Tool integration

Regula Integration Guide

OPA-based IaC compliance checker: archived in Sept 2024, functionality in Snyk IaC

Get a Free API Key

Integrate Regula with Vulnetix. Check Terraform, CloudFormation, Kubernetes, and ARM templates against OPA Rego rules. Note: Regula was archived Sept 2024; consider Trivy IaC or Checkov for new projects.

CLI toolSARIFJSON

Install & scan

$ # Homebrew (macOS/Linux): last release v3.4.0
brew tap fugue/regula
brew install regula

# Binary download
curl -L https://github.com/fugue/regula/releases/latest/download/regula_Linux_x86_64.tar.gz | tar xz
sudo mv regula /usr/local/bin/
$ regula run .   --format sarif   > regula.sarif

Run Regula in CI

Scan on every push and upload the report as a workflow artifact:

- name: Run Regula IaC scan
  run: |
    curl -L https://github.com/fugue/regula/releases/latest/download/regula_Linux_x86_64.tar.gz | tar xz
    sudo mv regula /usr/local/bin/
    regula run . --format sarif > regula.sarif

- name: Upload report
  uses: actions/upload-artifact@v6
  with:
    name: regula
    path: regula.sarif
    if-no-files-found: warn

Then one publish job hands every artifact in the run to Vulnetix, recorded under Regula's own name and version. Written once per workflow, however many scanners you run:

publish:
  name: Publish to Vulnetix
  runs-on: ubuntu-latest
  needs: [scan]        # every scanner job, or its report is never published
  if: always()         # or one failing scanner suppresses all the others
  permissions:
    contents: read
    actions: read      # required to list the run's artifacts
  env:
    VULNETIX_ORG_ID: ${{ secrets.VULNETIX_ORG_ID }}
    VULNETIX_API_KEY: ${{ secrets.VULNETIX_API_KEY }}
  steps:
    - uses: actions/checkout@v5
    - name: Install Vulnetix CLI
      run: |
        curl -fsSL https://cli.vulnetix.com/install.sh | sh -s -- --install-dir "$HOME/.local/bin"
        echo "$HOME/.local/bin" >> "$GITHUB_PATH"
    - name: Publish scanner reports
      env:
        GITHUB_TOKEN: ${{ github.token }}
      run: vulnetix gha upload --org-id "$VULNETIX_ORG_ID" --json

After the run, vulnetix gha status reports what was actually recorded.

How Vulnetix compares: better together

Vulnetix does not replace Regula. Keep running it. Vulnetix sits on top of Regula (and every other scanner you already own) turning disconnected tool outputs into one prioritised, fixable queue.

Regula is strongest at its core category and also carries features in Compliance & Policy Engines, just as Vulnetix spans categories.

CapabilityVulnetixRegula
Security coverage
SAST (static code analysis)Built-in rules + Semgrep augmentation
SCA / dependencies40+ ecosystems, transitive graph
DAST (dynamic testing)~ Ingests DAST results; no native dynamic engine
Container & imageImage CVEs, base image, Dockerfile~ Only via Kubernetes manifest checks (privileged/pod-security); no image/OCI layer scanning
IaC / misconfigurationTerraform, k8s, CloudFormationCore: Rego rules over Terraform/CFN/K8s/ARM for misconfig and compliance violations
Secret scanning1,000+ rules, source + binary + git history
Cloud / CSPMCloud-posture findings, compliance tab
Mobile (MAST)~ Ingests mobile scanner output; no native mobile engine
License complianceSPDX, copyleft/AGPL/SSPL policy
SBOM generationCycloneDX 1.7 + SPDX 2.3, cosign-signable
Malware / supply-chainDe-duplicated corpus + install-time firewall (25+ registries)
Network / infra vuln~ Ingests network scanner output; no native network scanner
FuzzingIngests fuzzing crashes; no native fuzzer
Pentest / bug bountyIngests pentest/bug-bounty findings; not a testing service
The Vulnetix orchestration layer
Cross-scanner dedup & one queue (ASPM)Correlates every scanner into one prioritised queue with ownership routing
Exploit-intel prioritisationEPSS, CISA KEV, Coalition ESS, CWSS, Vulnetix LEV
Reachability analysisTree-sitter + CVEAffected; direct/transitive/semantic
Versioned VEX + audit trailImmutable OpenVEX/CycloneDX, cosign-signable
Safe Harbour autofixResolves + applies the nearest safe version
End-of-life policyFlags/blocks past-EOL runtimes & packages
SSVC / risk-based policySSVC v2 + CISA/FedRAMP/Essential-8 presets

✓ full · ~ partial · ✗ not covered

What Regula does well

Where Vulnetix adds to it: Regula is archived (Sept 2024) and single-purpose IaC-as-policy. Vulnetix runs its own IaC misconfig checks natively and adds the entire missing stack around it (SAST, SCA, container, secrets, malware/package-firewall) then layers cross-scanner dedup, exploit-intel prioritisation, versioned VEX, SSVC and autofix that Regula never had. Vulnetix can also ingest Rego/OPA policy output, so an existing Regula pipeline is consolidated rather than replaced.

No migration, no rip-and-replace. Regula keeps doing what it does best; Vulnetix adds the orchestration, exploit-intelligence prioritisation and remediation layer built for the way AppSec works today.

Centralise Regula results in Vulnetix

Upload Regula SARIF, JSON output to the Vulnetix platform to deduplicate findings, prioritise them with EPSS, CISA KEV and Coalition ESS exploit intelligence, and track remediation across every scanner in a single queue.

Regula documentation ↗  ·  Source repository ↗

Wire Regula into your CI/CD pipeline →