101% more reported CVEs per day in 2026 than last year.

Comparison

CRACI vs Wiz

Wiz Code reads your GitHub Actions workflows and tells you which ones are configured in a risky way. CRACI is the runner those workflows execute on, so it records what each build fetched and controls what it can reach.

Updated

The short answer

Wiz is a cloud security platform, and since March 11, 2026 part of Google. Wiz Code is its code security product: it scans code, dependencies, secrets and IaC, checks version control and CI/CD settings, and connects what it finds to the cloud resources the code ends up running on. In April 2026 Wiz extended Wiz Code to GitHub Actions: it now parses workflow files, models workflows, jobs and runners on its Security Graph, and flags risky triggers, permissions, third-party actions and AI agent configurations.

That is configuration analysis: it tells you which workflows could be abused. CRACI works one layer down. It is the runner for GitHub Actions, so it records the packages each job actually pulled in, enforces an egress policy while the job runs and keeps monitoring what shipped. Wiz covers far more ground, from code to cloud; CRACI covers what happens inside the build.

At a glance

Capability CRACI Wiz Code
Runs your builds Jobs run on CRACI runners Analyzes your repositories, workflows and cloud
GitHub Actions workflow analysis Triggers, permissions, third-party actions, AI agents
CI/CD posture checks OWASP Top 10 CI/CD, CIS for GitHub and GitLab
Build network egress policy Default deny or allow, validated before the job, fails closed Not stated
Threat detection on runners Network trace per job; no process monitoring Wiz Sensor on self-hosted runners
SBOM of what the build fetched Recorded per job, with a completeness state SCA and SBOM from code; agentless SBOMs of cloud workloads
Vulnerability monitoring SBOMs of what shipped re-evaluated continuously Cloud workloads, prioritized with Security Graph context
SAST, secrets, IaC and malware scanning Built in, plus third-party scanner findings
Cloud security and code-to-cloud mapping Traces cloud risks back to the source code
CI systems covered GitHub Actions today; GitLab CI and Jenkins on the roadmap Workflow modeling announced for GitHub Actions; posture benchmarks for GitHub and GitLab
Pricing $0.002 per vCPU-minute ($0.004 for 2 vCPU), metered per second; no monthly fee and no per-SBOM charge No list prices published; licensing by quote (as of September 2026).
  • Included
  • Not included
  • On the roadmap

"Not stated" means we could not confirm it in Wiz's public pages.

What Wiz does well

The Wiz Code homepage
wiz.io

Code to cloud

  • Cloud context. Wiz's core is cloud security across AWS, Azure, Google Cloud and Oracle Cloud. It scans VMs, containers and serverless functions without agents, and ranks vulnerabilities with context from its Security Graph: network exposure, identities, data sensitivity and attack paths.
  • Code-to-cloud mapping. Wiz Code traces a risk found in the cloud back to the source code that produced it, and suggests the fix in that code. For a team already on Wiz, code findings land in the same graph as everything else.
  • Scanning in one place. SCA and SBOM for direct and transitive dependencies, IaC scanning of Terraform, CloudFormation, Azure Resource Manager, Kubernetes and Docker against more than 1,000 rules, secrets in code, IaC templates and container images, sensitive data such as PII and PHI, and malware scanning of the codebase "before it reaches your CI runners". Wiz SAST and findings from third-party scanners complete the picture.

GitHub Actions and CI/CD posture

  • Workflows on the graph. Wiz parses GitHub Actions workflow YAML and models workflows, jobs, runners and their relationships, so a pipeline becomes a queryable asset with context about what triggers it and what it can access.
  • Risky configuration. It flags dangerous triggers such as pull_request_target, analyzes the permissions declared in workflow files and raises issues for risky or excessive ones, surfaces risky inputs and potential secret leaks in pipeline definitions, inventories the third-party actions each workflow uses, and flags AI agents in workflows that are open to prompt injection.
  • Benchmarks. Wiz Code checks version control and CI/CD systems against misconfigurations and insecure defaults, with OpenSSF Best Practices, the OWASP Top 10 CI/CD Risks and CIS benchmarks for GitHub and GitLab.
  • Threat detection. Wiz ingests audit logs from version control and CI/CD platforms to catch events such as a suspicious clone or a deleted branch protection rule, and its Sensor on self-hosted CI runners can detect suspicious activity, such as a runner contacting a crypto-mining domain.

Where CRACI is different

Enforcement inside the job, not findings about it

Wiz's announcement describes inventory, analysis and findings. It does not describe controlling what a job can reach while it runs. CRACI's egress policy is part of the runner. Policies are default deny or default allow, with 24 built-in software-source presets, typed custom sources for npm, PyPI, apt, apk, the Go proxy, Nix, Cargo, OCI registries and Git, and explicit TLS, TCP, UDP and ICMP rules. They are validated before the job starts and fail closed, and CRACI alerts you on a violation.

