Integrate SW360 with Vulnetix. Use the SW360 REST API to export component and project SBOMs in SPDX or CycloneDX format, then upload to Vulnetix.
How Vulnetix compares: better together
Vulnetix does not replace SW360. Keep running it. Vulnetix sits on top of SW360 (and every other scanner you already own) turning disconnected tool outputs into one prioritised, fixable queue.
SW360 is strongest at its core category and also carries features in SBOM Generation, SCA, Compliance & Policy Engines, just as Vulnetix spans categories.
| Capability | Vulnetix | SW360 |
|---|---|---|
| Security coverage | ||
| SAST (static code analysis) | ✓ Built-in rules + Semgrep augmentation | ✗ |
| SCA / dependencies | ✓ 40+ ecosystems, transitive graph | ~ Tracks component versions and runs scheduled CVE-database searches against catalogued releases |
| DAST (dynamic testing) | ~ Ingests DAST results; no native dynamic engine | ✗ |
| Container & image | ✓ Image CVEs, base image, Dockerfile | ✗ |
| IaC / misconfiguration | ✓ Terraform, k8s, CloudFormation | ✗ |
| Secret scanning | ✓ 1,000+ rules, source + binary + git history | ✗ |
| Cloud / CSPM | ✓ Cloud-posture findings, compliance tab | ✗ |
| Mobile (MAST) | ~ Ingests mobile scanner output; no native mobile engine | ✗ |
| License compliance | ✓ SPDX, copyleft/AGPL/SSPL policy | ✓ Core: license obligation management and clearing workflows; FOSSology integration for license scanning |
| SBOM generation | ✓ CycloneDX 1.7 + SPDX 2.3, cosign-signable | ~ Imports/exports SPDX and CycloneDX SBOMs; component-catalog oriented rather than repo SBOM generation |
| Malware / supply-chain | ✓ De-duplicated corpus + install-time firewall (25+ registries) | ✗ |
| Network / infra vuln | ~ Ingests network scanner output; no native network scanner | ✗ |
| Fuzzing | ✗ Ingests fuzzing crashes; no native fuzzer | ✗ |
| Pentest / bug bounty | ✗ Ingests pentest/bug-bounty findings; not a testing service | ✗ |
| The Vulnetix orchestration layer | ||
| Cross-scanner dedup & one queue (ASPM) | ✓ Correlates every scanner into one prioritised queue with ownership routing | ✗ |
| Exploit-intel prioritisation | ✓ EPSS, CISA KEV, Coalition ESS, CWSS, Vulnetix LEV | ✗ |
| Reachability analysis | ✓ Tree-sitter + CVEAffected; direct/transitive/semantic | ✗ |
| Versioned VEX + audit trail | ✓ Immutable OpenVEX/CycloneDX, cosign-signable | ✗ |
| Safe Harbour autofix | ✓ Resolves + applies the nearest safe version | ✗ |
| End-of-life policy | ✓ Flags/blocks past-EOL runtimes & packages | ✗ |
| SSVC / risk-based policy | ✓ SSVC v2 + CISA/FedRAMP/Essential-8 presets | ✗ |
✓ full · ~ partial · ✗ not covered
What SW360 does well
- Mature component/release lifecycle catalog with license obligation tracking and clearing-request workflows, integrated with FOSSology for deep license scanning
- Imports and manages both SPDX and CycloneDX SBOMs and maps components to a curated component database (e.g. via CaPyCli)
- Vulnerability management with scheduled CVE-database searches mapped against catalogued components
- Export Control Classification (ECC) and moderation/approval workflows suited to enterprise open-source governance
Where Vulnetix adds to it: SW360 is an open-source component-catalog and license-clearing portal; its vulnerability feature is catalog-level CVE matching, not multi-engine scanning. Vulnetix natively scans SAST/SCA/IaC/container/secrets/cloud/malware across 40+ ecosystems and layers cross-scanner dedup, exploit-intel prioritization, reachability, immutable versioned VEX, autofix and SSVC. Vulnetix also emits CycloneDX 1.7 + SPDX 2.3 SBOMs directly; SW360 remains strong as the license-obligation and clearing system of record it feeds into.
No migration, no rip-and-replace. SW360 keeps doing what it does best; Vulnetix adds the orchestration, exploit-intelligence prioritisation and remediation layer built for the way AppSec works today.
Centralise SW360 results in Vulnetix
Upload SW360 SPDX, CycloneDX, JSON output to the Vulnetix platform to deduplicate findings, prioritise them with EPSS, CISA KEV and Coalition ESS exploit intelligence, and track remediation across every scanner in a single queue.