- Open Autofix pull requests or merge requests.
- Generate Upgrade Guidance for Supply Chain findings.
- Run a Managed Scan for a project using Maven registries.
1
Sign in to Semgrep AppSec Platform.
2
Navigate to Settings > Integrations.
3
Click Add, then select Registry.
4
In the dialog that appears, provide the following information:
- The Name of your registry.
- The .
- The Authentication method. If none is required, select None (public registry).
- Username and password: provide the required Username and Password.
- API token: provide the required token value.
- AWS CodeArtifact (IAM role): provide the ARN of an IAM role that Semgrep assumes. This option appears when you enter an AWS CodeArtifact Maven URL. It requires setup in your AWS account first, and Dynamic Dependency Resolution uses it. This option is in private beta. Contact Semgrep Support to enable it. See Connect an AWS CodeArtifact registry to Semgrep.
5
Optional: if your registry is only accessible from your private network, select Use network broker for registry access. This option requires a Semgrep Network Broker deployed within your network.When enabled, Semgrep routes registry traffic through the broker, allowing Semgrep to access registries that are not publicly accessible on the internet.
For the broker to reach your registry, its allowlist must include the registry URL. See Use Semgrep Network Broker for private registry access.
6
Click Connect to save your changes and proceed.