Prerequisites
Ensure that:- You have enabled Slack notifications from Semgrep.
- Your organization uses Unified Policies.
Set up incident notifications

The Early notification for Supply Chain incidents policy on the Policies page.
1
In your Slack workspace, find or create a channel for Semgrep notifications. Then, run
/semgrep_add_channel in the channel to make it available to your policies. See Receive Slack notifications for more information.2
In Semgrep AppSec Platform, go to Rules & Policies > Policies.
3
Find the policy named Early notification for Supply Chain incidents. Click its icon, then select Edit policy.
4
Go to Actions. Click Add action > Send a Slack message, and select the Slack channel you configured at the beginning of the setup process.
5
Click Update.
6
You will be redirected back to the Remediation policies page. Click the policy’s icon, then select Enable policy.
What to do during an incident
Every notification includes a View incident advisories button that takes you to the Advisories page, filtered to that incident. A View blog post button appears when Semgrep has published a blog post about the incident.1
Click View incident advisories to see the list of related advisories, including compromised packages and versions.
2
If your notification lists affected projects, initiate a scan on them to confirm and get up-to-date findings.
3
Remove or upgrade any compromised dependencies you find, then re-scan to confirm the findings clear. See Detect and remove malicious dependencies for remediation guidance.