Tool integration

SW360 Integration Guide

Eclipse Foundation SBOM management portal with REST API for SPDX and CycloneDX export

Get a Free API Key

Integrate SW360 with Vulnetix. Use the SW360 REST API to export component and project SBOMs in SPDX or CycloneDX format, then upload to Vulnetix.

SaaS platformSPDXCycloneDXJSON

How Vulnetix compares: better together

Vulnetix does not replace SW360. Keep running it. Vulnetix sits on top of SW360 (and every other scanner you already own) turning disconnected tool outputs into one prioritised, fixable queue.

SW360 is strongest at its core category and also carries features in SBOM Generation, SCA, Compliance & Policy Engines, just as Vulnetix spans categories.

CapabilityVulnetixSW360
Security coverage
SAST (static code analysis)Built-in rules + Semgrep augmentation
SCA / dependencies40+ ecosystems, transitive graph~ Tracks component versions and runs scheduled CVE-database searches against catalogued releases
DAST (dynamic testing)~ Ingests DAST results; no native dynamic engine
Container & imageImage CVEs, base image, Dockerfile
IaC / misconfigurationTerraform, k8s, CloudFormation
Secret scanning1,000+ rules, source + binary + git history
Cloud / CSPMCloud-posture findings, compliance tab
Mobile (MAST)~ Ingests mobile scanner output; no native mobile engine
License complianceSPDX, copyleft/AGPL/SSPL policyCore: license obligation management and clearing workflows; FOSSology integration for license scanning
SBOM generationCycloneDX 1.7 + SPDX 2.3, cosign-signable~ Imports/exports SPDX and CycloneDX SBOMs; component-catalog oriented rather than repo SBOM generation
Malware / supply-chainDe-duplicated corpus + install-time firewall (25+ registries)
Network / infra vuln~ Ingests network scanner output; no native network scanner
FuzzingIngests fuzzing crashes; no native fuzzer
Pentest / bug bountyIngests pentest/bug-bounty findings; not a testing service
The Vulnetix orchestration layer
Cross-scanner dedup & one queue (ASPM)Correlates every scanner into one prioritised queue with ownership routing
Exploit-intel prioritisationEPSS, CISA KEV, Coalition ESS, CWSS, Vulnetix LEV
Reachability analysisTree-sitter + CVEAffected; direct/transitive/semantic
Versioned VEX + audit trailImmutable OpenVEX/CycloneDX, cosign-signable
Safe Harbour autofixResolves + applies the nearest safe version
End-of-life policyFlags/blocks past-EOL runtimes & packages
SSVC / risk-based policySSVC v2 + CISA/FedRAMP/Essential-8 presets

✓ full · ~ partial · ✗ not covered

What SW360 does well

Where Vulnetix adds to it: SW360 is an open-source component-catalog and license-clearing portal; its vulnerability feature is catalog-level CVE matching, not multi-engine scanning. Vulnetix natively scans SAST/SCA/IaC/container/secrets/cloud/malware across 40+ ecosystems and layers cross-scanner dedup, exploit-intel prioritization, reachability, immutable versioned VEX, autofix and SSVC. Vulnetix also emits CycloneDX 1.7 + SPDX 2.3 SBOMs directly; SW360 remains strong as the license-obligation and clearing system of record it feeds into.

No migration, no rip-and-replace. SW360 keeps doing what it does best; Vulnetix adds the orchestration, exploit-intelligence prioritisation and remediation layer built for the way AppSec works today.

Centralise SW360 results in Vulnetix

Upload SW360 SPDX, CycloneDX, JSON output to the Vulnetix platform to deduplicate findings, prioritise them with EPSS, CISA KEV and Coalition ESS exploit intelligence, and track remediation across every scanner in a single queue.

SW360 documentation ↗  ·  Source repository ↗

Wire SW360 into your CI/CD pipeline →