Tool integration

ShellCheck Integration Guide

Static analysis for shell scripts

Get a Free API Key

Integrate ShellCheck with Vulnetix. Lint shell scripts for bugs and security issues, convert to SARIF, and upload results.

Shell / BashCLI toolSARIF

Install & scan

$ uv run --with shellcheck-py shellcheck --version
$ # ShellCheck doesn't output SARIF natively - use JSON + converter
uv run --with shellcheck-py shellcheck -f json1 script.sh > shellcheck.json

# Or with shellcheck-sarif converter (requires Rust/cargo):
# cargo install shellcheck-sarif
# shellcheck -f json script.sh | shellcheck-sarif > shellcheck.sarif

Run ShellCheck in CI

Scan on every push and upload the report as a workflow artifact:

- name: Run ShellCheck
  run: |
    pip install shellcheck-py
    find . -name '*.sh' -exec shellcheck -f json1 {} + > shellcheck.json

- name: Upload to Vulnetix
  run: vulnetix upload --file shellcheck.json

How Vulnetix compares: better together

Vulnetix does not replace ShellCheck. Keep running it. Vulnetix sits on top of ShellCheck (and every other scanner you already own) turning disconnected tool outputs into one prioritised, fixable queue.

CapabilityVulnetixShellCheck
Security coverage
SAST (static code analysis)Built-in rules + Semgrep augmentation~ Static analysis narrowly scoped to shell scripts; flags command-injection/quoting/eval risks but no general-purpose code SAST
SCA / dependencies40+ ecosystems, transitive graph
DAST (dynamic testing)~ Ingests DAST results; no native dynamic engine
Container & imageImage CVEs, base image, Dockerfile
IaC / misconfigurationTerraform, k8s, CloudFormation
Secret scanning1,000+ rules, source + binary + git history
Cloud / CSPMCloud-posture findings, compliance tab
Mobile (MAST)~ Ingests mobile scanner output; no native mobile engine
License complianceSPDX, copyleft/AGPL/SSPL policy
SBOM generationCycloneDX 1.7 + SPDX 2.3, cosign-signable
Malware / supply-chainDe-duplicated corpus + install-time firewall (25+ registries)
Network / infra vuln~ Ingests network scanner output; no native network scanner
FuzzingIngests fuzzing crashes; no native fuzzer
Pentest / bug bountyIngests pentest/bug-bounty findings; not a testing service
The Vulnetix orchestration layer
Cross-scanner dedup & one queue (ASPM)Correlates every scanner into one prioritised queue with ownership routing
Exploit-intel prioritisationEPSS, CISA KEV, Coalition ESS, CWSS, Vulnetix LEV
Reachability analysisTree-sitter + CVEAffected; direct/transitive/semantic
Versioned VEX + audit trailImmutable OpenVEX/CycloneDX, cosign-signable
Safe Harbour autofixResolves + applies the nearest safe version
End-of-life policyFlags/blocks past-EOL runtimes & packages
SSVC / risk-based policySSVC v2 + CISA/FedRAMP/Essential-8 presets

✓ full · ~ partial · ✗ not covered

What ShellCheck does well

Where Vulnetix adds to it: ShellCheck is the shell-script linting core; Vulnetix ingests its SARIF into a cross-scanner deduplicated queue and surrounds it with the coverage ShellCheck never attempts (SCA, container, IaC, secrets, cloud, malware, SBOM) plus exploit-intel prioritisation, reachability, versioned VEX, and autofix. Vulnetix orchestrates ShellCheck's findings; it does not replace its shell-specific rule engine.

No migration, no rip-and-replace. ShellCheck keeps doing what it does best; Vulnetix adds the orchestration, exploit-intelligence prioritisation and remediation layer built for the way AppSec works today.

Centralise ShellCheck results in Vulnetix

Upload ShellCheck SARIF output to the Vulnetix platform to deduplicate findings, prioritise them with EPSS, CISA KEV and Coalition ESS exploit intelligence, and track remediation across every scanner in a single queue.

ShellCheck documentation ↗  ·  Source repository ↗

Wire ShellCheck into your CI/CD pipeline →