelligence, and track remediation across every scanner in a single queue.