Tool integration

OpenText Debricked Integration Guide

SCA from OpenText with developer-first automation and policy enforcement

Get a Free API Key

Integrate OpenText Debricked with Vulnetix. Use the Debricked CLI to scan dependencies and export CycloneDX SBOMs from the Debricked dashboard for upload to Vulnetix.

SaaS platformCycloneDXSPDXSARIFJSON

Run OpenText Debricked in CI

Scan on every push and upload the report as a workflow artifact:

- name: Debricked scan
  uses: debricked/actions@v1
  with:
    integration-id: github-actions
  env:
    DEBRICKED_TOKEN: ${{ secrets.DEBRICKED_TOKEN }}

How Vulnetix compares: better together

Vulnetix does not replace OpenText Debricked. Keep running it. Vulnetix sits on top of OpenText Debricked (and every other scanner you already own) turning disconnected tool outputs into one prioritised, fixable queue.

OpenText Debricked is strongest at its core category and also carries features in License Compliance, SBOM Generation, just as Vulnetix spans categories.

CapabilityVulnetixOpenText Debricked
Security coverage
SAST (static code analysis)✓ Built-in rules + Semgrep augmentation✗
SCA / dependencies✓ 40+ ecosystems, transitive graph✓ Core: ML-assisted dependency vulnerability scanning from lockfiles across ecosystems (now OpenText Core SCA)
DAST (dynamic testing)~ Ingests DAST results; no native dynamic engine✗
Container & image✓ Image CVEs, base image, Dockerfile✗
IaC / misconfiguration✓ Terraform, k8s, CloudFormation✗
Secret scanning✓ 1,000+ rules, source + binary + git history✗
Cloud / CSPM✓ Cloud-posture findings, compliance tab✗
Mobile (MAST)~ Ingests mobile scanner output; no native mobile engine✗
License compliance✓ SPDX, copyleft/AGPL/SSPL policy✓ Full licence-risk management and compliance reporting per dependency
SBOM generation✓ CycloneDX 1.7 + SPDX 2.3, cosign-signable✓ Exports CycloneDX SBOM for supply-chain component records
Malware / supply-chain✓ De-duplicated corpus + install-time firewall (25+ registries)✗
Network / infra vuln~ Ingests network scanner output; no native network scanner✗
Fuzzing✗ Ingests fuzzing crashes; no native fuzzer✗
Pentest / bug bounty✗ Ingests pentest/bug-bounty findings; not a testing service✗
The Vulnetix orchestration layer
Cross-scanner dedup & one queue (ASPM)✓ Correlates every scanner into one prioritised queue with ownership routing~ Automations/policy engine consolidates and gates dependency findings, but scope is Debricked's own SCA data, not cross-scanner ASPM
Exploit-intel prioritisation✓ EPSS, CISA KEV, Coalition ESS, CWSS, Vulnetix LEV~ ML prioritisation correlating exploitability feeds (EPSS-style); CISA KEV/ESS/LEV not a native product pillar
Reachability analysis✓ Tree-sitter + CVEAffected; direct/transitive/semantic✗
Versioned VEX + audit trail✓ Immutable OpenVEX/CycloneDX, cosign-signable✗
Safe Harbour autofix✓ Resolves + applies the nearest safe version✓ Generates CVE-specific and repository-wide fix pull requests updating deps + lockfiles
End-of-life policy✓ Flags/blocks past-EOL runtimes & packages✗
SSVC / risk-based policy✓ SSVC v2 + CISA/FedRAMP/Essential-8 presets✗

✓ full · ~ partial · ✗ not covered

What OpenText Debricked does well

Where Vulnetix adds to it: Debricked is a strong, developer-friendly SCA-plus-licence engine with good fix PRs. Vulnetix does not replace it: it ingests Debricked's CycloneDX/findings, merges them with SAST/IaC/container/secrets/cloud results into a single deduped queue, and adds exploit-intel (EPSS, CISA KEV, Coalition ESS, Vulnetix LEV), reachability, versioned VEX+audit, EOL and SSVC that a pure-SCA tool does not provide.

No migration, no rip-and-replace. OpenText Debricked keeps doing what it does best; Vulnetix adds the orchestration, exploit-intelligence prioritisation and remediation layer built for the way AppSec works today.

Centralise OpenText Debricked results in Vulnetix

Upload OpenText Debricked CycloneDX, SPDX, SARIF, JSON output to the Vulnetix platform to deduplicate findings, prioritise them with EPSS, CISA KEV and Coalition ESS exploit intelligence, and track remediation across every scanner in a single queue.

OpenText Debricked documentation ↗

Wire OpenText Debricked into your CI/CD pipeline →