Integrate golangci-lint with Vulnetix. Run 100+ Go linters in parallel with native SARIF output for centralized vulnerability management.
Install & scan
$ go install github.com/golangci/golangci-lint/cmd/golangci-lint@latest $ golangci-lint run --output.sarif.path=golangci-lint.sarif
Run golangci-lint in CI
Scan on every push and upload the report as a workflow artifact:
- name: Install golangci-lint
run: go install github.com/golangci/golangci-lint/cmd/golangci-lint@latest
- name: Run golangci-lint
run: golangci-lint run --output.sarif.path=golangci-lint.sarif
- name: Upload report
uses: actions/upload-artifact@v6
with:
name: golangci-lint
path: golangci-lint.sarif
if-no-files-found: warnThen one publish job hands every artifact in the run to Vulnetix, recorded under golangci-lint's own name and version. Written once per workflow, however many scanners you run:
publish:
name: Publish to Vulnetix
runs-on: ubuntu-latest
needs: [scan] # every scanner job, or its report is never published
if: always() # or one failing scanner suppresses all the others
permissions:
contents: read
actions: read # required to list the run's artifacts
env:
VULNETIX_ORG_ID: ${{ secrets.VULNETIX_ORG_ID }}
VULNETIX_API_KEY: ${{ secrets.VULNETIX_API_KEY }}
steps:
- uses: actions/checkout@v5
- name: Install Vulnetix CLI
run: |
curl -fsSL https://cli.vulnetix.com/install.sh | sh -s -- --install-dir "$HOME/.local/bin"
echo "$HOME/.local/bin" >> "$GITHUB_PATH"
- name: Publish scanner reports
env:
GITHUB_TOKEN: ${{ github.token }}
run: vulnetix gha upload --org-id "$VULNETIX_ORG_ID" --jsonAfter the run, vulnetix gha status reports what was actually recorded.
How Vulnetix compares: better together
Vulnetix does not replace golangci-lint. Keep running it. Vulnetix sits on top of golangci-lint (and every other scanner you already own) turning disconnected tool outputs into one prioritised, fixable queue.
golangci-lint is strongest at its core category and also carries features in Secret Scanning, just as Vulnetix spans categories.
| Capability | Vulnetix | golangci-lint |
|---|---|---|
| Security coverage | ||
| SAST (static code analysis) | ✓ Built-in rules + Semgrep augmentation | ~ Static Go analysis; security depth comes from bundled gosec/staticcheck, not the default quality linters |
| SCA / dependencies | ✓ 40+ ecosystems, transitive graph | ✗ |
| DAST (dynamic testing) | ~ Ingests DAST results; no native dynamic engine | ✗ |
| Container & image | ✓ Image CVEs, base image, Dockerfile | ✗ |
| IaC / misconfiguration | ✓ Terraform, k8s, CloudFormation | ✗ |
| Secret scanning | ✓ 1,000+ rules, source + binary + git history | ~ gosec G101 flags hardcoded credentials in Go source (not a dedicated secret scanner) |
| Cloud / CSPM | ✓ Cloud-posture findings, compliance tab | ✗ |
| Mobile (MAST) | ~ Ingests mobile scanner output; no native mobile engine | ✗ |
| License compliance | ✓ SPDX, copyleft/AGPL/SSPL policy | ✗ |
| SBOM generation | ✓ CycloneDX 1.7 + SPDX 2.3, cosign-signable | ✗ |
| Malware / supply-chain | ✓ De-duplicated corpus + install-time firewall (25+ registries) | ✗ |
| Network / infra vuln | ~ Ingests network scanner output; no native network scanner | ✗ |
| Fuzzing | ✗ Ingests fuzzing crashes; no native fuzzer | ✗ |
| Pentest / bug bounty | ✗ Ingests pentest/bug-bounty findings; not a testing service | ✗ |
| The Vulnetix orchestration layer | ||
| Cross-scanner dedup & one queue (ASPM) | ✓ Correlates every scanner into one prioritised queue with ownership routing | ✗ |
| Exploit-intel prioritisation | ✓ EPSS, CISA KEV, Coalition ESS, CWSS, Vulnetix LEV | ✗ |
| Reachability analysis | ✓ Tree-sitter + CVEAffected; direct/transitive/semantic | ✗ |
| Versioned VEX + audit trail | ✓ Immutable OpenVEX/CycloneDX, cosign-signable | ✗ |
| Safe Harbour autofix | ✓ Resolves + applies the nearest safe version | ✗ |
| End-of-life policy | ✓ Flags/blocks past-EOL runtimes & packages | ✗ |
| SSVC / risk-based policy | ✓ SSVC v2 + CISA/FedRAMP/Essential-8 presets | ✗ |
✓ full · ~ partial · ✗ not covered
What golangci-lint does well
- Go-native meta-linter that runs 100+ analyzers (staticcheck, govet, gosec, revive) in one parallel, cached pass with very low false positives
- Bundles gosec, which does AST/SSA security analysis for 50+ Go weakness classes mapped to CWE (hardcoded creds, weak crypto, SQL injection, command injection)
- First-class CI/editor integration and machine-readable output including native SARIF, JSON, Checkstyle, Code-Climate and JUnit-XML
- Deep Go type-aware analysis and autofix for many linters, tuned as the de-facto standard gate for Go repos
Where Vulnetix adds to it: Vulnetix ingests golangci-lint/gosec SARIF into its cross-scanner queue, dedups Go findings against SCA/container results, and layers EPSS/KEV/LEV exploit-intel prioritisation, reachability, versioned VEX and SSVC on top. It does not replace golangci-lint as the language-native Go linter; it consolidates and prioritises what golangci-lint produces alongside every other scanner.
No migration, no rip-and-replace. golangci-lint keeps doing what it does best; Vulnetix adds the orchestration, exploit-intelligence prioritisation and remediation layer built for the way AppSec works today.
Centralise golangci-lint results in Vulnetix
Upload golangci-lint SARIF output to the Vulnetix platform to deduplicate findings, prioritise them with EPSS, CISA KEV and Coalition ESS exploit intelligence, and track remediation across every scanner in a single queue.