Skip to main content
Semgrep’s Security Research team monitors the open source ecosystem and responds in real time when a package is compromised, publishing an Advisory as soon as an incident is confirmed. If you’ve configured the Early notification for Supply Chain incidents policy, Semgrep automatically posts to a Slack channel of your choosing within minutes of declaring the incident. You don’t have to look for the news yourself: Semgrep checks the compromised package versions against your projects’ most recent dependency data and tells you whether any of them are affected in the same notification. You are notified every time Semgrep declares a new supply chain incident, whether or not any of your projects use the affected packages.

Prerequisites

Ensure that:

Set up incident notifications

The Early notification for Supply Chain incidents policy, showing its condition (Supply chain incident declared) and action (Send a Slack message)

The Early notification for Supply Chain incidents policy on the Policies page.

1
In your Slack workspace, find or create a channel for Semgrep notifications. Then, run /semgrep_add_channel in the channel to make it available to your policies. See Receive Slack notifications for more information.
2
In Semgrep AppSec Platform, go to Rules & Policies > Policies.
3
Find the policy named Early notification for Supply Chain incidents. Click its icon, then select Edit policy.
4
Go to Actions. Click Add action > Send a Slack message, and select the Slack channel you configured at the beginning of the setup process.
5
Click Update.
6
You will be redirected back to the Remediation policies page. Click the policy’s icon, then select Enable policy.

What to do during an incident

Every notification includes a View incident advisories button that takes you to the Advisories page, filtered to that incident. A View blog post button appears when Semgrep has published a blog post about the incident.
1
Click View incident advisories to see the list of related advisories, including compromised packages and versions.
2
If your notification lists affected projects, initiate a scan on them to confirm and get up-to-date findings.
3
Remove or upgrade any compromised dependencies you find, then re-scan to confirm the findings clear. See Detect and remove malicious dependencies for remediation guidance.

Malware incident response with Semgrep Supply Chain

Detect and remove malicious dependencies