Integrate Orca Security with Vulnetix. Use Orca's shift-left GitHub Actions to scan IaC, containers, and code. Export SARIF findings for upload to Vulnetix.
Run Orca Security in CI
Scan on every push and upload the report as a workflow artifact:
- name: Orca IaC scan
id: orca
uses: orcasecurity/shiftleft-iac-action@v1
with:
api_token: ${{ secrets.ORCA_SECURITY_API_TOKEN }}
project_key: ${{ vars.ORCA_PROJECT_KEY }}
path: "terraform,k8s"
format: sarif
output: results/
- name: Upload report
uses: actions/upload-artifact@v6
with:
name: orca
path: results/iac.sarif
if-no-files-found: warnThen one publish job hands every artifact in the run to Vulnetix, recorded under Orca Security's own name and version. Written once per workflow, however many scanners you run:
publish:
name: Publish to Vulnetix
runs-on: ubuntu-latest
needs: [scan] # every scanner job, or its report is never published
if: always() # or one failing scanner suppresses all the others
permissions:
contents: read
actions: read # required to list the run's artifacts
env:
VULNETIX_ORG_ID: ${{ secrets.VULNETIX_ORG_ID }}
VULNETIX_API_KEY: ${{ secrets.VULNETIX_API_KEY }}
steps:
- uses: actions/checkout@v5
- name: Install Vulnetix CLI
run: |
curl -fsSL https://cli.vulnetix.com/install.sh | sh -s -- --install-dir "$HOME/.local/bin"
echo "$HOME/.local/bin" >> "$GITHUB_PATH"
- name: Publish scanner reports
env:
GITHUB_TOKEN: ${{ github.token }}
run: vulnetix gha upload --org-id "$VULNETIX_ORG_ID" --jsonAfter the run, vulnetix gha status reports what was actually recorded.
How Vulnetix compares: better together
Vulnetix does not replace Orca Security. Keep running it. Vulnetix sits on top of Orca Security (and every other scanner you already own) turning disconnected tool outputs into one prioritised, fixable queue.
Orca Security is strongest at its core category and also carries features in SAST, SCA, IaC & Cloud Configuration, Secret Scanning, Container & Image Scanning, License Compliance, SBOM Generation, just as Vulnetix spans categories.
| Capability | Vulnetix | Orca Security |
|---|---|---|
| Security coverage | ||
| SAST (static code analysis) | ✓ Built-in rules + Semgrep augmentation | ✓ First-party source scanning on every PR/push with AI false-positive triage |
| SCA / dependencies | ✓ 40+ ecosystems, transitive graph | ✓ Open-source dependency scanning across 7 language ecosystems incl. transitive deps |
| DAST (dynamic testing) | ~ Ingests DAST results; no native dynamic engine | ✗ |
| Container & image | ✓ Image CVEs, base image, Dockerfile | ✓ Continuous container-image scanning in registries and CI/CD |
| IaC / misconfiguration | ✓ Terraform, k8s, CloudFormation | ✓ Terraform, CloudFormation, ARM, Google Deployment Manager, Ansible, Kubernetes templates |
| Secret scanning | ✓ 1,000+ rules, source + binary + git history | ✓ Detects exposed keys/tokens/credentials early in SDLC before build/commit |
| Cloud / CSPM | ✓ Cloud-posture findings, compliance tab | ✓ Core: agentless CSPM/CNAPP across AWS, Azure, GCP via SideScanning |
| Mobile (MAST) | ~ Ingests mobile scanner output; no native mobile engine | ✗ |
| License compliance | ✓ SPDX, copyleft/AGPL/SSPL policy | ~ Detects OSS licenses of third-party packages and associated obligations |
| SBOM generation | ✓ CycloneDX 1.7 + SPDX 2.3, cosign-signable | ✓ Generates full SBOM of code repositories including transitive dependencies |
| Malware / supply-chain | ✓ De-duplicated corpus + install-time firewall (25+ registries) | ~ Malware detection across scanned workloads and images (not an install-time package firewall) |
| Network / infra vuln | ~ Ingests network scanner output; no native network scanner | ✗ |
| Fuzzing | ✗ Ingests fuzzing crashes; no native fuzzer | ✗ |
| Pentest / bug bounty | ✗ Ingests pentest/bug-bounty findings; not a testing service | ✗ |
| The Vulnetix orchestration layer | ||
| Cross-scanner dedup & one queue (ASPM) | ✓ Correlates every scanner into one prioritised queue with ownership routing | ~ Unified platform data model + attack-path correlation, but centred on Orca's own scanners |
| Exploit-intel prioritisation | ✓ EPSS, CISA KEV, Coalition ESS, CWSS, Vulnetix LEV | ✓ Ranks findings with EPSS and CISA KEV alongside CVSS |
| Reachability analysis | ✓ Tree-sitter + CVEAffected; direct/transitive/semantic | ✓ Function-level code reachability confirms the vulnerable function is actually called |
| Versioned VEX + audit trail | ✓ Immutable OpenVEX/CycloneDX, cosign-signable | ✗ |
| Safe Harbour autofix | ✓ Resolves + applies the nearest safe version | ✓ AI-driven one-click remediation pull requests |
| End-of-life policy | ✓ Flags/blocks past-EOL runtimes & packages | ✗ |
| SSVC / risk-based policy | ✓ SSVC v2 + CISA/FedRAMP/Essential-8 presets | ✗ |
✓ full · ~ partial · ✗ not covered
What Orca Security does well
- Agentless SideScanning reads workload data directly from cloud API and snapshot data, giving fast, deployment-free coverage across AWS/Azure/GCP with no agents to maintain
- Deep attack-path analysis and unified data model that correlates vulns, misconfigs, secrets, identity and network exposure to prioritise what is truly reachable and exploitable
- Genuine shift-left AppSec suite: SAST, SCA (Ruby/Python/PHP/Node/.NET/Java/Go), IaC (Terraform/CFN/ARM/Ansible/k8s), secrets and full-repo SBOM with transitive deps
- Function-level code reachability plus AI-driven one-click remediation PRs for turning alerts into fixes
Where Vulnetix adds to it: Orca and Vulnetix are complementary: Orca is a strong agentless CNAPP for cloud posture and its own AppSec scanners, and Vulnetix ingests Orca's cloud, container and code findings into a vendor-neutral cross-scanner queue that also consolidates other scanners Orca does not run. On top Vulnetix adds capabilities Orca lacks: immutable versioned VEX with audit trail, explicit EOL and SSVC policy, ESS/CWSS/LEV signals beyond EPSS+KEV, a 25+ registry install-time package firewall, and dual CycloneDX 1.7 + SPDX 2.3 SBOM output.
No migration, no rip-and-replace. Orca Security keeps doing what it does best; Vulnetix adds the orchestration, exploit-intelligence prioritisation and remediation layer built for the way AppSec works today.
Centralise Orca Security results in Vulnetix
Upload Orca Security SARIF, JSON output to the Vulnetix platform to deduplicate findings, prioritise them with EPSS, CISA KEV and Coalition ESS exploit intelligence, and track remediation across every scanner in a single queue.