101% more reported CVEs per day in 2026 than last year.

Comparison

CRACI vs DefectDojo

DefectDojo is where findings from many security tools meet. CRACI is where the record of what your software is built from begins. For a PSIRT, both answer parts of the same question: which of our products does this vulnerability affect?

Updated

The short answer

DefectDojo is an open-source vulnerability management platform and an OWASP Flagship project, with a commercial edition, DefectDojo Pro, from DefectDojo Inc. in Austin, Texas. It imports results from the security tools you already run, deduplicates them into one queue and tracks remediation. Pro adds SBOM management and a PSIRT Advisory Engine. CRACI is a GitHub Actions runner that records what each build pulls in while it runs, produces the SBOM from that record, monitors it for new vulnerabilities and lets security teams triage what it finds. DefectDojo collects what other tools report; CRACI is the source of the dependency record for the software you build.

At a glance

Capability CRACI DefectDojo
Generates SBOMs Recorded by the runner during each build Imports SBOMs you upload (Pro)
Runs your CI builds Jobs run on CRACI runners Ingests results from your pipeline
Imports findings from other scanners 500+ supported tools, deduplicated
SBOM completeness state Five states per job and per cache Depends on the SBOM it receives
Imports third-party SBOMs Vendor SBOMs can be added CycloneDX and SPDX (Pro)
Continuous vulnerability analysis Monitored SBOMs re-evaluated across builds and repositories Pro matches advisory feeds against SBOM data
VEX CycloneDX VEX export (Pro)
Triage and ownership Triage and route findings to teams Cases with owners, SLA tracking, Jira tickets
Build network egress policy Default deny or allow, fails closed Works on results after the build
Deployment Managed today; customer-hosted runners on the roadmap, Enterprise Open source self-hosted; Pro in the cloud or self-hosted
CI systems GitHub Actions today; GitLab CI and Jenkins on the roadmap Not a CI system; takes in results from the pipeline
Pricing (October 2026) Pay per build minute, no monthly fee Community free; Pro from $100 per month plus $0.15 per finding
  • Included
  • Not included
  • On the roadmap

What DefectDojo does well

The DefectDojo homepage
defectdojo.com

One queue for every scanner. DefectDojo's site lists more than 500 supported tools and describes the goal plainly: "Every SAST, DAST, SCA, cloud, and container scanner in your stack, deduplicated into a single queue." Deduplication across overlapping scanners is the reason many teams adopt it. Findings get owners, SLAs and Jira tickets from there.

Open source with a long track record. The Community Edition is free under the BSD 3-Clause license and runs with Docker Compose. OWASP lists DefectDojo as a Flagship project, and DefectDojo says more than 10,000 organizations use it. DefectDojo Inc. raised a $7 million Series A in September 2024.

SBOMs as an asset model. In Pro, an SBOM uploaded to an asset becomes a set of dependencies in Locations, DefectDojo's component-level asset model. It imports CycloneDX (JSON and XML) and SPDX (JSON, XML and tag-value), exports CycloneDX 1.6 or SPDX 2.3, and exports finding statuses as a CycloneDX VEX document. Its docs are clear that DefectDojo does not generate SBOMs itself.

A PSIRT workflow. DefectDojo launched its PSIRT Advisory Engine in April 2026 as "the first purpose-built security platform for PSIRT." It is a Pro capability. It ingests advisories from feeds such as CISA Known Exploited Vulnerabilities, the NVD, the EUVD, Red Hat and Exploit-DB, matches them against SBOM data or custom asset rules, prioritizes them by CVSS, EPSS and KEV status, groups them into cases with owners, and publishes branded PDF advisories. The September 2026 Pro release added CSAF 2.0 and VEX advisory export and a CRA Article 14 reporting interface.

Published pricing. Pro on pay as you go is $100 per month plus $0.15 per finding processed, with discounts for annual prepayment. The Community Edition stays free.

