Integrate Datree with Vulnetix. Scan Kubernetes manifests for misconfigurations and security issues, output results as JSON, and upload to Vulnetix.
Install & scan
$ # Homebrew brew tap datreeio/datree && brew install datree # Shell script curl https://get.datree.io | /bin/bash $ datree test ./manifests/*.yaml --output json 2>&1 | tee datree-report.json
Run Datree in CI
Scan on every push and upload the report as a workflow artifact:
- name: Install Datree run: curl https://get.datree.io | /bin/bash - name: Scan Kubernetes manifests run: datree test ./manifests/*.yaml --output json > datree-report.json || true - name: Upload to Vulnetix run: vulnetix upload --file datree-report.json
How Vulnetix compares: better together
Vulnetix does not replace Datree. Keep running it. Vulnetix sits on top of Datree (and every other scanner you already own) turning disconnected tool outputs into one prioritised, fixable queue.
Datree is strongest at its core category and also carries features in Compliance & Policy Engines, just as Vulnetix spans categories.
| Capability | Vulnetix | Datree |
|---|---|---|
| Security coverage | ||
| SAST (static code analysis) | ✓ Built-in rules + Semgrep augmentation | ✗ |
| SCA / dependencies | ✓ 40+ ecosystems, transitive graph | ✗ |
| DAST (dynamic testing) | ~ Ingests DAST results; no native dynamic engine | ✗ |
| Container & image | ✓ Image CVEs, base image, Dockerfile | ✗ |
| IaC / misconfiguration | ✓ Terraform, k8s, CloudFormation | ✓ Core: validates Kubernetes/Helm manifests against 100+ built-in misconfiguration rules; the commercial SaaS backend closed in July 2023 but the offline CLI remains functional |
| Secret scanning | ✓ 1,000+ rules, source + binary + git history | ✗ |
| Cloud / CSPM | ✓ Cloud-posture findings, compliance tab | ✗ |
| Mobile (MAST) | ~ Ingests mobile scanner output; no native mobile engine | ✗ |
| License compliance | ✓ SPDX, copyleft/AGPL/SSPL policy | ✗ |
| SBOM generation | ✓ CycloneDX 1.7 + SPDX 2.3, cosign-signable | ✗ |
| Malware / supply-chain | ✓ De-duplicated corpus + install-time firewall (25+ registries) | ✗ |
| Network / infra vuln | ~ Ingests network scanner output; no native network scanner | ✗ |
| Fuzzing | ✗ Ingests fuzzing crashes; no native fuzzer | ✗ |
| Pentest / bug bounty | ✗ Ingests pentest/bug-bounty findings; not a testing service | ✗ |
| The Vulnetix orchestration layer | ||
| Cross-scanner dedup & one queue (ASPM) | ✓ Correlates every scanner into one prioritised queue with ownership routing | ✗ |
| Exploit-intel prioritisation | ✓ EPSS, CISA KEV, Coalition ESS, CWSS, Vulnetix LEV | ✗ |
| Reachability analysis | ✓ Tree-sitter + CVEAffected; direct/transitive/semantic | ✗ |
| Versioned VEX + audit trail | ✓ Immutable OpenVEX/CycloneDX, cosign-signable | ✗ |
| Safe Harbour autofix | ✓ Resolves + applies the nearest safe version | ✗ |
| End-of-life policy | ✓ Flags/blocks past-EOL runtimes & packages | ✗ |
| SSVC / risk-based policy | ✓ SSVC v2 + CISA/FedRAMP/Essential-8 presets | ✗ |
✓ full · ~ partial · ✗ not covered
What Datree does well
- 100+ built-in Kubernetes misconfiguration rules out of the box, covering workload security, high availability, NSA hardening guidance and ArgoCD best practices
- Combines three checks in one pass: YAML validity, Kubernetes schema validation, and policy evaluation
- Fully local/offline CLI evaluation: manifest contents never leave the machine, so it works air-gapped with no cluster needed
- Helm plugin and custom-rule authoring for policy tailored to an organisation's standards
Where Vulnetix adds to it: Datree is a single-purpose Kubernetes manifest linter, no code, dependency, image or secret scanning, and (since its 2023 SaaS shutdown) no central policy backend or dashboard. Vulnetix provides native IaC misconfiguration detection alongside 13 other scan categories and layers exploit-intel prioritisation, cross-scanner dedup, versioned VEX and SSVC on top. Vulnetix consolidates Datree's manifest findings into one prioritised queue rather than replacing its k8s-linting niche.
No migration, no rip-and-replace. Datree keeps doing what it does best; Vulnetix adds the orchestration, exploit-intelligence prioritisation and remediation layer built for the way AppSec works today.
Centralise Datree results in Vulnetix
Upload Datree JSON, JUnit output to the Vulnetix platform to deduplicate findings, prioritise them with EPSS, CISA KEV and Coalition ESS exploit intelligence, and track remediation across every scanner in a single queue.