Tool integration

Trunk Check Integration Guide

Unified linting platform with native SARIF output

Get a Free API Key

Integrate Trunk Check with Vulnetix. Run multiple linters through Trunk's unified interface and export SARIF results.

Multi-language meta-linterSaaS platformSARIF

How Vulnetix compares: better together

Vulnetix does not replace Trunk Check. Keep running it. Vulnetix sits on top of Trunk Check (and every other scanner you already own) turning disconnected tool outputs into one prioritised, fixable queue.

Trunk Check is strongest at its core category and also carries features in Secret Scanning, IaC & Cloud Configuration, SCA, Container & Image Scanning, License Compliance, just as Vulnetix spans categories.

CapabilityVulnetixTrunk Check
Security coverage
SAST (static code analysis)Built-in rules + Semgrep augmentationOrchestrates semgrep, bandit and other static linters as its core
SCA / dependencies40+ ecosystems, transitive graph~ Runs osv-scanner/trivy for dependency CVEs via plugins
DAST (dynamic testing)~ Ingests DAST results; no native dynamic engine
Container & imageImage CVEs, base image, Dockerfile~ Trivy plugin can scan images/Dockerfiles
IaC / misconfigurationTerraform, k8s, CloudFormation~ Runs checkov/tfsec/trivy for IaC misconfig via plugins
Secret scanning1,000+ rules, source + binary + git history~ Runs trufflehog/gitleaks secret scanners via plugins
Cloud / CSPMCloud-posture findings, compliance tab
Mobile (MAST)~ Ingests mobile scanner output; no native mobile engine
License complianceSPDX, copyleft/AGPL/SSPL policy~ Trivy plugin can detect dependency licenses; no dedicated license-policy engine
SBOM generationCycloneDX 1.7 + SPDX 2.3, cosign-signable
Malware / supply-chainDe-duplicated corpus + install-time firewall (25+ registries)
Network / infra vuln~ Ingests network scanner output; no native network scanner
FuzzingIngests fuzzing crashes; no native fuzzer
Pentest / bug bountyIngests pentest/bug-bounty findings; not a testing service
The Vulnetix orchestration layer
Cross-scanner dedup & one queue (ASPM)Correlates every scanner into one prioritised queue with ownership routing~ Consolidates and normalises multi-linter output into one CLI/report, but not a full cross-scanner ASPM risk model
Exploit-intel prioritisationEPSS, CISA KEV, Coalition ESS, CWSS, Vulnetix LEV
Reachability analysisTree-sitter + CVEAffected; direct/transitive/semantic
Versioned VEX + audit trailImmutable OpenVEX/CycloneDX, cosign-signable
Safe Harbour autofixResolves + applies the nearest safe version~ Auto-applies formatter/linter fixes for many tools
End-of-life policyFlags/blocks past-EOL runtimes & packages
SSVC / risk-based policySSVC v2 + CISA/FedRAMP/Essential-8 presets

✓ full · ~ partial · ✗ not covered

What Trunk Check does well

Where Vulnetix adds to it: Trunk Check unifies dev-loop linters; Vulnetix is a security-focused ASPM layer that dedupes findings from Trunk's tools (and non-Trunk scanners) into one prioritised queue enriched with exploit intelligence (EPSS, CISA KEV, Coalition ESS, LEV), reachability, immutable versioned VEX, SSVC policy, EOL policy and Safe Harbour autofix PRs. Vulnetix also adds native supply-chain malware detection and an install-time package firewall Trunk does not have. Better together: Trunk drives fast in-editor linting, Vulnetix drives risk-based triage and remediation on top.

No migration, no rip-and-replace. Trunk Check keeps doing what it does best; Vulnetix adds the orchestration, exploit-intelligence prioritisation and remediation layer built for the way AppSec works today.

Centralise Trunk Check results in Vulnetix

Upload Trunk Check SARIF output to the Vulnetix platform to deduplicate findings, prioritise them with EPSS, CISA KEV and Coalition ESS exploit intelligence, and track remediation across every scanner in a single queue.

Trunk Check documentation ↗

Wire Trunk Check into your CI/CD pipeline →