π Semgrep AppSec Platform
Added
- You can now reauthorize or reconnect supported OAuth ticketing integrations instead of creating a new connection.
Changed
- Improved scan configuration generation. Scans now start up to 6 seconds sooner.
- The Issues API now includes descriptions for the
status,triageState, andaggregateStatevalues, and points toaggregateStateas the recommended field. - Improved repository sync performance.
Fixed
- Fixed an issue where Azure DevOps service principal authentication failed with a missing package error. The failure affected repository sync, webhook autoscans, Autofix, and Autotriage for organizations using service principal credentials.
- Fixed an issue where receivers could not verify webhook signatures.
- Fixed an issue where a read-only API token could still update project tags.
- Fixed an issue where reinstalling the Slack app caused authorization to fail if the Slack workspace had changed.
- Fixed an issue where AI provider credentials could be saved for a provider outside the organizationβs allowed provider catalog.
- Fixed an issue where a remediation policy showed a failure badge on the Policies page if Semgrep no longer had its action logs.
π» Semgrep Code
Changed
- Autofix is now enabled for all customers. Autofix remains opt-in for each finding: it runs only when you request a fix from the finding Details page or through the API.
- Homebrew installs of Semgrep are no longer supported on Intel Macs.
Fixed
- Fixed an issue where a finding opened by a new version of a rule inherited the triage state of the finding it replaced.
βοΈ Semgrep Supply Chain
Added
- You can now add a webhook as an action on the Early notification for Supply Chain incidents policy, in addition to Slack.
Changed
- Supply Chain Autofix is now independent of Upgrade Guidance. You can open a Supply Chain Autofix pull request even when Upgrade Guidance is disabled or has not run. The setting has been renamed to Upgrade Guidance.
Fixed
- Fixed an issue where Upgrade Guidance did not appear for repositories with hundreds of direct dependency findings.
- Fixed an issue where an AWS CodeArtifact credential on one private registry prevented Semgrep from configuring other private registries during Dynamic Dependency Resolution.
π€ Semgrep Multimodal
Added
- Added the ability to record an ignore reason and a comment when triaging an Agentic Workflows issue.
Fixed
- Fixed an issue where the Activity timeline on an Agentic Workflows issue did not load if the history included a field the timeline does not show.
- Fixed an issue where block actions did not appear in the action results view even though the block had executed.
- Fixed an issue where the Remediation policies page listed an Agentic Workflows policy under Multiple finding types instead of Workflows when the workflow produced fix patches.
- Workflow jobs filters now persist across page refreshes and navigation.
π Semgrep Secrets
Fixed
- Fixed an issue where the Secrets Rules page loaded indefinitely if the organization did not have a Secrets policy. Semgrep now shows an unavailable state in that case, and a separate error if the policy configuration fails to load.