Tool integration

OSS-Fuzz Integration Guide

Google's free continuous fuzzing service for open-source projects, powered by ClusterFuzz

Get a Free API Key

Integrate OSS-Fuzz with Vulnetix. Onboard your open-source project to receive continuous fuzzing from Google, then monitor and export discovered vulnerabilities for Vulnetix ingestion.

SaaS platformJSON

How Vulnetix compares: better together

Vulnetix does not replace OSS-Fuzz. Keep running it. Vulnetix sits on top of OSS-Fuzz (and every other scanner you already own) turning disconnected tool outputs into one prioritised, fixable queue.

CapabilityVulnetixOSS-Fuzz
Security coverage
SAST (static code analysis)Built-in rules + Semgrep augmentation
SCA / dependencies40+ ecosystems, transitive graph
DAST (dynamic testing)~ Ingests DAST results; no native dynamic engine
Container & imageImage CVEs, base image, Dockerfile
IaC / misconfigurationTerraform, k8s, CloudFormation
Secret scanning1,000+ rules, source + binary + git history
Cloud / CSPMCloud-posture findings, compliance tab
Mobile (MAST)~ Ingests mobile scanner output; no native mobile engine
License complianceSPDX, copyleft/AGPL/SSPL policy
SBOM generationCycloneDX 1.7 + SPDX 2.3, cosign-signable
Malware / supply-chainDe-duplicated corpus + install-time firewall (25+ registries)
Network / infra vuln~ Ingests network scanner output; no native network scanner
FuzzingIngests fuzzing crashes; no native fuzzerContinuous multi-engine fuzzing service (ClusterFuzz) for open-source projects; its core mission.
Pentest / bug bountyIngests pentest/bug-bounty findings; not a testing service
The Vulnetix orchestration layer
Cross-scanner dedup & one queue (ASPM)Correlates every scanner into one prioritised queue with ownership routing~ ClusterFuzz de-duplicates reproducible crashes and files unique bugs, but only within its own fuzzing output, not cross-scanner ASPM consolidation.
Exploit-intel prioritisationEPSS, CISA KEV, Coalition ESS, CWSS, Vulnetix LEV
Reachability analysisTree-sitter + CVEAffected; direct/transitive/semantic
Versioned VEX + audit trailImmutable OpenVEX/CycloneDX, cosign-signable
Safe Harbour autofixResolves + applies the nearest safe version
End-of-life policyFlags/blocks past-EOL runtimes & packages
SSVC / risk-based policySSVC v2 + CISA/FedRAMP/Essential-8 presets

✓ full · ~ partial · ✗ not covered

What OSS-Fuzz does well

Where Vulnetix adds to it: Vulnetix does not run fuzzing and is not a fuzzing service; it ingests and orchestrates OSS-Fuzz/ClusterFuzz crash output as one input among many scanners. Where ClusterFuzz de-duplicates only its own crashes, Vulnetix deduplicates across SAST/SCA/container/secrets/fuzzing into a single prioritised queue with EPSS/KEV/LEV, reachability, versioned VEX, SBOM and autofix. Better together: OSS-Fuzz runs the fuzzers, Vulnetix unifies their findings with the rest of your posture.

No migration, no rip-and-replace. OSS-Fuzz keeps doing what it does best; Vulnetix adds the orchestration, exploit-intelligence prioritisation and remediation layer built for the way AppSec works today.

Centralise OSS-Fuzz results in Vulnetix

Upload OSS-Fuzz JSON output to the Vulnetix platform to deduplicate findings, prioritise them with EPSS, CISA KEV and Coalition ESS exploit intelligence, and track remediation across every scanner in a single queue.

OSS-Fuzz documentation ↗  ·  Source repository ↗

Wire OSS-Fuzz into your CI/CD pipeline →