Tool integration

Aqua Security Integration Guide

Full-stack cloud native security platform: use Trivy OSS for CLI scanning

Get a Free API Key

Integrate Aqua Security with Vulnetix. Use Trivy (Aqua's open-source scanner) or the Aqua Platform to scan containers, IaC, and code. Export SARIF or JSON findings for upload to Vulnetix.

SaaS platformSARIFJSONCycloneDX

Run Aqua Security in CI

Scan on every push and upload the report as a workflow artifact:

- name: Build image
  run: docker build -t myapp:${{ github.sha }} .

- name: Trivy container scan
  uses: aquasecurity/trivy-action@0.33.1
  with:
    image-ref: myapp:${{ github.sha }}
    format: sarif
    output: trivy.sarif
    severity: CRITICAL,HIGH

- name: Upload report
  uses: actions/upload-artifact@v6
  with:
    name: aqua-security
    path: trivy.sarif
    if-no-files-found: warn

Then one publish job hands every artifact in the run to Vulnetix, recorded under Aqua Security's own name and version. Written once per workflow, however many scanners you run:

publish:
  name: Publish to Vulnetix
  runs-on: ubuntu-latest
  needs: [scan]        # every scanner job, or its report is never published
  if: always()         # or one failing scanner suppresses all the others
  permissions:
    contents: read
    actions: read      # required to list the run's artifacts
  env:
    VULNETIX_ORG_ID: ${{ secrets.VULNETIX_ORG_ID }}
    VULNETIX_API_KEY: ${{ secrets.VULNETIX_API_KEY }}
  steps:
    - uses: actions/checkout@v5
    - name: Install Vulnetix CLI
      run: |
        curl -fsSL https://cli.vulnetix.com/install.sh | sh -s -- --install-dir "$HOME/.local/bin"
        echo "$HOME/.local/bin" >> "$GITHUB_PATH"
    - name: Publish scanner reports
      env:
        GITHUB_TOKEN: ${{ github.token }}
      run: vulnetix gha upload --org-id "$VULNETIX_ORG_ID" --json

After the run, vulnetix gha status reports what was actually recorded.

How Vulnetix compares: better together

Vulnetix does not replace Aqua Security. Keep running it. Vulnetix sits on top of Aqua Security (and every other scanner you already own) turning disconnected tool outputs into one prioritised, fixable queue.

Aqua Security is strongest at its core category and also carries features in SCA, IaC & Cloud Configuration, Secret Scanning, SBOM Generation, License Compliance, Cloud Security & CSPM, SAST, just as Vulnetix spans categories.

CapabilityVulnetixAqua Security
Security coverage
SAST (static code analysis)✓ Built-in rules + Semgrep augmentation~ SAST included in Universal Code Scanning, secondary to container/SCA core
SCA / dependencies✓ 40+ ecosystems, transitive graph✓ Trivy dependency scanning + Aqua package risk grading across ecosystems
DAST (dynamic testing)~ Ingests DAST results; no native dynamic engine✗
Container & image✓ Image CVEs, base image, Dockerfile✓ Core: Trivy + Aqua image scanning, runtime CWPP, KSPM, DTA malware sandbox
IaC / misconfiguration✓ Terraform, k8s, CloudFormation✓ Trivy/Aqua misconfig scanning for Terraform, K8s, CloudFormation
Secret scanning✓ 1,000+ rules, source + binary + git history✓ Trivy + Aqua source and image secret detection
Cloud / CSPM✓ Cloud-posture findings, compliance tab✓ CSPM + KSPM, agentless cloud posture in the Aqua Platform
Mobile (MAST)~ Ingests mobile scanner output; no native mobile engine✗
License compliance✓ SPDX, copyleft/AGPL/SSPL policy✓ Trivy license analysis in code and images
SBOM generation✓ CycloneDX 1.7 + SPDX 2.3, cosign-signable✓ Trivy generates CycloneDX/SPDX SBOMs; Aqua issues digitally signed SBOMs
Malware / supply-chain✓ De-duplicated corpus + install-time firewall (25+ registries)✓ Supply-chain malware scanning of source + Dynamic Threat Analysis sandbox for images
Network / infra vuln~ Ingests network scanner output; no native network scanner✗
Fuzzing✗ Ingests fuzzing crashes; no native fuzzer✗
Pentest / bug bounty✗ Ingests pentest/bug-bounty findings; not a testing service✗
The Vulnetix orchestration layer
Cross-scanner dedup & one queue (ASPM)✓ Correlates every scanner into one prioritised queue with ownership routing~ Code-to-cloud correlation links code findings to runtime, but not a broad third-party-scanner ASPM aggregator
Exploit-intel prioritisation✓ EPSS, CISA KEV, Coalition ESS, CWSS, Vulnetix LEV~ Risk-based vulnerability prioritization; KEV/EPSS-style scoring in platform
Reachability analysis✓ Tree-sitter + CVEAffected; direct/transitive/semantic✗
Versioned VEX + audit trail✓ Immutable OpenVEX/CycloneDX, cosign-signable✗
Safe Harbour autofix✓ Resolves + applies the nearest safe version✗
End-of-life policy✓ Flags/blocks past-EOL runtimes & packages✗
SSVC / risk-based policy✓ SSVC v2 + CISA/FedRAMP/Essential-8 presets✗

✓ full · ~ partial · ✗ not covered

What Aqua Security does well

Where Vulnetix adds to it: Vulnetix ingests Trivy/Aqua output (SCA, container, IaC, secrets, SBOM) and layers a cross-scanner dedup queue, exploit-intel prioritisation (EPSS, KEV, ESS, CWSS, LEV), reachability, immutable versioned VEX, Safe Harbour autofix, EOL and SSVC on top. It does not run Aqua's agent-based runtime enforcement or DTA sandbox, and complements rather than replaces the Aqua Platform.

No migration, no rip-and-replace. Aqua Security keeps doing what it does best; Vulnetix adds the orchestration, exploit-intelligence prioritisation and remediation layer built for the way AppSec works today.

Centralise Aqua Security results in Vulnetix

Upload Aqua Security SARIF, JSON, CycloneDX output to the Vulnetix platform to deduplicate findings, prioritise them with EPSS, CISA KEV and Coalition ESS exploit intelligence, and track remediation across every scanner in a single queue.

Aqua Security documentation ↗

Wire Aqua Security into your CI/CD pipeline →