Tool integration

cdxgen Integration Guide

OWASP's universal CycloneDX SBOM generator supporting 20+ package managers

Get a Free API Key

Generate CycloneDX or SPDX SBOMs for any project with cdxgen and upload to Vulnetix. Supports npm, pip, Maven, Gradle, Go modules, Cargo, NuGet, Composer, and 20+ more ecosystems.

CLI toolCycloneDXSPDX

Install & scan

$ # Zero-install - run directly with npx
npx @cyclonedx/cdxgen --version

# Or install globally
npm install -g @cyclonedx/cdxgen
$ npx @cyclonedx/cdxgen -o bom.json .

Run cdxgen in CI

Scan on every push and upload the report as a workflow artifact:

- name: Generate SBOM with cdxgen
  run: npx @cyclonedx/cdxgen -o bom.json .

- name: Upload report
  uses: actions/upload-artifact@v6
  with:
    name: cdxgen
    path: bom.json
    if-no-files-found: warn

Then one publish job hands every artifact in the run to Vulnetix, recorded under cdxgen's own name and version. Written once per workflow, however many scanners you run:

publish:
  name: Publish to Vulnetix
  runs-on: ubuntu-latest
  needs: [scan]        # every scanner job, or its report is never published
  if: always()         # or one failing scanner suppresses all the others
  permissions:
    contents: read
    actions: read      # required to list the run's artifacts
  env:
    VULNETIX_ORG_ID: ${{ secrets.VULNETIX_ORG_ID }}
    VULNETIX_API_KEY: ${{ secrets.VULNETIX_API_KEY }}
  steps:
    - uses: actions/checkout@v5
    - name: Install Vulnetix CLI
      run: |
        curl -fsSL https://cli.vulnetix.com/install.sh | sh -s -- --install-dir "$HOME/.local/bin"
        echo "$HOME/.local/bin" >> "$GITHUB_PATH"
    - name: Publish scanner reports
      env:
        GITHUB_TOKEN: ${{ github.token }}
      run: vulnetix gha upload --org-id "$VULNETIX_ORG_ID" --json

After the run, vulnetix gha status reports what was actually recorded.

How Vulnetix compares: better together

Vulnetix does not replace cdxgen. Keep running it. Vulnetix sits on top of cdxgen (and every other scanner you already own) turning disconnected tool outputs into one prioritised, fixable queue.

cdxgen is strongest at its core category and also carries features in SCA, Container & Image Scanning, License Compliance, just as Vulnetix spans categories.

CapabilityVulnetixcdxgen
Security coverage
SAST (static code analysis)Built-in rules + Semgrep augmentation
SCA / dependencies40+ ecosystems, transitive graph~ No native matcher; integrates with OWASP depscan for VDR vulnerability reports
DAST (dynamic testing)~ Ingests DAST results; no native dynamic engine
Container & imageImage CVEs, base image, Dockerfile~ Generates SBOMs from container images and rootfs directories (OBOM)
IaC / misconfigurationTerraform, k8s, CloudFormation
Secret scanning1,000+ rules, source + binary + git history
Cloud / CSPMCloud-posture findings, compliance tab
Mobile (MAST)~ Ingests mobile scanner output; no native mobile engine
License complianceSPDX, copyleft/AGPL/SSPL policy~ Auto-resolves package licenses by querying public registries
SBOM generationCycloneDX 1.7 + SPDX 2.3, cosign-signableCore: universal CycloneDX 1.5-1.7 + SPDX 3.0.1 generator across many ecosystems
Malware / supply-chainDe-duplicated corpus + install-time firewall (25+ registries)
Network / infra vuln~ Ingests network scanner output; no native network scanner
FuzzingIngests fuzzing crashes; no native fuzzer
Pentest / bug bountyIngests pentest/bug-bounty findings; not a testing service
The Vulnetix orchestration layer
Cross-scanner dedup & one queue (ASPM)Correlates every scanner into one prioritised queue with ownership routing
Exploit-intel prioritisationEPSS, CISA KEV, Coalition ESS, CWSS, Vulnetix LEV
Reachability analysisTree-sitter + CVEAffected; direct/transitive/semantic~ Evinse mode emits evidence/call-stack occurrences for select languages
Versioned VEX + audit trailImmutable OpenVEX/CycloneDX, cosign-signable~ VDR/VEX output via depscan integration and CDXA attestation signing; not immutable versioned VEX
Safe Harbour autofixResolves + applies the nearest safe version
End-of-life policyFlags/blocks past-EOL runtimes & packages
SSVC / risk-based policySSVC v2 + CISA/FedRAMP/Essential-8 presets

✓ full · ~ partial · ✗ not covered

What cdxgen does well

Where Vulnetix adds to it: cdxgen is a best-in-class SBOM generator with evidence and depscan-driven vuln reports, but leaves prioritisation, dedup, governance and remediation to other tools. Vulnetix ingests cdxgen SBOMs and layers cross-scanner dedup into one queue, EPSS/KEV/ESS/CWSS/LEV prioritisation, reachability via tree-sitter+CVEAffected, immutable versioned VEX with audit, Safe Harbour autofix, EOL and SSVC, while also authoring its own CycloneDX 1.7 + SPDX 2.3. It consumes cdxgen output as a rich input rather than replacing its generation.

No migration, no rip-and-replace. cdxgen keeps doing what it does best; Vulnetix adds the orchestration, exploit-intelligence prioritisation and remediation layer built for the way AppSec works today.

Centralise cdxgen results in Vulnetix

Upload cdxgen CycloneDX, SPDX output to the Vulnetix platform to deduplicate findings, prioritise them with EPSS, CISA KEV and Coalition ESS exploit intelligence, and track remediation across every scanner in a single queue.

cdxgen documentation ↗  ·  Source repository ↗

Wire cdxgen into your CI/CD pipeline →