Skip to main content

๐Ÿค– Semgrep Multimodal

Added

Fixed

  • Fixed an issue where customers were required to enable Semgrep Managed Scans before they could run an on-demand AI-powered detection scan.

๐ŸŒ Semgrep AppSec Platform

Added

  • Webhook validation and test failure error messages now include specific failure reasons.
  • Semgrep now shows a confirmation warning when you add or remove project tags that are attached to policies, both during bulk edit and from a projectโ€™s settings page.

Fixed

  • Fixed an issue where the auto-ignore automation sometimes reverted a manual triage decision by setting all instances of the finding back to Provisionally ignored.
  • Fixed GitHub PAT setup errors so namespace permission failures now show clearer, more actionable messages.
  • Fixed an issue where Provisionally ignored findings could not be reopened from the finding Details page.
  • Fixed an issue where a Slack notification channel mapping was deleted when the Semgrep Slack app lacked permission to post to a private channel. Semgrep now removes the mapping only when the channel is deleted.

โ›“๏ธ Semgrep Supply Chain

Added

  • You can configure license compliance to block a dependency only when all of its licenses are blocked, instead of when any license is blocked.

Changed

  • Released a default Supply Chain incident notification policy to all Supply Chain customers using Unified policies. Organizations can configure a Slack channel to be notified during an ongoing Supply Chain incident, including whether they may be affected based on their most recent SBOM. Semgrep AppSec Platformโ€™s incident policy page has been redesigned to be visually distinctive from regular policy pages, and Semgrep now warns when a configured Slack channel cannot receive automated messages.

๐Ÿ”ง Semgrep Community Edition

The following versions of Semgrep Community Edition were released during the week of July 27-August 2, 2026:

1.172.0