Integrate OpenText Debricked with Vulnetix. Use the Debricked CLI to scan dependencies and export CycloneDX SBOMs from the Debricked dashboard for upload to Vulnetix.
Run OpenText Debricked in CI
Scan on every push and upload the report as a workflow artifact:
- name: Debricked scan
uses: debricked/actions@v1
with:
integration-id: github-actions
env:
DEBRICKED_TOKEN: ${{ secrets.DEBRICKED_TOKEN }}
How Vulnetix compares: better together
Vulnetix does not replace OpenText Debricked. Keep running it. Vulnetix sits on top of OpenText Debricked (and every other scanner you already own) turning disconnected tool outputs into one prioritised, fixable queue.
OpenText Debricked is strongest at its core category and also carries features in License Compliance, SBOM Generation, just as Vulnetix spans categories.
| Capability | Vulnetix | OpenText Debricked |
|---|---|---|
| Security coverage | ||
| SAST (static code analysis) | ✓ Built-in rules + Semgrep augmentation | ✗ |
| SCA / dependencies | ✓ 40+ ecosystems, transitive graph | ✓ Core: ML-assisted dependency vulnerability scanning from lockfiles across ecosystems (now OpenText Core SCA) |
| DAST (dynamic testing) | ~ Ingests DAST results; no native dynamic engine | ✗ |
| Container & image | ✓ Image CVEs, base image, Dockerfile | ✗ |
| IaC / misconfiguration | ✓ Terraform, k8s, CloudFormation | ✗ |
| Secret scanning | ✓ 1,000+ rules, source + binary + git history | ✗ |
| Cloud / CSPM | ✓ Cloud-posture findings, compliance tab | ✗ |
| Mobile (MAST) | ~ Ingests mobile scanner output; no native mobile engine | ✗ |
| License compliance | ✓ SPDX, copyleft/AGPL/SSPL policy | ✓ Full licence-risk management and compliance reporting per dependency |
| SBOM generation | ✓ CycloneDX 1.7 + SPDX 2.3, cosign-signable | ✓ Exports CycloneDX SBOM for supply-chain component records |
| Malware / supply-chain | ✓ De-duplicated corpus + install-time firewall (25+ registries) | ✗ |
| Network / infra vuln | ~ Ingests network scanner output; no native network scanner | ✗ |
| Fuzzing | ✗ Ingests fuzzing crashes; no native fuzzer | ✗ |
| Pentest / bug bounty | ✗ Ingests pentest/bug-bounty findings; not a testing service | ✗ |
| The Vulnetix orchestration layer | ||
| Cross-scanner dedup & one queue (ASPM) | ✓ Correlates every scanner into one prioritised queue with ownership routing | ~ Automations/policy engine consolidates and gates dependency findings, but scope is Debricked's own SCA data, not cross-scanner ASPM |
| Exploit-intel prioritisation | ✓ EPSS, CISA KEV, Coalition ESS, CWSS, Vulnetix LEV | ~ ML prioritisation correlating exploitability feeds (EPSS-style); CISA KEV/ESS/LEV not a native product pillar |
| Reachability analysis | ✓ Tree-sitter + CVEAffected; direct/transitive/semantic | ✗ |
| Versioned VEX + audit trail | ✓ Immutable OpenVEX/CycloneDX, cosign-signable | ✗ |
| Safe Harbour autofix | ✓ Resolves + applies the nearest safe version | ✓ Generates CVE-specific and repository-wide fix pull requests updating deps + lockfiles |
| End-of-life policy | ✓ Flags/blocks past-EOL runtimes & packages | ✗ |
| SSVC / risk-based policy | ✓ SSVC v2 + CISA/FedRAMP/Essential-8 presets | ✗ |
✓ full · ~ partial · ✗ not covered
What OpenText Debricked does well
- Developer-first workflow: tight GitHub/GitLab/Jira/CLI integration with fast lockfile scanning designed to live in the pull-request loop
- One-click automated fix pull requests that update direct and transitive dependency versions plus lockfiles, including bulk repository-wide remediation
- Machine-learning-based prioritisation and open-source dependency-health scoring to surface the risks worth acting on
- Flexible automations/policy engine that fails pipelines on new high-risk vulns or disallowed licences, with strong CycloneDX SBOM export
Where Vulnetix adds to it: Debricked is a strong, developer-friendly SCA-plus-licence engine with good fix PRs. Vulnetix does not replace it: it ingests Debricked's CycloneDX/findings, merges them with SAST/IaC/container/secrets/cloud results into a single deduped queue, and adds exploit-intel (EPSS, CISA KEV, Coalition ESS, Vulnetix LEV), reachability, versioned VEX+audit, EOL and SSVC that a pure-SCA tool does not provide.
No migration, no rip-and-replace. OpenText Debricked keeps doing what it does best; Vulnetix adds the orchestration, exploit-intelligence prioritisation and remediation layer built for the way AppSec works today.
Centralise OpenText Debricked results in Vulnetix
Upload OpenText Debricked CycloneDX, SPDX, SARIF, JSON output to the Vulnetix platform to deduplicate findings, prioritise them with EPSS, CISA KEV and Coalition ESS exploit intelligence, and track remediation across every scanner in a single queue.