A Semgrep scan is having a problem - what next?
Troubleshoot common issues with Semgrep scans.
Troubleshoot common issues with Semgrep scans.
Set up Semgrep Supply Chain to correctly detect packages in Maven.
Search through all your dependencies in all your onboarded repositories at any time.
How to generate lockfiles for Semgrep Supply Chain in a Circle CI pipeline.
Generate various Python lock files to run Semgrep Supply Chain scans successfully.
Prevent unwanted noise when scanning for dependency vulnerabilities by ignoring lockfiles or code files.
Refer to this section to set up Semgrep Supply Chain for your specific tooling or pipeline.
Configure Jenkins to send the correct branch name to Semgrep AppSec Platform.
Semgrep Supply Chain can detect and list a package's license. Prevent or exempt certain packages from being used based on their licenses.
Learn how Semgrep leverages its engine to scan open source dependencies with high-signal rules.
Generate a CycloneDX JSON or XML SBOM to view all dependencies of a repository.
Customize how Semgrep Supply Chain scans your codebase's open source dependencies.
Definitions of Semgrep Supply Chain and software composition analysis (SCA) terms.
Perform triage and remediation of dependency vulnerabilities through Semgrep Supply Chain.
Troubleshoot why findings for Semgrep Supply Chain are not showing.