Generate CycloneDX or SPDX SBOMs for any project with cdxgen and upload to Vulnetix. Supports npm, pip, Maven, Gradle, Go modules, Cargo, NuGet, Composer, and 20+ more ecosystems.
Install & scan
$ # Zero-install - run directly with npx npx @cyclonedx/cdxgen --version # Or install globally npm install -g @cyclonedx/cdxgen $ npx @cyclonedx/cdxgen -o bom.json .
Run cdxgen in CI
Scan on every push and upload the report as a workflow artifact:
- name: Generate SBOM with cdxgen
run: npx @cyclonedx/cdxgen -o bom.json .
- name: Upload report
uses: actions/upload-artifact@v6
with:
name: cdxgen
path: bom.json
if-no-files-found: warnThen one publish job hands every artifact in the run to Vulnetix, recorded under cdxgen's own name and version. Written once per workflow, however many scanners you run:
publish:
name: Publish to Vulnetix
runs-on: ubuntu-latest
needs: [scan] # every scanner job, or its report is never published
if: always() # or one failing scanner suppresses all the others
permissions:
contents: read
actions: read # required to list the run's artifacts
env:
VULNETIX_ORG_ID: ${{ secrets.VULNETIX_ORG_ID }}
VULNETIX_API_KEY: ${{ secrets.VULNETIX_API_KEY }}
steps:
- uses: actions/checkout@v5
- name: Install Vulnetix CLI
run: |
curl -fsSL https://cli.vulnetix.com/install.sh | sh -s -- --install-dir "$HOME/.local/bin"
echo "$HOME/.local/bin" >> "$GITHUB_PATH"
- name: Publish scanner reports
env:
GITHUB_TOKEN: ${{ github.token }}
run: vulnetix gha upload --org-id "$VULNETIX_ORG_ID" --jsonAfter the run, vulnetix gha status reports what was actually recorded.
How Vulnetix compares: better together
Vulnetix does not replace cdxgen. Keep running it. Vulnetix sits on top of cdxgen (and every other scanner you already own) turning disconnected tool outputs into one prioritised, fixable queue.
cdxgen is strongest at its core category and also carries features in SCA, Container & Image Scanning, License Compliance, just as Vulnetix spans categories.
| Capability | Vulnetix | cdxgen |
|---|---|---|
| Security coverage | ||
| SAST (static code analysis) | ✓ Built-in rules + Semgrep augmentation | ✗ |
| SCA / dependencies | ✓ 40+ ecosystems, transitive graph | ~ No native matcher; integrates with OWASP depscan for VDR vulnerability reports |
| DAST (dynamic testing) | ~ Ingests DAST results; no native dynamic engine | ✗ |
| Container & image | ✓ Image CVEs, base image, Dockerfile | ~ Generates SBOMs from container images and rootfs directories (OBOM) |
| IaC / misconfiguration | ✓ Terraform, k8s, CloudFormation | ✗ |
| Secret scanning | ✓ 1,000+ rules, source + binary + git history | ✗ |
| Cloud / CSPM | ✓ Cloud-posture findings, compliance tab | ✗ |
| Mobile (MAST) | ~ Ingests mobile scanner output; no native mobile engine | ✗ |
| License compliance | ✓ SPDX, copyleft/AGPL/SSPL policy | ~ Auto-resolves package licenses by querying public registries |
| SBOM generation | ✓ CycloneDX 1.7 + SPDX 2.3, cosign-signable | ✓ Core: universal CycloneDX 1.5-1.7 + SPDX 3.0.1 generator across many ecosystems |
| Malware / supply-chain | ✓ De-duplicated corpus + install-time firewall (25+ registries) | ✗ |
| Network / infra vuln | ~ Ingests network scanner output; no native network scanner | ✗ |
| Fuzzing | ✗ Ingests fuzzing crashes; no native fuzzer | ✗ |
| Pentest / bug bounty | ✗ Ingests pentest/bug-bounty findings; not a testing service | ✗ |
| The Vulnetix orchestration layer | ||
| Cross-scanner dedup & one queue (ASPM) | ✓ Correlates every scanner into one prioritised queue with ownership routing | ✗ |
| Exploit-intel prioritisation | ✓ EPSS, CISA KEV, Coalition ESS, CWSS, Vulnetix LEV | ✗ |
| Reachability analysis | ✓ Tree-sitter + CVEAffected; direct/transitive/semantic | ~ Evinse mode emits evidence/call-stack occurrences for select languages |
| Versioned VEX + audit trail | ✓ Immutable OpenVEX/CycloneDX, cosign-signable | ~ VDR/VEX output via depscan integration and CDXA attestation signing; not immutable versioned VEX |
| Safe Harbour autofix | ✓ Resolves + applies the nearest safe version | ✗ |
| End-of-life policy | ✓ Flags/blocks past-EOL runtimes & packages | ✗ |
| SSVC / risk-based policy | ✓ SSVC v2 + CISA/FedRAMP/Essential-8 presets | ✗ |
✓ full · ~ partial · ✗ not covered
What cdxgen does well
- OWASP-official universal SBOM generator spanning many package managers and BOM types. SBOM, CBOM (cryptography), OBOM, SaaSBOM, AI-BOM and HBOM
- Broad output support: CycloneDX 1.5-1.7 plus SPDX 3.0.1 JSON-LD export, with validate/sign/verify built in
- Container and rootfs image SBOMs plus automatic license resolution by querying Maven/npm/NuGet registries
- Evinse (evidence) mode adds reachability/call-stack evidence, and depscan integration produces VDR/VEX vulnerability reports
Where Vulnetix adds to it: cdxgen is a best-in-class SBOM generator with evidence and depscan-driven vuln reports, but leaves prioritisation, dedup, governance and remediation to other tools. Vulnetix ingests cdxgen SBOMs and layers cross-scanner dedup into one queue, EPSS/KEV/ESS/CWSS/LEV prioritisation, reachability via tree-sitter+CVEAffected, immutable versioned VEX with audit, Safe Harbour autofix, EOL and SSVC, while also authoring its own CycloneDX 1.7 + SPDX 2.3. It consumes cdxgen output as a rich input rather than replacing its generation.
No migration, no rip-and-replace. cdxgen keeps doing what it does best; Vulnetix adds the orchestration, exploit-intelligence prioritisation and remediation layer built for the way AppSec works today.
Centralise cdxgen results in Vulnetix
Upload cdxgen CycloneDX, SPDX output to the Vulnetix platform to deduplicate findings, prioritise them with EPSS, CISA KEV and Coalition ESS exploit intelligence, and track remediation across every scanner in a single queue.