Tool integration

golangci-lint Integration Guide

Go meta-linter aggregating 100+ linters with SARIF output

Get a Free API Key

Integrate golangci-lint with Vulnetix. Run 100+ Go linters in parallel with native SARIF output for centralized vulnerability management.

CLI toolSARIF

Install & scan

$ go install github.com/golangci/golangci-lint/cmd/golangci-lint@latest
$ golangci-lint run --output.sarif.path=golangci-lint.sarif

Run golangci-lint in CI

Scan on every push and upload the report as a workflow artifact:

- name: Install golangci-lint
  run: go install github.com/golangci/golangci-lint/cmd/golangci-lint@latest
- name: Run golangci-lint
  run: golangci-lint run --output.sarif.path=golangci-lint.sarif
- name: Upload report
  uses: actions/upload-artifact@v6
  with:
    name: golangci-lint
    path: golangci-lint.sarif
    if-no-files-found: warn

Then one publish job hands every artifact in the run to Vulnetix, recorded under golangci-lint's own name and version. Written once per workflow, however many scanners you run:

publish:
  name: Publish to Vulnetix
  runs-on: ubuntu-latest
  needs: [scan]        # every scanner job, or its report is never published
  if: always()         # or one failing scanner suppresses all the others
  permissions:
    contents: read
    actions: read      # required to list the run's artifacts
  env:
    VULNETIX_ORG_ID: ${{ secrets.VULNETIX_ORG_ID }}
    VULNETIX_API_KEY: ${{ secrets.VULNETIX_API_KEY }}
  steps:
    - uses: actions/checkout@v5
    - name: Install Vulnetix CLI
      run: |
        curl -fsSL https://cli.vulnetix.com/install.sh | sh -s -- --install-dir "$HOME/.local/bin"
        echo "$HOME/.local/bin" >> "$GITHUB_PATH"
    - name: Publish scanner reports
      env:
        GITHUB_TOKEN: ${{ github.token }}
      run: vulnetix gha upload --org-id "$VULNETIX_ORG_ID" --json

After the run, vulnetix gha status reports what was actually recorded.

How Vulnetix compares: better together

Vulnetix does not replace golangci-lint. Keep running it. Vulnetix sits on top of golangci-lint (and every other scanner you already own) turning disconnected tool outputs into one prioritised, fixable queue.

golangci-lint is strongest at its core category and also carries features in Secret Scanning, just as Vulnetix spans categories.

CapabilityVulnetixgolangci-lint
Security coverage
SAST (static code analysis)Built-in rules + Semgrep augmentation~ Static Go analysis; security depth comes from bundled gosec/staticcheck, not the default quality linters
SCA / dependencies40+ ecosystems, transitive graph
DAST (dynamic testing)~ Ingests DAST results; no native dynamic engine
Container & imageImage CVEs, base image, Dockerfile
IaC / misconfigurationTerraform, k8s, CloudFormation
Secret scanning1,000+ rules, source + binary + git history~ gosec G101 flags hardcoded credentials in Go source (not a dedicated secret scanner)
Cloud / CSPMCloud-posture findings, compliance tab
Mobile (MAST)~ Ingests mobile scanner output; no native mobile engine
License complianceSPDX, copyleft/AGPL/SSPL policy
SBOM generationCycloneDX 1.7 + SPDX 2.3, cosign-signable
Malware / supply-chainDe-duplicated corpus + install-time firewall (25+ registries)
Network / infra vuln~ Ingests network scanner output; no native network scanner
FuzzingIngests fuzzing crashes; no native fuzzer
Pentest / bug bountyIngests pentest/bug-bounty findings; not a testing service
The Vulnetix orchestration layer
Cross-scanner dedup & one queue (ASPM)Correlates every scanner into one prioritised queue with ownership routing
Exploit-intel prioritisationEPSS, CISA KEV, Coalition ESS, CWSS, Vulnetix LEV
Reachability analysisTree-sitter + CVEAffected; direct/transitive/semantic
Versioned VEX + audit trailImmutable OpenVEX/CycloneDX, cosign-signable
Safe Harbour autofixResolves + applies the nearest safe version
End-of-life policyFlags/blocks past-EOL runtimes & packages
SSVC / risk-based policySSVC v2 + CISA/FedRAMP/Essential-8 presets

✓ full · ~ partial · ✗ not covered

What golangci-lint does well

Where Vulnetix adds to it: Vulnetix ingests golangci-lint/gosec SARIF into its cross-scanner queue, dedups Go findings against SCA/container results, and layers EPSS/KEV/LEV exploit-intel prioritisation, reachability, versioned VEX and SSVC on top. It does not replace golangci-lint as the language-native Go linter; it consolidates and prioritises what golangci-lint produces alongside every other scanner.

No migration, no rip-and-replace. golangci-lint keeps doing what it does best; Vulnetix adds the orchestration, exploit-intelligence prioritisation and remediation layer built for the way AppSec works today.

Centralise golangci-lint results in Vulnetix

Upload golangci-lint SARIF output to the Vulnetix platform to deduplicate findings, prioritise them with EPSS, CISA KEV and Coalition ESS exploit intelligence, and track remediation across every scanner in a single queue.

golangci-lint documentation ↗  ·  Source repository ↗

Wire golangci-lint into your CI/CD pipeline →