Integrate Regula with Vulnetix. Check Terraform, CloudFormation, Kubernetes, and ARM templates against OPA Rego rules. Note: Regula was archived Sept 2024; consider Trivy IaC or Checkov for new projects.
Install & scan
$ # Homebrew (macOS/Linux): last release v3.4.0 brew tap fugue/regula brew install regula # Binary download curl -L https://github.com/fugue/regula/releases/latest/download/regula_Linux_x86_64.tar.gz | tar xz sudo mv regula /usr/local/bin/ $ regula run . --format sarif > regula.sarif
Run Regula in CI
Scan on every push and upload the report as a workflow artifact:
- name: Run Regula IaC scan
run: |
curl -L https://github.com/fugue/regula/releases/latest/download/regula_Linux_x86_64.tar.gz | tar xz
sudo mv regula /usr/local/bin/
regula run . --format sarif > regula.sarif
- name: Upload report
uses: actions/upload-artifact@v6
with:
name: regula
path: regula.sarif
if-no-files-found: warnThen one publish job hands every artifact in the run to Vulnetix, recorded under Regula's own name and version. Written once per workflow, however many scanners you run:
publish:
name: Publish to Vulnetix
runs-on: ubuntu-latest
needs: [scan] # every scanner job, or its report is never published
if: always() # or one failing scanner suppresses all the others
permissions:
contents: read
actions: read # required to list the run's artifacts
env:
VULNETIX_ORG_ID: ${{ secrets.VULNETIX_ORG_ID }}
VULNETIX_API_KEY: ${{ secrets.VULNETIX_API_KEY }}
steps:
- uses: actions/checkout@v5
- name: Install Vulnetix CLI
run: |
curl -fsSL https://cli.vulnetix.com/install.sh | sh -s -- --install-dir "$HOME/.local/bin"
echo "$HOME/.local/bin" >> "$GITHUB_PATH"
- name: Publish scanner reports
env:
GITHUB_TOKEN: ${{ github.token }}
run: vulnetix gha upload --org-id "$VULNETIX_ORG_ID" --jsonAfter the run, vulnetix gha status reports what was actually recorded.
How Vulnetix compares: better together
Vulnetix does not replace Regula. Keep running it. Vulnetix sits on top of Regula (and every other scanner you already own) turning disconnected tool outputs into one prioritised, fixable queue.
Regula is strongest at its core category and also carries features in Compliance & Policy Engines, just as Vulnetix spans categories.
| Capability | Vulnetix | Regula |
|---|---|---|
| Security coverage | ||
| SAST (static code analysis) | ✓ Built-in rules + Semgrep augmentation | ✗ |
| SCA / dependencies | ✓ 40+ ecosystems, transitive graph | ✗ |
| DAST (dynamic testing) | ~ Ingests DAST results; no native dynamic engine | ✗ |
| Container & image | ✓ Image CVEs, base image, Dockerfile | ~ Only via Kubernetes manifest checks (privileged/pod-security); no image/OCI layer scanning |
| IaC / misconfiguration | ✓ Terraform, k8s, CloudFormation | ✓ Core: Rego rules over Terraform/CFN/K8s/ARM for misconfig and compliance violations |
| Secret scanning | ✓ 1,000+ rules, source + binary + git history | ✗ |
| Cloud / CSPM | ✓ Cloud-posture findings, compliance tab | ✗ |
| Mobile (MAST) | ~ Ingests mobile scanner output; no native mobile engine | ✗ |
| License compliance | ✓ SPDX, copyleft/AGPL/SSPL policy | ✗ |
| SBOM generation | ✓ CycloneDX 1.7 + SPDX 2.3, cosign-signable | ✗ |
| Malware / supply-chain | ✓ De-duplicated corpus + install-time firewall (25+ registries) | ✗ |
| Network / infra vuln | ~ Ingests network scanner output; no native network scanner | ✗ |
| Fuzzing | ✗ Ingests fuzzing crashes; no native fuzzer | ✗ |
| Pentest / bug bounty | ✗ Ingests pentest/bug-bounty findings; not a testing service | ✗ |
| The Vulnetix orchestration layer | ||
| Cross-scanner dedup & one queue (ASPM) | ✓ Correlates every scanner into one prioritised queue with ownership routing | ✗ |
| Exploit-intel prioritisation | ✓ EPSS, CISA KEV, Coalition ESS, CWSS, Vulnetix LEV | ✗ |
| Reachability analysis | ✓ Tree-sitter + CVEAffected; direct/transitive/semantic | ✗ |
| Versioned VEX + audit trail | ✓ Immutable OpenVEX/CycloneDX, cosign-signable | ✗ |
| Safe Harbour autofix | ✓ Resolves + applies the nearest safe version | ✗ |
| End-of-life policy | ✓ Flags/blocks past-EOL runtimes & packages | ✗ |
| SSVC / risk-based policy | ✓ SSVC v2 + CISA/FedRAMP/Essential-8 presets | ✗ |
✓ full · ~ partial · ✗ not covered
What Regula does well
- Pure OPA/Rego policy engine: checks Terraform (HCL + JSON plans), CloudFormation, Kubernetes YAML and ARM templates before deployment, with fully custom Rego rules
- Ships a library of rules mapped to the CIS AWS, Azure, Google Cloud and Kubernetes Foundations Benchmarks for compliance reporting
- Lightweight single-binary CLI that fits cleanly into CI/pre-deploy gates; its engine was strong enough that Snyk absorbed it into snyk/policy-engine to power Snyk IaC
Where Vulnetix adds to it: Regula is archived (Sept 2024) and single-purpose IaC-as-policy. Vulnetix runs its own IaC misconfig checks natively and adds the entire missing stack around it (SAST, SCA, container, secrets, malware/package-firewall) then layers cross-scanner dedup, exploit-intel prioritisation, versioned VEX, SSVC and autofix that Regula never had. Vulnetix can also ingest Rego/OPA policy output, so an existing Regula pipeline is consolidated rather than replaced.
No migration, no rip-and-replace. Regula keeps doing what it does best; Vulnetix adds the orchestration, exploit-intelligence prioritisation and remediation layer built for the way AppSec works today.
Centralise Regula results in Vulnetix
Upload Regula SARIF, JSON output to the Vulnetix platform to deduplicate findings, prioritise them with EPSS, CISA KEV and Coalition ESS exploit intelligence, and track remediation across every scanner in a single queue.