Integrate DevSkim with Vulnetix. Scan code for security anti-patterns across multiple languages. SARIF is the default output format.
Install & scan
$ dotnet tool install --global Microsoft.CST.DevSkim.CLI $ devskim analyze -I /path/to/source -O devskim.sarif
Run DevSkim in CI
Scan on every push and upload the report as a workflow artifact:
- name: Install DevSkim
run: dotnet tool install --global Microsoft.CST.DevSkim.CLI
- name: Run DevSkim
run: devskim analyze -I . -O devskim.sarif
- name: Upload report
uses: actions/upload-artifact@v6
with:
name: devskim
path: devskim.sarif
if-no-files-found: warnThen one publish job hands every artifact in the run to Vulnetix, recorded under DevSkim's own name and version. Written once per workflow, however many scanners you run:
publish:
name: Publish to Vulnetix
runs-on: ubuntu-latest
needs: [scan] # every scanner job, or its report is never published
if: always() # or one failing scanner suppresses all the others
permissions:
contents: read
actions: read # required to list the run's artifacts
env:
VULNETIX_ORG_ID: ${{ secrets.VULNETIX_ORG_ID }}
VULNETIX_API_KEY: ${{ secrets.VULNETIX_API_KEY }}
steps:
- uses: actions/checkout@v5
- name: Install Vulnetix CLI
run: |
curl -fsSL https://cli.vulnetix.com/install.sh | sh -s -- --install-dir "$HOME/.local/bin"
echo "$HOME/.local/bin" >> "$GITHUB_PATH"
- name: Publish scanner reports
env:
GITHUB_TOKEN: ${{ github.token }}
run: vulnetix gha upload --org-id "$VULNETIX_ORG_ID" --jsonAfter the run, vulnetix gha status reports what was actually recorded.
How Vulnetix compares: better together
Vulnetix does not replace DevSkim. Keep running it. Vulnetix sits on top of DevSkim (and every other scanner you already own) turning disconnected tool outputs into one prioritised, fixable queue.
DevSkim is strongest at its core category and also carries features in Secret Scanning, just as Vulnetix spans categories.
| Capability | Vulnetix | DevSkim |
|---|---|---|
| Security coverage | ||
| SAST (static code analysis) | ✓ Built-in rules + Semgrep augmentation | ✓ Core: pattern/regex rules for security anti-patterns (weak crypto like MD5/DES, dangerous APIs, TLS misuse) across 9+ languages |
| SCA / dependencies | ✓ 40+ ecosystems, transitive graph | ✗ |
| DAST (dynamic testing) | ~ Ingests DAST results; no native dynamic engine | ✗ |
| Container & image | ✓ Image CVEs, base image, Dockerfile | ✗ |
| IaC / misconfiguration | ✓ Terraform, k8s, CloudFormation | ✗ |
| Secret scanning | ✓ 1,000+ rules, source + binary + git history | ~ Rules flag hardcoded credentials/keys and cryptographic constants, but it is not a dedicated entropy/secrets scanner |
| Cloud / CSPM | ✓ Cloud-posture findings, compliance tab | ✗ |
| Mobile (MAST) | ~ Ingests mobile scanner output; no native mobile engine | ✗ |
| License compliance | ✓ SPDX, copyleft/AGPL/SSPL policy | ✗ |
| SBOM generation | ✓ CycloneDX 1.7 + SPDX 2.3, cosign-signable | ✗ |
| Malware / supply-chain | ✓ De-duplicated corpus + install-time firewall (25+ registries) | ✗ |
| Network / infra vuln | ~ Ingests network scanner output; no native network scanner | ✗ |
| Fuzzing | ✗ Ingests fuzzing crashes; no native fuzzer | ✗ |
| Pentest / bug bounty | ✗ Ingests pentest/bug-bounty findings; not a testing service | ✗ |
| The Vulnetix orchestration layer | ||
| Cross-scanner dedup & one queue (ASPM) | ✓ Correlates every scanner into one prioritised queue with ownership routing | ✗ |
| Exploit-intel prioritisation | ✓ EPSS, CISA KEV, Coalition ESS, CWSS, Vulnetix LEV | ✗ |
| Reachability analysis | ✓ Tree-sitter + CVEAffected; direct/transitive/semantic | ✗ |
| Versioned VEX + audit trail | ✓ Immutable OpenVEX/CycloneDX, cosign-signable | ✗ |
| Safe Harbour autofix | ✓ Resolves + applies the nearest safe version | ~ Provides inline suggested code fixes for a subset of rules in the IDE |
| End-of-life policy | ✓ Flags/blocks past-EOL runtimes & packages | ✗ |
| SSVC / risk-based policy | ✓ SSVC v2 + CISA/FedRAMP/Essential-8 presets | ✗ |
✓ full · ~ partial · ✗ not covered
What DevSkim does well
- Fast, low-false-positive pattern-based security linting across 9+ languages (C/C++, C#, Java, JS/TS, Python, Go, Ruby, Cobol and more) with no build required
- Inline IDE feedback via VS/VS Code extensions over the Language Server Protocol, squiggles as you type
- Easy-to-author custom rules (JSON) so teams can encode org-specific anti-patterns quickly
- Ships suggested fixes for many rules (e.g. swap weak crypto/deprecated APIs) directly in-editor
Where Vulnetix adds to it: DevSkim is a lightweight in-editor linter; Vulnetix consumes its output and adds cross-scanner dedup into one queue, exploit-intel prioritisation, reachability, versioned VEX and policy (EOL/SSVC) that a single-file pattern linter has no concept of, complementing rather than replacing its fast shift-left feedback.
No migration, no rip-and-replace. DevSkim keeps doing what it does best; Vulnetix adds the orchestration, exploit-intelligence prioritisation and remediation layer built for the way AppSec works today.
Centralise DevSkim results in Vulnetix
Upload DevSkim SARIF output to the Vulnetix platform to deduplicate findings, prioritise them with EPSS, CISA KEV and Coalition ESS exploit intelligence, and track remediation across every scanner in a single queue.