Semgrep
Cortex Cloud AppSec integrates with Semgrep to ingest SCA and SAST findings into the unified AppSec data model.
The Semgrep integration enables automated, periodic ingestion of Semgrep scan results from Semgrep-scanned projects. The integration supports two scan types that can be enabled independently or together:
SCA (Software Composition Analysis): Ingests open-source dependency vulnerabilities, producing CVE-based vulnerability findings and software package assets
SAST (Static Application Security Testing): Ingests code-level security vulnerabilities, producing findings with precise source code locations, CWE classifications, and commit attribution
Prerequisites
Cortex Cloud requirements
User permissions: You need View/Edit permissions for Data Sources and Integrations. Use the AppSec Admin or Instance Administrator role.
Connected VCS: Connect a version control system and onboard at least one repository.
Semgrep requirements
API token: Create a Semgrep API token with the Web API scope. In Semgrep, go to Settings → Tokens → API tokens.
Egress path: Configure an egress path for outbound Semgrep-to-Cortex Cloud traffic.
Manage integration instances
Manage administration channels, credential rotation, and integration deletion in Third-party integrations lifecycle administration and automation.
Manage ingested findings
Investigate findings, prioritize issues, remediate risks, and enforce policies in Manage the third-party data lifecycle.
Next step
Last updated
Was this helpful?
