Cursor Origin support is in beta. Beta features are subject to change with continued internal benchmarking and customer feedback. Cursor Origin does not yet offer full feature parity with other source code managers. See Supported features and beta limitations.
Before you begin
You need:- Permission to manage source code manager connections in your Semgrep organization.
- Permission in Cursor to install apps and select the repositories Semgrep can access.
Connect Cursor Origin
If Cursor Origin is not already connected, follow Connect a source code manager. You can use either the Semgrep-first or Cursor-first flow.Add repositories to Managed Scans
1
In Semgrep AppSec Platform, click Projects.
2
Click Scan new project > Semgrep Managed Scan.
3
On the Enable Managed Scans for repos page, select the Cursor Origin repositories you want to add.
i. Optional: If you do not see the repository you want to add, click Sync projects. If the repository does not appear after syncing, see Repositories do not appear.
i. Optional: If you do not see the repository you want to add, click Sync projects. If the repository does not appear after syncing, see Repositories do not appear.
4
Click Enable Managed Scans. The Enable Managed Scans dialog appears. By default, Semgrep runs both full and diff-aware scans.
5
Optional: Disable PR diff-aware scans by turning off the Enable PR/MR scans toggle.
6
Click Enable.
What happens next
- After enabling Managed Scans, Semgrep performs a full scan on the selected repositories in batches.
- Each repository you add becomes a in Semgrep AppSec Platform containing its findings, scan history, and scan metadata.
- Projects with a Managed Scan configuration are tagged with
managed-scan, regardless of whether the project is actively being scanned.
Manage scans and projects
After you enable Managed Scans, Cursor Origin projects use the same controls as other source code managers. To open a project’s settings, go to Projects, find the project, and click Details > Settings. From there, you can:- Run a full scan
- Turn diff-aware PR scans on or off
- Turn Managed full scans or Managed diff scans off for that project
- Delete the project
Pull request checks and comments
When Managed Scans run on a Cursor pull request, Semgrep can post a scan check and finding comments on that PR. A failing Semgrep check blocks merging only if Cursor requires that check. To receive PR comments:1
Connect Cursor Origin and add the repository to Managed Scans, including PR (diff-aware) scans.
2
Configure your in Unified policies to leave PR comments for the findings you want developers to see.
3
Open or update a pull request in Cursor Origin. After the Managed Scan finishes, review the Semgrep check and any finding comments on the PR.
Manage repository access
Change repository access
To limit which repositories Semgrep can access without disconnecting Cursor Origin:1
In Cursor, update the app installation and select only the repositories Semgrep should access.
2
In Semgrep AppSec Platform, go to Projects and click Sync projects.
Disconnect Cursor Origin
To remove the Cursor Origin connection from Semgrep:1
In Semgrep AppSec Platform, click Settings > Source code managers.
2
On the Cursor Origin entry you want to remove, click Remove app, then click Remove to confirm.
Supported features and beta limitations
Feature coverage is still expanding; some capabilities available on GitHub, GitLab, Bitbucket, or Azure DevOps are not available for Cursor Origin yet.
Troubleshoot
Repositories do not appear
1
In Semgrep AppSec Platform, click Settings > Source code managers.
2
Confirm that your Cursor Origin connection shows a healthy status. Click Test if needed.
3
Return to Projects, then click Sync projects.
4
Optional: Perform a hard refresh (Ctrl+F5 or Cmd+Shift+R).
5
If repositories are still missing, open the app installation in Cursor and confirm Semgrep has access to those repositories. Then sync again in Semgrep.