This matters because supply chain attacks run inside jobs that look correctly configured. Wiz's own research on the second Shai-Hulud wave found that most infections ran in CI/CD pipelines. A posture finding can tell you a workflow is exposed; it cannot stop a compromised package that is already running. With a default-deny policy, a connection to a host the build does not need is blocked, even in an attack nobody has seen before.

What the build fetched, not what the code declares

Wiz Code's SCA scans the dependencies in your code, and its agentless SBOMs describe cloud workloads. CRACI sees the traffic coming into each build: a package-aware proxy records every package the job fetched across npm, PyPI, RubyGems, Cargo, Go, Nix, OCI, apt, apk and Git sources, plus download presets, including packages restored from CI caches. That is how CRACI records the hidden dependencies that lockfile-based tools miss, such as code downloaded by npm install hooks or the base image layers of a container build. The GitHub Actions a workflow ran are in the SBOM too, pinned to the commit that was used. Every SBOM carries a completeness state per job and per cache, so when the record has a gap, it says so.

Evidence from the build

The API returns SBOMs, network traces and provenance. CRACI does not sign provenance and claims no SLSA level. CRACI keeps re-evaluating the SBOMs of what you shipped as new vulnerabilities are published, and shows every past build that contained a vulnerable dependency, so you know how long you were exposed.

Where Wiz is ahead

To be plain about it: CRACI has no SAST, secrets, IaC or malware scanning, no CI/CD posture checks, no process monitoring on runners, no cloud security and no code-to-cloud mapping. It runs GitHub Actions only today, with GitLab CI and Jenkins on the roadmap. If your priority is one view of risk from code to cloud, Wiz covers much more.

Which one fits

Wiz is the better fit when

  • You already use Wiz for cloud security and want code and pipeline risk in the same graph.
  • You want to find risky workflow triggers, permissions and third-party actions across many repositories.
  • You need SAST, secrets, IaC and malware scanning with cloud context for prioritization.
  • You run self-hosted runners and want threat detection on them.

CRACI is the better fit when

  • You want an egress policy enforced inside every GitHub Actions job, not only findings about the workflow.
  • You need an SBOM of what each build actually fetched, with a completeness state you can show an auditor.
  • You want monitoring of what shipped and build history from the same record.

Using both

Wiz Code's posture checks, code scanning and cloud security cover ground CRACI does not touch by design, so they stay where they are. CRACI replaces the runner, not GitHub Actions: your workflows and repositories stay in GitHub, so Wiz keeps analyzing the same workflow files while the jobs run on CRACI. CRACI also runs builds about twice as fast as GitHub-hosted runners, thanks to faster hardware, shorter queue times and caching, and charges only for build minutes. See CRACI pricing.

For the Cyber Resilience Act

The Cyber Resilience Act is one of several frameworks that ask for an SBOM and a vulnerability handling process. CRACI automates a significant part of the supply chain visibility and evidence a CRA process needs: build-time SBOMs exported as CycloneDX or SPDX, vulnerability tracking, and provenance through the API. See CRA evidence. Neither tool makes a product compliant on its own.

For other platforms in this space, see CRACI vs OX Security, CRACI vs StepSecurity, CRACI vs Xygeni and software supply chain security tools.

Wiz questions, answered

What is Wiz Code?

Wiz Code is the code security part of the Wiz cloud security platform. It scans code for vulnerable dependencies, secrets, IaC misconfigurations, sensitive data and malware, adds SAST and findings from third-party scanners, checks version control and CI/CD settings against benchmarks, and traces cloud risks back to the source code that caused them.

Does Wiz Code secure GitHub Actions?

Wiz Code analyzes GitHub Actions configuration. Since April 2026 it parses workflow YAML files and models workflows, jobs, runners and their relationships on the Wiz Security Graph, flags dangerous triggers such as pull_request_target, raises issues for risky or excessive permissions, inventories third-party actions and flags risky AI agent setups. Wiz's announcement does not describe controlling what a job can reach while it runs. CRACI is the runner, so it enforces an egress policy inside every job.

Is Wiz part of Google?

Yes. Google completed its acquisition of Wiz on March 11, 2026. Wiz says it remains a multi-cloud platform covering AWS, Azure, Google Cloud and Oracle Cloud.

How much does Wiz cost?

Wiz does not publish list prices. As of September 2026 its pricing page describes unified offerings and à la carte options, with quotes on request. CRACI charges only for build minutes: $0.002 per vCPU-minute ($0.004 for a default 2 vCPU runner), metered per second, with no monthly fee.

Can CRACI replace Wiz Code?

Not as a whole. CRACI has no SAST, secrets, IaC or malware scanning, no CI/CD posture checks and no cloud security. For GitHub Actions builds, CRACI adds what configuration analysis cannot: it is the runner, so it records the packages each job fetched and enforces an egress policy while the job runs.

Run one real build and compare

Point one GitHub Actions workflow at CRACI and see its SBOM, egress policy and network trace next to your Wiz findings.

Book a demo