Integrate terraform-compliance with Vulnetix. Write BDD-style compliance tests in Gherkin for your Terraform plans and export JSON results for upload to Vulnetix.
Install & scan
$ # Install with pip pip install terraform-compliance # Or via uv uv run --with terraform-compliance terraform-compliance --help $ # Generate Terraform plan JSON first terraform plan -out=tfplan terraform show -json tfplan > plan.json # Run compliance tests terraform-compliance -f ./compliance-tests/ -p plan.json --junit-xml compliance-results.xml
Run terraform-compliance in CI
Scan on every push and upload the report as a workflow artifact:
- name: Generate Terraform plan
run: |
terraform init
terraform plan -out=tfplan
terraform show -json tfplan > plan.json
- name: Run compliance tests
run: |
pip install terraform-compliance
terraform-compliance -f ./compliance-tests/ -p plan.json --junit-xml compliance-results.xml
- name: Upload results to Vulnetix
run: vulnetix upload --file compliance-results.xml
How Vulnetix compares: better together
Vulnetix does not replace terraform-compliance. Keep running it. Vulnetix sits on top of terraform-compliance (and every other scanner you already own) turning disconnected tool outputs into one prioritised, fixable queue.
terraform-compliance is strongest at its core category and also carries features in Secret Scanning, just as Vulnetix spans categories.
| Capability | Vulnetix | terraform-compliance |
|---|---|---|
| Security coverage | ||
| SAST (static code analysis) | ✓ Built-in rules + Semgrep augmentation | ✗ |
| SCA / dependencies | ✓ 40+ ecosystems, transitive graph | ✗ |
| DAST (dynamic testing) | ~ Ingests DAST results; no native dynamic engine | ✗ |
| Container & image | ✓ Image CVEs, base image, Dockerfile | ✗ |
| IaC / misconfiguration | ✓ Terraform, k8s, CloudFormation | ✓ Core: BDD/Gherkin compliance testing of terraform plans, enforces encryption, security-group, tagging, VPC/subnet and resource-restriction policies |
| Secret scanning | ✓ 1,000+ rules, source + binary + git history | ~ Can author BDD scenarios asserting no plaintext secrets/passwords in resource config, but has no dedicated secret-detection engine |
| Cloud / CSPM | ✓ Cloud-posture findings, compliance tab | ✗ |
| Mobile (MAST) | ~ Ingests mobile scanner output; no native mobile engine | ✗ |
| License compliance | ✓ SPDX, copyleft/AGPL/SSPL policy | ✗ |
| SBOM generation | ✓ CycloneDX 1.7 + SPDX 2.3, cosign-signable | ✗ |
| Malware / supply-chain | ✓ De-duplicated corpus + install-time firewall (25+ registries) | ✗ |
| Network / infra vuln | ~ Ingests network scanner output; no native network scanner | ✗ |
| Fuzzing | ✗ Ingests fuzzing crashes; no native fuzzer | ✗ |
| Pentest / bug bounty | ✗ Ingests pentest/bug-bounty findings; not a testing service | ✗ |
| The Vulnetix orchestration layer | ||
| Cross-scanner dedup & one queue (ASPM) | ✓ Correlates every scanner into one prioritised queue with ownership routing | ✗ |
| Exploit-intel prioritisation | ✓ EPSS, CISA KEV, Coalition ESS, CWSS, Vulnetix LEV | ✗ |
| Reachability analysis | ✓ Tree-sitter + CVEAffected; direct/transitive/semantic | ✗ |
| Versioned VEX + audit trail | ✓ Immutable OpenVEX/CycloneDX, cosign-signable | ✗ |
| Safe Harbour autofix | ✓ Resolves + applies the nearest safe version | ✗ |
| End-of-life policy | ✓ Flags/blocks past-EOL runtimes & packages | ✗ |
| SSVC / risk-based policy | ✓ SSVC v2 + CISA/FedRAMP/Essential-8 presets | ✗ |
✓ full · ~ partial · ✗ not covered
What terraform-compliance does well
- Human-readable BDD/Gherkin compliance policies that double as automated tests, security requirements written in plain-English Cucumber-style scenarios
- Provider-agnostic negative testing against the terraform plan before apply, so it catches drift from any provider's resources
- Segregation-of-duty design: compliance tests can live in a separate repo maintained by a dedicated security/GRC team
- Lightweight and portable: pip or Docker install, trivial to drop into CI/CD pipelines and git hooks
Where Vulnetix adds to it: terraform-compliance excels at expressing custom org policy as readable Gherkin against a Terraform plan, but is scoped to IaC compliance assertions you write yourself. Vulnetix adds a full native scanner stack (SAST, SCA, container, secrets, cloud, SBOM) plus built-in IaC misconfig rules, and consolidates terraform-compliance results into a cross-scanner deduped queue with EPSS/KEV prioritisation, versioned VEX and SSVC. It layers on top, it does not replace the team's Gherkin policy suite.
No migration, no rip-and-replace. terraform-compliance keeps doing what it does best; Vulnetix adds the orchestration, exploit-intelligence prioritisation and remediation layer built for the way AppSec works today.
Centralise terraform-compliance results in Vulnetix
Upload terraform-compliance JSON output to the Vulnetix platform to deduplicate findings, prioritise them with EPSS, CISA KEV and Coalition ESS exploit intelligence, and track remediation across every scanner in a single queue.