Integrate govulncheck with Vulnetix. The official Go tool for finding known vulnerabilities in dependencies, with native SARIF output.
Install & scan
$ go install golang.org/x/vuln/cmd/govulncheck@latest $ govulncheck -format sarif ./... > govulncheck.sarif
Run govulncheck in CI
Scan on every push and upload the report as a workflow artifact:
- name: Install govulncheck
run: go install golang.org/x/vuln/cmd/govulncheck@latest
- name: Run govulncheck
run: govulncheck -format sarif ./... > govulncheck.sarif
- name: Upload report
uses: actions/upload-artifact@v6
with:
name: govulncheck
path: govulncheck.sarif
if-no-files-found: warnThen one publish job hands every artifact in the run to Vulnetix, recorded under govulncheck's own name and version. Written once per workflow, however many scanners you run:
publish:
name: Publish to Vulnetix
runs-on: ubuntu-latest
needs: [scan] # every scanner job, or its report is never published
if: always() # or one failing scanner suppresses all the others
permissions:
contents: read
actions: read # required to list the run's artifacts
env:
VULNETIX_ORG_ID: ${{ secrets.VULNETIX_ORG_ID }}
VULNETIX_API_KEY: ${{ secrets.VULNETIX_API_KEY }}
steps:
- uses: actions/checkout@v5
- name: Install Vulnetix CLI
run: |
curl -fsSL https://cli.vulnetix.com/install.sh | sh -s -- --install-dir "$HOME/.local/bin"
echo "$HOME/.local/bin" >> "$GITHUB_PATH"
- name: Publish scanner reports
env:
GITHUB_TOKEN: ${{ github.token }}
run: vulnetix gha upload --org-id "$VULNETIX_ORG_ID" --jsonAfter the run, vulnetix gha status reports what was actually recorded.
How Vulnetix compares: better together
Vulnetix does not replace govulncheck. Keep running it. Vulnetix sits on top of govulncheck (and every other scanner you already own) turning disconnected tool outputs into one prioritised, fixable queue.
govulncheck is strongest at its core category and also carries features in SAST, just as Vulnetix spans categories.
| Capability | Vulnetix | govulncheck |
|---|---|---|
| Security coverage | ||
| SAST (static code analysis) | ✓ Built-in rules + Semgrep augmentation | ~ Performs static call-graph analysis of source, but only to determine vuln reachability, not general code-quality SAST |
| SCA / dependencies | ✓ 40+ ecosystems, transitive graph | ✓ Core: matches Go module dependencies against the Go vuln DB (OSV) |
| DAST (dynamic testing) | ~ Ingests DAST results; no native dynamic engine | ✗ |
| Container & image | ✓ Image CVEs, base image, Dockerfile | ✗ |
| IaC / misconfiguration | ✓ Terraform, k8s, CloudFormation | ✗ |
| Secret scanning | ✓ 1,000+ rules, source + binary + git history | ✗ |
| Cloud / CSPM | ✓ Cloud-posture findings, compliance tab | ✗ |
| Mobile (MAST) | ~ Ingests mobile scanner output; no native mobile engine | ✗ |
| License compliance | ✓ SPDX, copyleft/AGPL/SSPL policy | ✗ |
| SBOM generation | ✓ CycloneDX 1.7 + SPDX 2.3, cosign-signable | ✗ |
| Malware / supply-chain | ✓ De-duplicated corpus + install-time firewall (25+ registries) | ✗ |
| Network / infra vuln | ~ Ingests network scanner output; no native network scanner | ✗ |
| Fuzzing | ✗ Ingests fuzzing crashes; no native fuzzer | ✗ |
| Pentest / bug bounty | ✗ Ingests pentest/bug-bounty findings; not a testing service | ✗ |
| The Vulnetix orchestration layer | ||
| Cross-scanner dedup & one queue (ASPM) | ✓ Correlates every scanner into one prioritised queue with ownership routing | ✗ |
| Exploit-intel prioritisation | ✓ EPSS, CISA KEV, Coalition ESS, CWSS, Vulnetix LEV | ✗ |
| Reachability analysis | ✓ Tree-sitter + CVEAffected; direct/transitive/semantic | ✓ Symbol/function-level reachability is its defining feature |
| Versioned VEX + audit trail | ✓ Immutable OpenVEX/CycloneDX, cosign-signable | ~ Can output OpenVEX statements, but not immutable versioned VEX with audit history |
| Safe Harbour autofix | ✓ Resolves + applies the nearest safe version | ✗ |
| End-of-life policy | ✓ Flags/blocks past-EOL runtimes & packages | ✗ |
| SSVC / risk-based policy | ✓ SSVC v2 + CISA/FedRAMP/Essential-8 presets | ✗ |
✓ full · ~ partial · ✗ not covered
What govulncheck does well
- Symbol-level reachability: only reports vulnerabilities in functions your code can actually reach, cutting Go SCA false positives dramatically
- Authoritative Go vulnerability database (vuln.go.dev, OSV format) curated by the Go security team at Google
- Scans both source trees and compiled binaries (-mode binary), useful for auditing artifacts you did not build
- Emits SARIF and OpenVEX output, integrating cleanly into code scanning and VEX pipelines
Where Vulnetix adds to it: Vulnetix does SCA across 40+ ecosystems (govulncheck is Go-only) and provides its own reachability (tree-sitter + CVEAffected). It ingests govulncheck's Go-specific symbol-level results, folds them into cross-scanner dedup, and adds EPSS/KEV/ESS/LEV prioritisation, immutable versioned VEX + audit, EOL/SSVC policy and Safe Harbour autofix that govulncheck (report-only) lacks.
No migration, no rip-and-replace. govulncheck keeps doing what it does best; Vulnetix adds the orchestration, exploit-intelligence prioritisation and remediation layer built for the way AppSec works today.
Centralise govulncheck results in Vulnetix
Upload govulncheck SARIF output to the Vulnetix platform to deduplicate findings, prioritise them with EPSS, CISA KEV and Coalition ESS exploit intelligence, and track remediation across every scanner in a single queue.