Integrate Trunk Check with Vulnetix. Run multiple linters through Trunk's unified interface and export SARIF results.
How Vulnetix compares: better together
Vulnetix does not replace Trunk Check. Keep running it. Vulnetix sits on top of Trunk Check (and every other scanner you already own) turning disconnected tool outputs into one prioritised, fixable queue.
Trunk Check is strongest at its core category and also carries features in Secret Scanning, IaC & Cloud Configuration, SCA, Container & Image Scanning, License Compliance, just as Vulnetix spans categories.
| Capability | Vulnetix | Trunk Check |
|---|---|---|
| Security coverage | ||
| SAST (static code analysis) | ✓ Built-in rules + Semgrep augmentation | ✓ Orchestrates semgrep, bandit and other static linters as its core |
| SCA / dependencies | ✓ 40+ ecosystems, transitive graph | ~ Runs osv-scanner/trivy for dependency CVEs via plugins |
| DAST (dynamic testing) | ~ Ingests DAST results; no native dynamic engine | ✗ |
| Container & image | ✓ Image CVEs, base image, Dockerfile | ~ Trivy plugin can scan images/Dockerfiles |
| IaC / misconfiguration | ✓ Terraform, k8s, CloudFormation | ~ Runs checkov/tfsec/trivy for IaC misconfig via plugins |
| Secret scanning | ✓ 1,000+ rules, source + binary + git history | ~ Runs trufflehog/gitleaks secret scanners via plugins |
| Cloud / CSPM | ✓ Cloud-posture findings, compliance tab | ✗ |
| Mobile (MAST) | ~ Ingests mobile scanner output; no native mobile engine | ✗ |
| License compliance | ✓ SPDX, copyleft/AGPL/SSPL policy | ~ Trivy plugin can detect dependency licenses; no dedicated license-policy engine |
| SBOM generation | ✓ CycloneDX 1.7 + SPDX 2.3, cosign-signable | ✗ |
| Malware / supply-chain | ✓ De-duplicated corpus + install-time firewall (25+ registries) | ✗ |
| Network / infra vuln | ~ Ingests network scanner output; no native network scanner | ✗ |
| Fuzzing | ✗ Ingests fuzzing crashes; no native fuzzer | ✗ |
| Pentest / bug bounty | ✗ Ingests pentest/bug-bounty findings; not a testing service | ✗ |
| The Vulnetix orchestration layer | ||
| Cross-scanner dedup & one queue (ASPM) | ✓ Correlates every scanner into one prioritised queue with ownership routing | ~ Consolidates and normalises multi-linter output into one CLI/report, but not a full cross-scanner ASPM risk model |
| Exploit-intel prioritisation | ✓ EPSS, CISA KEV, Coalition ESS, CWSS, Vulnetix LEV | ✗ |
| Reachability analysis | ✓ Tree-sitter + CVEAffected; direct/transitive/semantic | ✗ |
| Versioned VEX + audit trail | ✓ Immutable OpenVEX/CycloneDX, cosign-signable | ✗ |
| Safe Harbour autofix | ✓ Resolves + applies the nearest safe version | ~ Auto-applies formatter/linter fixes for many tools |
| End-of-life policy | ✓ Flags/blocks past-EOL runtimes & packages | ✗ |
| SSVC / risk-based policy | ✓ SSVC v2 + CISA/FedRAMP/Essential-8 presets | ✗ |
✓ full · ~ partial · ✗ not covered
What Trunk Check does well
- Meta-linter that manages tool versions, configs and runtime isolation for 100+ underlying linters/scanners through one CLI and daemon
- Git-aware: scans only changed files (hold-the-line), keeping CI fast and preventing new issues without forcing legacy cleanup
- Bundles security tools like semgrep, bandit, trufflehog/gitleaks, checkov, trivy and osv-scanner behind a single config
- First-class SARIF in and out plus strong IDE (VSCode/Neovim) and CI integration for developer-loop feedback
Where Vulnetix adds to it: Trunk Check unifies dev-loop linters; Vulnetix is a security-focused ASPM layer that dedupes findings from Trunk's tools (and non-Trunk scanners) into one prioritised queue enriched with exploit intelligence (EPSS, CISA KEV, Coalition ESS, LEV), reachability, immutable versioned VEX, SSVC policy, EOL policy and Safe Harbour autofix PRs. Vulnetix also adds native supply-chain malware detection and an install-time package firewall Trunk does not have. Better together: Trunk drives fast in-editor linting, Vulnetix drives risk-based triage and remediation on top.
No migration, no rip-and-replace. Trunk Check keeps doing what it does best; Vulnetix adds the orchestration, exploit-intelligence prioritisation and remediation layer built for the way AppSec works today.
Centralise Trunk Check results in Vulnetix
Upload Trunk Check SARIF output to the Vulnetix platform to deduplicate findings, prioritise them with EPSS, CISA KEV and Coalition ESS exploit intelligence, and track remediation across every scanner in a single queue.