Where CRACI is different

DefectDojo works from results that other tools produce. CRACI produces its own record, because it is the machine the build runs on.

The SBOM comes from the build

DefectDojo's advisory matching is only as good as the SBOM data you load into it, and that SBOM comes from a generator somewhere upstream. CRACI replaces the runner: you change runs-on to craci, and a package-aware proxy records what each job fetches from package sources, including packages restored from CI caches and hidden dependencies that no lockfile lists. The SBOM, in CycloneDX or SPDX, comes from that record, and each one states how complete it is per job and per cache: Complete, Complete with connections, Incomplete, Unavailable or Not recorded.

Monitoring and triage on the same record

CRACI re-evaluates monitored SBOMs as new vulnerabilities are published and aggregates findings across builds and repositories. Build history shows every past build and its SBOM within your retention period, so you can see which builds contained a vulnerable dependency and for how long. The inventory view shows which software versions are deployed to which products. Security teams triage findings and route each one to the team that owns the fix, record VEX, and set policy gates that block a build, including builds that contain a specific CVE. You can also add vendor SBOMs, so bought-in components are monitored next to your own builds.

Control over what the build can reach

Because CRACI runs the job, it enforces a network egress policy: default deny or default allow, with 24 built-in software-source presets. Policies are validated before the job starts and fail closed. DefectDojo can track a risky component after the fact; an egress policy limits where a build could fetch from in the first place.

What CRACI does not do

CRACI does not import findings from other scanners, so it is not a single queue for SAST, DAST, cloud and container results. It does not scan source code; SAST and secrets scanning are outside its scope by design. It does not offer reachability analysis, and it supports GitHub Actions only today, with GitLab CI and Jenkins on the roadmap.

When to use which

  • You need one queue for findings from many tools. DefectDojo. It is built to take in results from SAST, DAST, SCA, cloud and container scanners and deduplicate them, and CRACI does not do that.
  • Your main exposure is the dependencies of software you build on GitHub Actions. CRACI. It produces the SBOM in the build, monitors it, and carries triage through to the owning team, so there is no generator to run and no SBOM upload to maintain.
  • You want advisory feeds matched to products, PDF advisories and a CRA Article 14 reporting interface in one tool. DefectDojo Pro builds these into its PSIRT Advisory Engine.
  • You need a free tool you host yourself. DefectDojo's Community Edition. CRACI is a managed service today, with customer-hosted runners on the roadmap for Enterprise.

Replacing the SBOM side of DefectDojo

If DefectDojo mostly holds SCA findings and uploaded SBOMs for software you build, CRACI covers that job in one product: the build, the SBOM, continuous monitoring and triage. There is no generator to keep in step with each ecosystem and no import job to maintain, and the inventory comes from what the build actually fetched rather than from what a scan estimated.

Be clear about what you give up. DefectDojo is open source and can be self-hosted. It deduplicates findings from hundreds of tools, not only dependencies. If it is the place where every scanner's results meet, keep it for that job; CRACI does not take in other tools' findings.

In a PSIRT

The first question in most PSIRT cases is which products and versions contain the affected component. FIRST's PSIRT Services Framework calls the inventory of product components essential to answering it. DefectDojo answers from the SBOM data you load; CRACI answers from a record of what each build fetched, and keeps answering as new CVEs appear. Read what a PSIRT does, CRACI for PSIRT teams and PSIRT tools compared.

For regulated products, CRACI automates a significant part of the software supply chain visibility and evidence that companies need for their wider CRA compliance process. No tool on this page makes a product compliant on its own.

CRACI supports GitHub Actions today. GitLab CI and Jenkins are on the roadmap. Read more about build-time SBOM generation and vulnerability tracking.

Weighing more than two tools? DefectDojo alternatives compares six options, including Dependency-Track.

See your products' exposure from the build

Book a demo and we will run one of your GitHub Actions workflows on CRACI and walk through what it fetched and which vulnerabilities it carries.

Book a demo