Skip to main content
Supply Chain Autofix opens a PR or MR that upgrades a vulnerable dependency to a fixed version. You choose when to use Autofix by selecting Open Autofix PR from a finding’s Fix menu or by calling the API. Supply Chain Autofix does not require Semgrep Multimodal or Upgrade Guidance (beta). You can open an Autofix PR or MR even if Upgrade Guidance is disabled or has not finished running. When Upgrade Guidance analysis has completed, Semgrep can include that information in the PR or MR description.

Prerequisites

To use Supply Chain Autofix, you must meet the following requirements:

Open an Autofix PR or MR

1
In Semgrep AppSec Platform, go to Supply Chain.
2
Select a finding.
3
Click Fix > Open Autofix PR.
  • If Autofix is unavailable, Open Autofix PR does not appear in the Fix menu, or Semgrep shows a modal with setup instructions instead of opening the PR.
Semgrep creates the branch and opens a PR or MR in the connected source code manager.

What the PR or MR contains

The PR or MR always includes:
  • Changes to the manifest or lockfile needed to upgrade the dependency.
  • The dependency version Semgrep selected.
  • A summary of the finding’s severity and reachability.
  • Details about the vulnerability and links to its CVE references.
  • Relevant dependency release notes, changelogs, and commits.
If Upgrade Guidance analysis has completed by the time you open the PR or MR, the description can also include affected files and functions and guidance on potential breaking changes. If analysis is still in progress or Upgrade Guidance is disabled, that information is not included. For upgrade analysis without opening a PR or MR, see Upgrade Guidance (beta).