Tool integration

Aqua Security Integration Guide

Full-stack cloud native security platform: use Trivy OSS for CLI scanning

Get a Free API Key

Integrate Aqua Security with Vulnetix. Use Trivy (Aqua's open-source scanner) or the Aqua Platform to scan containers, IaC, and code. Export SARIF or JSON findings for upload to Vulnetix.

SaaS platformSARIFJSONCycloneDX

Run Aqua Security in CI

Scan on every push and upload the report as a workflow artifact:

- name: Build image
  run: docker build -t myapp:${{ github.sha }} .

- name: Trivy container scan
  uses: aquasecurity/trivy-action@0.33.1
  with:
    image-ref: myapp:${{ github.sha }}
    format: sarif
    output: trivy.sarif
    severity: CRITICAL,HIGH

- name: Upload report
  uses: actions/upload-artifact@v6
  with:
    name: aqua-security
    path: trivy.sarif
    if-no-files-found: warn

Then one publish job hands every artifact in the run to Vulnetix, recorded under Aqua Security's own name and version. Written once per workflow, however many scanners you run:

publish:
  name: Publish to Vulnetix
  runs-on: ubuntu-latest
  needs: [scan]        # every scanner job, or its report is never published
  if: always()         # or one failing scanner suppresses all the others
  permissions:
    contents: read
    actions: read      # required to list the run's artifacts
  env:
    VULNETIX_ORG_ID: ${{ secrets.VULNETIX_ORG_ID }}
    VULNETIX_API_KEY: ${{ secrets.VULNETIX_API_KEY }}
  steps:
    - uses: actions/checkout@v5
    - name: Install Vulnetix CLI
      run: |
        curl -fsSL https://cli.vulnetix.com/install.sh | sh -s -- --install-dir "$HOME/.local/bin"
        echo "$HOME/.local/bin" >> "$GITHUB_PATH"
    - name: Publish scanner reports
      env:
        GITHUB_TOKEN: ${{ github.token }}
      run: vulnetix gha upload --org-id "$VULNETIX_ORG_ID" --json

After the run, vulnetix gha status reports what was actually recorded.

How Vulnetix compares: better together

Vulnetix does not replace Aqua Security. Keep running it. Vulnetix sits on top of Aqua Security (and every other scanner you already own) turning disconnected tool outputs into one prioritised, fixable queue.

Aqua Security is strongest at its core category and also carries features in SCA, IaC & Cloud Configuration, Secret Scanning, SBOM Generation, License Compliance, Cloud Security & CSPM, SAST, just as Vulnetix spans categories.

CapabilityVulnetixAqua Security
Security coverage
SAST (static code analysis)Built-in rules + Semgrep augmentation~ SAST included in Universal Code Scanning, secondary to container/SCA core
SCA / dependencies40+ ecosystems, transitive graphTrivy dependency scanning + Aqua package risk grading across ecosystems
DAST (dynamic testing)~ Ingests DAST results; no native dynamic engine
Container & imageImage CVEs, base image, DockerfileCore: Trivy + Aqua image scanning, runtime CWPP, KSPM, DTA malware sandbox
IaC / misconfigurationTerraform, k8s, CloudFormationTrivy/Aqua misconfig scanning for Terraform, K8s, CloudFormation
Secret scanning1,000+ rules, source + binary + git historyTrivy + Aqua source and image secret detection
Cloud / CSPMCloud-posture findings, compliance tabCSPM + KSPM, agentless cloud posture in the Aqua Platform
Mobile (MAST)~ Ingests mobile scanner output; no native mobile engine
License complianceSPDX, copyleft/AGPL/SSPL policyTrivy license analysis in code and images
SBOM generationCycloneDX 1.7 + SPDX 2.3, cosign-signableTrivy generates CycloneDX/SPDX SBOMs; Aqua issues digitally signed SBOMs
Malware / supply-chainDe-duplicated corpus + install-time firewall (25+ registries)Supply-chain malware scanning of source + Dynamic Threat Analysis sandbox for images
Network / infra vuln~ Ingests network scanner output; no native network scanner
FuzzingIngests fuzzing crashes; no native fuzzer
Pentest / bug bountyIngests pentest/bug-bounty findings; not a testing service
The Vulnetix orchestration layer
Cross-scanner dedup & one queue (ASPM)Correlates every scanner into one prioritised queue with ownership routing~ Code-to-cloud correlation links code findings to runtime, but not a broad third-party-scanner ASPM aggregator
Exploit-intel prioritisationEPSS, CISA KEV, Coalition ESS, CWSS, Vulnetix LEV~ Risk-based vulnerability prioritization; KEV/EPSS-style scoring in platform
Reachability analysisTree-sitter + CVEAffected; direct/transitive/semantic
Versioned VEX + audit trailImmutable OpenVEX/CycloneDX, cosign-signable
Safe Harbour autofixResolves + applies the nearest safe version
End-of-life policyFlags/blocks past-EOL runtimes & packages
SSVC / risk-based policySSVC v2 + CISA/FedRAMP/Essential-8 presets

✓ full · ~ partial · ✗ not covered

What Aqua Security does well

Where Vulnetix adds to it: Vulnetix ingests Trivy/Aqua output (SCA, container, IaC, secrets, SBOM) and layers a cross-scanner dedup queue, exploit-intel prioritisation (EPSS, KEV, ESS, CWSS, LEV), reachability, immutable versioned VEX, Safe Harbour autofix, EOL and SSVC on top. It does not run Aqua's agent-based runtime enforcement or DTA sandbox, and complements rather than replaces the Aqua Platform.

No migration, no rip-and-replace. Aqua Security keeps doing what it does best; Vulnetix adds the orchestration, exploit-intelligence prioritisation and remediation layer built for the way AppSec works today.

Centralise Aqua Security results in Vulnetix

Upload Aqua Security SARIF, JSON, CycloneDX output to the Vulnetix platform to deduplicate findings, prioritise them with EPSS, CISA KEV and Coalition ESS exploit intelligence, and track remediation across every scanner in a single queue.

Aqua Security documentation ↗

Wire Aqua Security into your CI/CD pipeline →