Integrate GitGuardian with Vulnetix via the ggshield CLI. Scan git history, files, CI pipelines, and container images for hardcoded secrets. Export findings as SARIF for upload to Vulnetix.
Install & scan
$ # Recommended - run without global install uv run --with ggshield ggshield --version # Install globally with pip pip install ggshield # Or with pipx pipx install ggshield $ # Scan a git repository (full history) ggshield secret scan repo . --output ggshield.sarif --format sarif # Scan current directory files (no git history) ggshield secret scan path . --recursive --output ggshield.sarif --format sarif
Run GitGuardian in CI
Scan on every push and upload the report as a workflow artifact:
- name: GitGuardian Shield scan
uses: GitGuardian/ggshield-action@v1
env:
GITHUB_PUSH_BEFORE_SHA: ${{ github.event.before }}
GITHUB_DEFAULT_BRANCH: ${{ github.event.repository.default_branch }}
GITGUARDIAN_API_KEY: ${{ secrets.GITGUARDIAN_API_KEY }}
with:
args: secret scan ci --format sarif --output ggshield.sarif
- name: Upload report
uses: actions/upload-artifact@v6
with:
name: gitguardian
path: ggshield.sarif
if-no-files-found: warnThen one publish job hands every artifact in the run to Vulnetix, recorded under GitGuardian's own name and version. Written once per workflow, however many scanners you run:
publish:
name: Publish to Vulnetix
runs-on: ubuntu-latest
needs: [scan] # every scanner job, or its report is never published
if: always() # or one failing scanner suppresses all the others
permissions:
contents: read
actions: read # required to list the run's artifacts
env:
VULNETIX_ORG_ID: ${{ secrets.VULNETIX_ORG_ID }}
VULNETIX_API_KEY: ${{ secrets.VULNETIX_API_KEY }}
steps:
- uses: actions/checkout@v5
- name: Install Vulnetix CLI
run: |
curl -fsSL https://cli.vulnetix.com/install.sh | sh -s -- --install-dir "$HOME/.local/bin"
echo "$HOME/.local/bin" >> "$GITHUB_PATH"
- name: Publish scanner reports
env:
GITHUB_TOKEN: ${{ github.token }}
run: vulnetix gha upload --org-id "$VULNETIX_ORG_ID" --jsonAfter the run, vulnetix gha status reports what was actually recorded.
How Vulnetix compares: better together
Vulnetix does not replace GitGuardian. Keep running it. Vulnetix sits on top of GitGuardian (and every other scanner you already own) turning disconnected tool outputs into one prioritised, fixable queue.
GitGuardian is strongest at its core category and also carries features in IaC & Cloud Configuration, SCA, Container & Image Scanning, just as Vulnetix spans categories.
| Capability | Vulnetix | GitGuardian |
|---|---|---|
| Security coverage | ||
| SAST (static code analysis) | ✓ Built-in rules + Semgrep augmentation | ✗ |
| SCA / dependencies | ✓ 40+ ecosystems, transitive graph | ~ Dedicated SCA module (launched 2024): open-source dependency vulnerability detection + SBOM; secondary to its secrets core |
| DAST (dynamic testing) | ~ Ingests DAST results; no native dynamic engine | ✗ |
| Container & image | ✓ Image CVEs, base image, Dockerfile | ~ Scans container images/layers for exposed secrets across the SDLC; not CVE/OCI vuln scanning |
| IaC / misconfiguration | ✓ Terraform, k8s, CloudFormation | ~ ggshield/platform scans IaC files (Terraform/CFN/K8s/Docker) for misconfigurations alongside secrets |
| Secret scanning | ✓ 1,000+ rules, source + binary + git history | ✓ Core: 500+ secret types with validation across SDLC, plus NHI governance and honeytokens |
| Cloud / CSPM | ✓ Cloud-posture findings, compliance tab | ✗ |
| Mobile (MAST) | ~ Ingests mobile scanner output; no native mobile engine | ✗ |
| License compliance | ✓ SPDX, copyleft/AGPL/SSPL policy | ✗ |
| SBOM generation | ✓ CycloneDX 1.7 + SPDX 2.3, cosign-signable | ✗ |
| Malware / supply-chain | ✓ De-duplicated corpus + install-time firewall (25+ registries) | ✗ |
| Network / infra vuln | ~ Ingests network scanner output; no native network scanner | ✗ |
| Fuzzing | ✗ Ingests fuzzing crashes; no native fuzzer | ✗ |
| Pentest / bug bounty | ✗ Ingests pentest/bug-bounty findings; not a testing service | ✗ |
| The Vulnetix orchestration layer | ||
| Cross-scanner dedup & one queue (ASPM) | ✓ Correlates every scanner into one prioritised queue with ownership routing | ✗ |
| Exploit-intel prioritisation | ✓ EPSS, CISA KEV, Coalition ESS, CWSS, Vulnetix LEV | ✗ |
| Reachability analysis | ✓ Tree-sitter + CVEAffected; direct/transitive/semantic | ✗ |
| Versioned VEX + audit trail | ✓ Immutable OpenVEX/CycloneDX, cosign-signable | ✗ |
| Safe Harbour autofix | ✓ Resolves + applies the nearest safe version | ✗ |
| End-of-life policy | ✓ Flags/blocks past-EOL runtimes & packages | ✗ |
| SSVC / risk-based policy | ✓ SSVC v2 + CISA/FedRAMP/Essential-8 presets | ✗ |
✓ full · ~ partial · ✗ not covered
What GitGuardian does well
- Enterprise-grade secret detection at scale: 500+ secret types with high recall plus API validation to confirm active credentials, monitoring source code, CI/CD, containers, IaC files and public GitHub history
- Non-Human Identity (NHI) governance: inventories and tracks machine/service credentials across the org, a maturity level beyond one-off scanning
- Honeytokens: deployable decoy credentials that trigger real-time intrusion alerts (with Slack integration) if an attacker touches them
- ggshield CLI gives developers local pre-commit/pre-push/CI scanning backed by the same detection engine as the platform
Where Vulnetix adds to it: GitGuardian is the enterprise leader for secrets and NHI governance, with real but secondary IaC/SCA/container coverage. Vulnetix does not compete on secret recall. It ingests GitGuardian findings into one cross-scanner queue and deduplicates them against its own SAST/SCA/IaC/container/malware/license scanners. On top it adds exploit-intel prioritisation (EPSS, KEV, ESS, LEV), reachability, immutable versioned VEX + audit, Safe Harbour autofix, EOL and SSVC, the orchestration/ASPM layer GitGuardian doesn't provide. Better together: GitGuardian owns secrets + honeytokens, Vulnetix consolidates and prioritises the whole program.
No migration, no rip-and-replace. GitGuardian keeps doing what it does best; Vulnetix adds the orchestration, exploit-intelligence prioritisation and remediation layer built for the way AppSec works today.
Centralise GitGuardian results in Vulnetix
Upload GitGuardian SARIF, JSON output to the Vulnetix platform to deduplicate findings, prioritise them with EPSS, CISA KEV and Coalition ESS exploit intelligence, and track remediation across every scanner in a single queue.