diff --git a/docs/getting-started/scm-support.mdx b/docs/getting-started/scm-support.mdx index c67588cf3a..c7a7e25096 100644 --- a/docs/getting-started/scm-support.mdx +++ b/docs/getting-started/scm-support.mdx @@ -4,37 +4,33 @@ sidebarTitle: "Supported SCMs" description: "Semgrep supports the following source code managers (SCM) and plans to varying degrees. Please review the information for your specific SCM and plan to see what Semgrep features are available to you." --- -These columns cover multiple plans: +## Features + +These columns cover the following plans: - **GitHub**: Free, Pro, Team, and Enterprise Cloud - **GitLab**: Free, Premium, Ultimate, and GitLab Dedicated / Dedicated for Government - **GitLab Self-Managed**: Free, Premium, and Ultimate - **Bitbucket Cloud**: Free, Standard, and Premium -✅ Supported. ❌ Not supported. ⚠️ Supported only on some plans or versions; see the version shown or the note marked next to it. +✅ Supported  ·  ❌ Not supported  ·  ⚠️ Certain plans (see below)
-| Feature | GitHub | GitHub Enterprise Server | GitLab | GitLab Self-Managed | Bitbucket Cloud | Bitbucket Data Center | Azure DevOps Cloud | Azure DevOps Server | Cursor Origin§ | -| :--- | :---: | :---: | :---: | :---: | :---: | :---: | :---: | :---: | :---: | -| Diff-aware scans | ✅ | ✅ | ✅ | ✅ | ✅ | ⚠️ 8.8+ | ✅ | ❌ | ✅ | -| Sending findings to Semgrep AppSec Platform | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ❌ | ✅ | -| Default branch identification | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ❌ | ✅ | -| Pull request comments | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ❌ | ✅ | -| Triage through PR or MR comments | ✅ | ✅ | ⚠️* | ✅ | ⚠️† | ⚠️ 8.8+ | ✅ | ❌ | ❌ | -| Semgrep Managed Scans | ✅ | ✅ | ⚠️* | ⚠️* | ⚠️† | ✅ | ✅ | ❌ | ✅ | -| Semgrep Multimodal | ✅ | ✅ | ✅ | ✅ | ⚠️† | ✅ | ✅ | ❌ | ✅ | -| Generic secrets (requires Semgrep Multimodal) | ✅ | ✅ | ✅ | ✅ | ⚠️† | ✅ | ✅ | ❌ | ✅ | -| Autofix | ✅ | ✅ | ✅ | ✅ | ⚠️† | ✅ | ✅ | ✅ | ❌ | -| Query console | ✅ | ✅ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ✅ | -| Semgrep Network Broker | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ❌ | -| Semgrep Agentic Workflows | ✅ | ✅ | ✅ | ✅‡ | ✅ | ✅ | ✅ | ✅ | ❌ | - -
- -
- -Diff-aware scans and triage through PR comments require Bitbucket Data Center version 8.8 or later. +| Feature | GitHub | GitHub Enterprise Server | GitLab | GitLab Self-Managed | Bitbucket Cloud | Bitbucket Data Center | Azure DevOps Cloud | Cursor Origin§ | +| :--- | :---: | :---: | :---: | :---: | :---: | :---: | :---: | :---: | +| Diff-aware scans | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | +| Sending findings to Semgrep AppSec Platform | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | +| Default branch identification | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | +| Pull request comments | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | +| Triage through PR or MR comments | ✅ | ✅ | ⚠️* | ⚠️* | ⚠️† | ✅ | ✅ | ❌ | +| Semgrep Managed Scans | ✅ | ✅ | ⚠️* | ⚠️* | ⚠️† | ✅ | ✅ | ✅ | +| Semgrep Multimodal | ✅ | ✅ | ✅ | ✅ | ⚠️† | ✅ | ✅ | ✅ | +| Generic secrets | ✅ | ✅ | ✅ | ✅ | ⚠️† | ✅ | ✅ | ✅ | +| Autofix | ✅ | ✅ | ✅ | ✅ | ⚠️† | ✅ | ✅ | ❌ | +| Query console | ✅ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | +| Semgrep Network Broker | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ❌ | +| Semgrep Agentic Workflows | ✅ | ✅ | ✅ | ✅‡ | ✅ | ✅ | ✅ | ❌ |
@@ -62,13 +58,21 @@ Diff-aware scans and triage through PR comments require Bitbucket Data Center ve -[Autofix](/semgrep-code/triage-remediation/autofix) is supported on all source code managers in the table above at supported plan tiers (see footnotes † and *). To use Autofix through the [Semgrep Network Broker](/semgrep-ci/network-broker), upgrade to Network Broker 0.45.2 or later and set `allowCodeAccess` to `true` for that SCM. This setting defaults to `false`. Older broker versions return a 403 allowlist error. See [Use Semgrep Network Broker with Autofix](/semgrep-ci/network-broker#use-semgrep-network-broker-with-autofix). +## Minimum versions for self-hosted SCMs + +Semgrep doesn't support versions older than the minimum. -## Recommended GitLab version +| SCM | Minimum version | Recommended version | +| :--- | :--- | :--- | +| GitHub Enterprise Server | 3.9 | 3.10, for fine-grained personal access tokens | +| GitLab Self-Managed | 15.5 | 16.5, for [inline MR comments](#recommended-gitlab-version) | +| Bitbucket Data Center | 8.8 | 8.18, so Autofix can open draft PRs | -For GitLab Self-Managed, Semgrep recommends **GitLab 16.5 or later** for integrations that use unified diffs, including inline merge request comments from [Semgrep Agentic Workflows](/workflows/overview). + ## Access limitations diff --git a/docs/styles.css b/docs/styles.css index f41c378334..d466455c25 100644 --- a/docs/styles.css +++ b/docs/styles.css @@ -101,9 +101,10 @@ h1 { text-decoration: none !important; } -/* Footnote targets of the matrix's ⚠️ links: clear the sticky header and mark +/* Notes that the SCM support tables link to: clear the sticky header and mark the note the reader just jumped to. */ -[id^="note-"] { +[id^="note-"], +#recommended-gitlab-version { scroll-margin-top: 8rem; margin-block: 1rem; padding: 0.25rem 0.5rem; @@ -111,10 +112,12 @@ h1 { border-radius: 6px; } -[id^="note-"] > p { +[id^="note-"] > p, +#recommended-gitlab-version > p { margin: 0; } -[id^="note-"]:target { +[id^="note-"]:target, +#recommended-gitlab-version:target { background-color: rgba(202, 138, 4, 0.14); }