AWS CodeArtifact support is in private beta. To enable it for your organization, contact Semgrep Support.
How it works
- You add the CodeArtifact repository in Semgrep and save it. Semgrep shows a Semgrep role ARN, and generates an External ID when you save.
- You create an IAM role named
SemgrepCodeArtifactAccessin your AWS account. Its trust policy allows the Semgrep role ARN to assume it, but only with your External ID. - When a scan needs your packages, Semgrep assumes the role, requests a CodeArtifact authorization token, and uses it to download dependencies. Tokens expire after two hours.
Prerequisites
- A Maven repository in AWS CodeArtifact.
- Permission in your AWS account to create IAM roles and policies.
Step 1: Find your repository URL
Semgrep needs the repository’s Maven endpoint. It looks like this:Step 2: Add the registry in Semgrep and save it
Semgrep generates the External ID when you save the registry, so save it before you create the IAM role.1
Sign in to Semgrep AppSec Platform and navigate to Settings > Integrations.
2
Click Add, then select Registry. The Connect package registry drawer opens.
3
Fill in the registry details:
- Name: a display name for this registry in the Semgrep UI.
- Package manager: select Maven / Gradle.
- URL: paste your repository URL from Step 1. It must start with
https://. - Optional: select a Repository type if the repository serves only release artifacts, only snapshot artifacts, or both.
- Optional: select Use network broker for registry access if the registry is reachable only from a private network. This requires a Semgrep Network Broker. See Connect a private registry to Semgrep for details.
4
Under Authentication method, select AWS CodeArtifact (IAM role). This option appears only after you enter a CodeArtifact URL. The other methods on the form are Username and password, API token, and None (public registry). Semgrep doesn’t support token authentication for Maven repositories.When you select AWS CodeArtifact (IAM role), Semgrep shows three fields:
- IAM role ARN: the ARN of the role you create in Step 3. The form notes that the role must be named exactly
SemgrepCodeArtifactAccess. - External ID: read-only. Before you save, it shows Generated when you save this registry.
- Semgrep role ARN: read-only and already filled in. Semgrep uses this principal in your role’s trust policy.
5
In IAM role ARN, enter the ARN of the role you create in Step 3:The role doesn’t need to exist yet. Semgrep doesn’t contact AWS when you save.
6
Click Connect. The drawer stays open, switches to Edit package manager config, and now shows your External ID.
7
Copy the External ID and the Semgrep role ARN with the copy button next to each field. You need them in the next step. You can find them again later by opening the registry from Settings > Integrations.
Step 3: Create the IAM role in AWS
Trust policy
ReplaceSEMGREP_ROLE_ARN and EXTERNAL_ID with the values from Step 2:
Permissions policy
This policy grants read-only access to one repository. ReplaceREGION, ACCOUNT_ID, DOMAIN, and REPOSITORY:
To give Semgrep access to more repositories in the same domain, add their
repository ARNs to the ReadPackages statement.
Create the role
- AWS console
- AWS CLI
1
In the IAM console, go to Roles and click Create role.
2
Select Custom trust policy, paste the trust policy, and click Next.
3
Skip adding permissions and click Next.
4
Enter
SemgrepCodeArtifactAccess as the Role name and click Create role.5
Open the new role, click Add permissions > Create inline policy, select JSON, and paste the permissions policy. Name the policy, for example
SemgrepCodeArtifactRead, and click Create policy.Step 4: Verify the connection
Run a Managed Scan with Dynamic Dependency Resolution on a project that depends on a package from your CodeArtifact repository. When the scan finishes, the package appears in the project’s dependencies. If the scan fails with CodeArtifact registry credentials are unavailable, see Troubleshooting.More than one registry or organization
- Several repositories in one AWS account: they all use the same
SemgrepCodeArtifactAccessrole. Add each repository’s ARN toReadPackages, and each domain’s ARN toGetCodeArtifactTokenif they’re in different domains. Then add each one as a registry in Semgrep with the same role ARN. - Several Semgrep organizations using one AWS account: each organization has its own External ID. List all of them in the trust policy, for example
"sts:ExternalId": ["EXTERNAL_ID_1", "EXTERNAL_ID_2"].
Troubleshooting
The AWS CodeArtifact (IAM role) option doesn't appear
The AWS CodeArtifact (IAM role) option doesn't appear
The option only appears when the registry URL is a CodeArtifact URL: one that contains
.codeartifact. and ends in .amazonaws.com. Check that you pasted the Maven endpoint from Step 1. If the URL is correct and the option still doesn’t appear, CodeArtifact support isn’t enabled for your organization yet. Contact Semgrep Support to enable it.The External ID field is empty
The External ID field is empty
Semgrep generates the External ID when you save the registry. Click Connect to save it, then copy the value from the drawer.If you connected the registry before Semgrep started generating External IDs, the field stays empty until you save the registry again. Open the registry in Settings > Integrations, enter the role ARN in IAM role ARN again, and click Save changes. The Save changes button stays disabled until you change a field, which is why you need to re-enter the ARN. Then reopen the registry, copy the External ID, and add it to your role’s trust policy.
The Semgrep role ARN field is empty
The Semgrep role ARN field is empty
Contact Semgrep Support. Your organization’s Semgrep role isn’t configured yet.