Integrate Open Policy Agent (OPA) with Vulnetix. Write Rego policies, evaluate them against Kubernetes manifests, Terraform plans, or any JSON/YAML configuration with conftest, and upload results.
Install & scan
$ # OPA binary curl -L -o opa https://openpolicyagent.org/downloads/latest/opa_linux_amd64_static chmod +x opa && sudo mv opa /usr/local/bin/ # conftest (wraps OPA for structured config testing with SARIF output) brew install conftest # or curl -L https://github.com/open-policy-agent/conftest/releases/latest/download/conftest_Linux_x86_64.tar.gz | tar xz && sudo mv conftest /usr/local/bin/ $ conftest test --policy ./policy --output sarif . > opa-results.sarif
Run OPA in CI
Scan on every push and upload the report as a workflow artifact:
- name: Install conftest
run: |
curl -L https://github.com/open-policy-agent/conftest/releases/latest/download/conftest_Linux_x86_64.tar.gz | tar xz
sudo mv conftest /usr/local/bin/
- name: Run OPA policy tests
run: conftest test --policy ./policy --output sarif . > opa-results.sarif
- name: Upload report
uses: actions/upload-artifact@v6
with:
name: opa
path: opa-results.sarif
if-no-files-found: warnThen one publish job hands every artifact in the run to Vulnetix, recorded under OPA's own name and version. Written once per workflow, however many scanners you run:
publish:
name: Publish to Vulnetix
runs-on: ubuntu-latest
needs: [scan] # every scanner job, or its report is never published
if: always() # or one failing scanner suppresses all the others
permissions:
contents: read
actions: read # required to list the run's artifacts
env:
VULNETIX_ORG_ID: ${{ secrets.VULNETIX_ORG_ID }}
VULNETIX_API_KEY: ${{ secrets.VULNETIX_API_KEY }}
steps:
- uses: actions/checkout@v5
- name: Install Vulnetix CLI
run: |
curl -fsSL https://cli.vulnetix.com/install.sh | sh -s -- --install-dir "$HOME/.local/bin"
echo "$HOME/.local/bin" >> "$GITHUB_PATH"
- name: Publish scanner reports
env:
GITHUB_TOKEN: ${{ github.token }}
run: vulnetix gha upload --org-id "$VULNETIX_ORG_ID" --jsonAfter the run, vulnetix gha status reports what was actually recorded.
How Vulnetix compares: better together
Vulnetix does not replace OPA. Keep running it. Vulnetix sits on top of OPA (and every other scanner you already own) turning disconnected tool outputs into one prioritised, fixable queue.
OPA is strongest at its core category and also carries features in IaC & Cloud Configuration, Container & Image Scanning, just as Vulnetix spans categories.
| Capability | Vulnetix | OPA |
|---|---|---|
| Security coverage | ||
| SAST (static code analysis) | ✓ Built-in rules + Semgrep augmentation | ✗ |
| SCA / dependencies | ✓ 40+ ecosystems, transitive graph | ✗ |
| DAST (dynamic testing) | ~ Ingests DAST results; no native dynamic engine | ✗ |
| Container & image | ✓ Image CVEs, base image, Dockerfile | ~ conftest can enforce Dockerfile security policies via custom Rego rules |
| IaC / misconfiguration | ✓ Terraform, k8s, CloudFormation | ~ conftest validates Terraform/CloudFormation/k8s configs against Rego, but ships no built-in misconfig checks (you author the policies) |
| Secret scanning | ✓ 1,000+ rules, source + binary + git history | ✗ |
| Cloud / CSPM | ✓ Cloud-posture findings, compliance tab | ✗ |
| Mobile (MAST) | ~ Ingests mobile scanner output; no native mobile engine | ✗ |
| License compliance | ✓ SPDX, copyleft/AGPL/SSPL policy | ✗ |
| SBOM generation | ✓ CycloneDX 1.7 + SPDX 2.3, cosign-signable | ✗ |
| Malware / supply-chain | ✓ De-duplicated corpus + install-time firewall (25+ registries) | ✗ |
| Network / infra vuln | ~ Ingests network scanner output; no native network scanner | ✗ |
| Fuzzing | ✗ Ingests fuzzing crashes; no native fuzzer | ✗ |
| Pentest / bug bounty | ✗ Ingests pentest/bug-bounty findings; not a testing service | ✗ |
| The Vulnetix orchestration layer | ||
| Cross-scanner dedup & one queue (ASPM) | ✓ Correlates every scanner into one prioritised queue with ownership routing | ✗ |
| Exploit-intel prioritisation | ✓ EPSS, CISA KEV, Coalition ESS, CWSS, Vulnetix LEV | ✗ |
| Reachability analysis | ✓ Tree-sitter + CVEAffected; direct/transitive/semantic | ✗ |
| Versioned VEX + audit trail | ✓ Immutable OpenVEX/CycloneDX, cosign-signable | ✗ |
| Safe Harbour autofix | ✓ Resolves + applies the nearest safe version | ✗ |
| End-of-life policy | ✓ Flags/blocks past-EOL runtimes & packages | ✗ |
| SSVC / risk-based policy | ✓ SSVC v2 + CISA/FedRAMP/Essential-8 presets | ✗ |
✓ full · ~ partial · ✗ not covered
What OPA does well
- General-purpose CNCF-graduated policy engine: one Rego language enforces policy uniformly across IaC, Kubernetes, microservice/API authz and CI gates
- Evaluates policies locally at high speed, making it well suited to CI pipeline gate checks with machine-readable output
- With conftest, tests structured config (Terraform HCL, k8s YAML, Dockerfile, JSON/TOML/CUE, even CycloneDX/SPDX) against custom Rego before deploy
- Fully customer-defined policy: complete control over what is checked and how failures are reported, no vendor-fixed rule library to fight
Where Vulnetix adds to it: OPA is a policy engine, not a vulnerability scanner. It decides on data it is given. Vulnetix runs the actual SAST/SCA/IaC/container/secrets/cloud scanners OPA lacks, then consolidates findings into one prioritised queue with exploit-intel, reachability, VEX and SSVC. The two are complementary: OPA/conftest can gate a pipeline on custom rules while Vulnetix supplies the scan findings and risk scoring that inform those decisions.
No migration, no rip-and-replace. OPA keeps doing what it does best; Vulnetix adds the orchestration, exploit-intelligence prioritisation and remediation layer built for the way AppSec works today.
Centralise OPA results in Vulnetix
Upload OPA JSON, SARIF output to the Vulnetix platform to deduplicate findings, prioritise them with EPSS, CISA KEV and Coalition ESS exploit intelligence, and track remediation across every scanner in a single queue.