Tool integration

Datree Integration Guide

Kubernetes misconfiguration prevention CLI with 100+ built-in rules and offline mode

Get a Free API Key

Integrate Datree with Vulnetix. Scan Kubernetes manifests for misconfigurations and security issues, output results as JSON, and upload to Vulnetix.

SaaS platformJSONJUnit

Install & scan

$ # Homebrew
brew tap datreeio/datree && brew install datree

# Shell script
curl https://get.datree.io | /bin/bash
$ datree test ./manifests/*.yaml --output json 2>&1 | tee datree-report.json

Run Datree in CI

Scan on every push and upload the report as a workflow artifact:

- name: Install Datree
  run: curl https://get.datree.io | /bin/bash

- name: Scan Kubernetes manifests
  run: datree test ./manifests/*.yaml --output json > datree-report.json || true

- name: Upload to Vulnetix
  run: vulnetix upload --file datree-report.json

How Vulnetix compares: better together

Vulnetix does not replace Datree. Keep running it. Vulnetix sits on top of Datree (and every other scanner you already own) turning disconnected tool outputs into one prioritised, fixable queue.

Datree is strongest at its core category and also carries features in Compliance & Policy Engines, just as Vulnetix spans categories.

CapabilityVulnetixDatree
Security coverage
SAST (static code analysis)Built-in rules + Semgrep augmentation
SCA / dependencies40+ ecosystems, transitive graph
DAST (dynamic testing)~ Ingests DAST results; no native dynamic engine
Container & imageImage CVEs, base image, Dockerfile
IaC / misconfigurationTerraform, k8s, CloudFormationCore: validates Kubernetes/Helm manifests against 100+ built-in misconfiguration rules; the commercial SaaS backend closed in July 2023 but the offline CLI remains functional
Secret scanning1,000+ rules, source + binary + git history
Cloud / CSPMCloud-posture findings, compliance tab
Mobile (MAST)~ Ingests mobile scanner output; no native mobile engine
License complianceSPDX, copyleft/AGPL/SSPL policy
SBOM generationCycloneDX 1.7 + SPDX 2.3, cosign-signable
Malware / supply-chainDe-duplicated corpus + install-time firewall (25+ registries)
Network / infra vuln~ Ingests network scanner output; no native network scanner
FuzzingIngests fuzzing crashes; no native fuzzer
Pentest / bug bountyIngests pentest/bug-bounty findings; not a testing service
The Vulnetix orchestration layer
Cross-scanner dedup & one queue (ASPM)Correlates every scanner into one prioritised queue with ownership routing
Exploit-intel prioritisationEPSS, CISA KEV, Coalition ESS, CWSS, Vulnetix LEV
Reachability analysisTree-sitter + CVEAffected; direct/transitive/semantic
Versioned VEX + audit trailImmutable OpenVEX/CycloneDX, cosign-signable
Safe Harbour autofixResolves + applies the nearest safe version
End-of-life policyFlags/blocks past-EOL runtimes & packages
SSVC / risk-based policySSVC v2 + CISA/FedRAMP/Essential-8 presets

✓ full · ~ partial · ✗ not covered

What Datree does well

Where Vulnetix adds to it: Datree is a single-purpose Kubernetes manifest linter, no code, dependency, image or secret scanning, and (since its 2023 SaaS shutdown) no central policy backend or dashboard. Vulnetix provides native IaC misconfiguration detection alongside 13 other scan categories and layers exploit-intel prioritisation, cross-scanner dedup, versioned VEX and SSVC on top. Vulnetix consolidates Datree's manifest findings into one prioritised queue rather than replacing its k8s-linting niche.

No migration, no rip-and-replace. Datree keeps doing what it does best; Vulnetix adds the orchestration, exploit-intelligence prioritisation and remediation layer built for the way AppSec works today.

Centralise Datree results in Vulnetix

Upload Datree JSON, JUnit output to the Vulnetix platform to deduplicate findings, prioritise them with EPSS, CISA KEV and Coalition ESS exploit intelligence, and track remediation across every scanner in a single queue.

Datree documentation ↗  ·  Source repository ↗

Wire Datree into your CI/CD pipeline →