Skip to main content
Semgrep syncs the repositories you authorize and runs and scans. It then posts scan checks and finding comments on Cursor pull requests.
Cursor Origin support is in beta. Beta features are subject to change with continued internal benchmarking and customer feedback. Cursor Origin does not yet offer full feature parity with other source code managers. See Supported features and beta limitations.

Before you begin

You need:
  • Permission to manage source code manager connections in your Semgrep organization.
  • Permission in Cursor to install apps and select the repositories Semgrep can access.
See SCM permissions for roles and scopes. Semgrep connects to Cursor Origin through an app you install in Cursor. That integration plays a similar role to the Semgrep GitHub App: you install it, choose repositories, and connect it to your Semgrep organization. Semgrep recommends the Semgrep app, which uses the public Semgrep Cursor Origin app. For when to use Semgrep app versus Private app, see Choose an app type.

Connect Cursor Origin

If Cursor Origin is not already connected, follow Connect a source code manager. You can use either the Semgrep-first or Cursor-first flow.

Add repositories to Managed Scans

1
In Semgrep AppSec Platform, click Projects.
2
Click Scan new project > Semgrep Managed Scan.
3
On the Enable Managed Scans for repos page, select the Cursor Origin repositories you want to add.

i. Optional: If you do not see the repository you want to add, click Sync projects. If the repository does not appear after syncing, see Repositories do not appear.
4
Click Enable Managed Scans. The Enable Managed Scans dialog appears. By default, Semgrep runs both full and diff-aware scans.
5
Optional: Disable PR diff-aware scans by turning off the Enable PR/MR scans toggle.
6
Click Enable.
You have finished setting up a Semgrep Managed Scan.

What happens next

  • After enabling Managed Scans, Semgrep performs a full scan on the selected repositories in batches.
  • Each repository you add becomes a in Semgrep AppSec Platform containing its findings, scan history, and scan metadata.
  • Projects with a Managed Scan configuration are tagged with managed-scan, regardless of whether the project is actively being scanned.

Manage scans and projects

After you enable Managed Scans, Cursor Origin projects use the same controls as other source code managers. To open a project’s settings, go to Projects, find the project, and click Details > Settings. From there, you can:
  • Run a full scan
  • Turn diff-aware PR scans on or off
  • Turn Managed full scans or Managed diff scans off for that project
  • Delete the project
See Semgrep Managed Scans for how Managed Scans schedule full and diff-aware scans.

Pull request checks and comments

When Managed Scans run on a Cursor pull request, Semgrep can post a scan check and finding comments on that PR. A failing Semgrep check blocks merging only if Cursor requires that check. To receive PR comments:
1
Connect Cursor Origin and add the repository to Managed Scans, including PR (diff-aware) scans.
2
Configure your in Unified policies to leave PR comments for the findings you want developers to see.
3
Open or update a pull request in Cursor Origin. After the Managed Scan finishes, review the Semgrep check and any finding comments on the PR.
During the beta, triage by responding to PR comments and Autofix pull requests are not available for Cursor Origin.

Manage repository access

Change repository access

To limit which repositories Semgrep can access without disconnecting Cursor Origin:
1
In Cursor, update the app installation and select only the repositories Semgrep should access.
2
In Semgrep AppSec Platform, go to Projects and click Sync projects.

Disconnect Cursor Origin

To remove the Cursor Origin connection from Semgrep:
1
In Semgrep AppSec Platform, click Settings > Source code managers.
2
On the Cursor Origin entry you want to remove, click Remove app, then click Remove to confirm.

Supported features and beta limitations

Feature coverage is still expanding; some capabilities available on GitHub, GitLab, Bitbucket, or Azure DevOps are not available for Cursor Origin yet.

Troubleshoot

Repositories do not appear

1
In Semgrep AppSec Platform, click Settings > Source code managers.
2
Confirm that your Cursor Origin connection shows a healthy status. Click Test if needed.
3
Return to Projects, then click Sync projects.
4
Optional: Perform a hard refresh (Ctrl+F5 or Cmd+Shift+R).
5
If repositories are still missing, open the app installation in Cursor and confirm Semgrep has access to those repositories. Then sync again in Semgrep.

Other issues