🌐 Semgrep AppSec Platform
Added
- Cursor Origin support is now in public beta. You can connect Cursor Origin to Semgrep, sync repositories, run Managed Scans, and see scan checks and finding comments directly in Cursor pull requests. Set up the connection from Semgrep onboarding or the Cursor app installation flow.
- Added an
scmsconfiguration field to Semgrep Network Broker. Organizations that run multiple source code manager instances of the same type (GitHub, GitLab, Bitbucket, or Azure DevOps) and keep those instances off the public internet can list each instance inscmsinstead of maintaining a long custom allowlist per instance, and still keep endpoint-level protection. Per-SCM keys remain supported. This requires Network Broker v0.47.0 or later.
Changed
- Deployment tag API endpoints now require tag-specific API permissions. A token that can manage projects is no longer enough. Use a token with tag read permission to get, list, or find tags, and tag write permission to update or delete them.
Fixed
- Fixed an issue where repeated query parameters on v1 API endpoints were URL-decoded twice, so filters such as
reposdid not match repository names containing encoded characters, including Azure DevOps repositories with spaces in their names. Affected requests returned no findings, and a repository-filtered bulk triage could apply to a different repository. - Fixed an issue with permission detection for Azure DevOps and Bitbucket Data Center integrations. Previously, when Semgrep tested whether the token had write access, an HTTP 403 response was treated as success, so later Autofix actions failed. Semgrep now treats HTTP 403 as a lack of write access, so you can update the token before Autofix runs.
- Fixed an issue where a Network Broker allowlist refusal appeared as a source code manager permission error, so the error appeared to be about the token rather than the broker configuration.
- Fixed an issue with Semgrep Code findings that are automatically triaged. Previously, when Autotriage moved a finding to Provisionally ignored, Unified Policies blocking rules applied only during the first scan of a pull request or merge request. On any later scan, those findings were not blocked. Policy-based blocking actions are now applied on every scan.
💻 Semgrep Code
Fixed
- Fixed an issue where
semgrep-coreoccasionally hung when it exited on Windows.
⛓️ Semgrep Supply Chain
Added
- AWS CodeArtifact support is now in private beta. You can connect a private Maven or Gradle registry so Dynamic Dependency Resolution can resolve packages during Managed Scans. Semgrep assumes an IAM role in your AWS account instead of storing AWS keys. Contact Semgrep Support to enable it for your organization.
Changed
- Read-only API tokens can now call the v1 Supply Chain dependency and SBOM export endpoints. These endpoints previously required an admin-only scope. A token returns only the repositories its owner can access.
🤖 Semgrep Multimodal
Changed
- Running AI analysis or opening an Autofix pull request now requires triage permission, because they spend the organization’s AI credits and can write to its source code manager. Read-only users receive an explanatory error.
🛡️ Semgrep Guardian
Changed
- Semgrep Guardian 2.5.4 and later now checks for updates and downloads a new binary as soon as it is released, rather than waiting for the coding agent to re-index the repository, which previously added up to a week of unpredictable delay. Guardian verifies that the new version works before switching to it. To opt out, set
SEMGREP_GUARDIAN_AUTO_UPDATE=0orauto_update: falseinguardian.yaml. - Semgrep Guardian now meets SLSA Level 3 standards and cryptographically verifies that a downloaded binary was produced by Semgrep’s build pipeline. Binaries are signed with a pipeline-only key, and Guardian rejects any binary that is not signed with that key. You can validate which commit a binary was built from and which pipeline built it.
📝 Documentation and knowledge base
Added
- Added documentation for adding Cursor Origin repositories to Managed Scans.
- Added documentation for connecting an AWS CodeArtifact registry to Semgrep Supply Chain.