From 7c89a73a05720720dd5c51e25ff48deca7a0083d Mon Sep 17 00:00:00 2001 From: matthewdean-semgrep <198649744+matthewdean-semgrep@users.noreply.github.com> Date: Tue, 6 Oct 2026 19:10:14 -0700 Subject: [PATCH 01/14] docs(scm): correct SCM support values and add minimum versions Several cells claimed support that the code doesn't have. Query console only searches private repositories on GitHub.com. Semgrep can't connect to Azure DevOps Server at all. GitLab Self-Managed Free lacks group webhooks, just like GitLab Free. Supply Chain Autofix gets its own row, because its SCM support differs from Code Autofix. It doesn't work on Bitbucket Data Center. Nothing checks the version of a self-hosted SCM, so each minimum is the version that added an API Semgrep calls. The Bitbucket Data Center 8.8 minimum replaces the per-cell 8.8 notes. Co-Authored-By: Claude Opus 5.5 --- docs/getting-started/scm-support.mdx | 44 ++++++++++++++++++---------- 1 file changed, 28 insertions(+), 16 deletions(-) diff --git a/docs/getting-started/scm-support.mdx b/docs/getting-started/scm-support.mdx index c67588cf3a..f76da6453c 100644 --- a/docs/getting-started/scm-support.mdx +++ b/docs/getting-started/scm-support.mdx @@ -11,36 +11,32 @@ These columns cover multiple plans: - **GitLab Self-Managed**: Free, Premium, and Ultimate - **Bitbucket Cloud**: Free, Standard, and Premium -✅ Supported. ❌ Not supported. ⚠️ Supported only on some plans or versions; see the version shown or the note marked next to it. +✅ Supported. ❌ Not supported. ⚠️ Supported only on some plans; select it to see which.
-| Feature | GitHub | GitHub Enterprise Server | GitLab | GitLab Self-Managed | Bitbucket Cloud | Bitbucket Data Center | Azure DevOps Cloud | Azure DevOps Server | Cursor Origin§ | +| Feature | GitHub | GitHub Enterprise Server | GitLab | GitLab Self-Managed | Bitbucket Cloud | Bitbucket Data Center | Azure DevOps Cloud | Azure DevOps Server‖ | Cursor Origin§ | | :--- | :---: | :---: | :---: | :---: | :---: | :---: | :---: | :---: | :---: | -| Diff-aware scans | ✅ | ✅ | ✅ | ✅ | ✅ | ⚠️ 8.8+ | ✅ | ❌ | ✅ | +| Diff-aware scans | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ❌ | ✅ | | Sending findings to Semgrep AppSec Platform | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ❌ | ✅ | +| Links from findings to source code | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ❌ | ✅ | | Default branch identification | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ❌ | ✅ | | Pull request comments | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ❌ | ✅ | -| Triage through PR or MR comments | ✅ | ✅ | ⚠️* | ✅ | ⚠️† | ⚠️ 8.8+ | ✅ | ❌ | ❌ | +| Triage through PR or MR comments | ✅ | ✅ | ⚠️* | ⚠️* | ⚠️† | ✅ | ✅ | ❌ | ❌ | | Semgrep Managed Scans | ✅ | ✅ | ⚠️* | ⚠️* | ⚠️† | ✅ | ✅ | ❌ | ✅ | | Semgrep Multimodal | ✅ | ✅ | ✅ | ✅ | ⚠️† | ✅ | ✅ | ❌ | ✅ | | Generic secrets (requires Semgrep Multimodal) | ✅ | ✅ | ✅ | ✅ | ⚠️† | ✅ | ✅ | ❌ | ✅ | -| Autofix | ✅ | ✅ | ✅ | ✅ | ⚠️† | ✅ | ✅ | ✅ | ❌ | -| Query console | ✅ | ✅ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ✅ | -| Semgrep Network Broker | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ❌ | -| Semgrep Agentic Workflows | ✅ | ✅ | ✅ | ✅‡ | ✅ | ✅ | ✅ | ✅ | ❌ | - -
- -
- -Diff-aware scans and triage through PR comments require Bitbucket Data Center version 8.8 or later. +| Autofix | ✅ | ✅ | ✅ | ✅ | ⚠️† | ✅ | ✅ | ❌ | ❌ | +| Supply Chain Autofix | ✅ | ✅ | ✅ | ✅ | ⚠️† | ❌ | ✅ | ❌ | ❌ | +| Query console | ✅ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | +| Semgrep Network Broker | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ❌ | ❌ | +| Semgrep Agentic Workflows | ✅ | ✅ | ✅ | ✅‡ | ✅ | ✅ | ✅ | ❌ | ❌ |
-†Semgrep Multimodal, Managed Scans, and Autofix on Bitbucket Cloud require a [workspace access token](https://support.atlassian.com/bitbucket-cloud/docs/create-a-workspace-access-token/), which is only available on **Bitbucket Cloud Premium**. Managed Scans and triage through PR comments also require workspace-level webhooks, which are not available on Bitbucket Cloud Free or Standard. +†Semgrep Multimodal, Managed Scans, Autofix, and Supply Chain Autofix on Bitbucket Cloud require a [workspace access token](https://support.atlassian.com/bitbucket-cloud/docs/create-a-workspace-access-token/), which is only available on **Bitbucket Cloud Premium**. Managed Scans and triage through PR comments also require workspace-level webhooks, which are not available on Bitbucket Cloud Free or Standard.
@@ -56,13 +52,29 @@ Diff-aware scans and triage through PR comments require Bitbucket Data Center ve +
+ +‖Semgrep can't connect to Azure DevOps Server. + +
+
§Cursor Origin support is in beta. Feature parity with other SCMs is incomplete during the beta. See [Cursor Origin Managed Scans](/deployment/managed-scanning/cursor#supported-features-and-beta-limitations).
-[Autofix](/semgrep-code/triage-remediation/autofix) is supported on all source code managers in the table above at supported plan tiers (see footnotes † and *). To use Autofix through the [Semgrep Network Broker](/semgrep-ci/network-broker), upgrade to Network Broker 0.45.2 or later and set `allowCodeAccess` to `true` for that SCM. This setting defaults to `false`. Older broker versions return a 403 allowlist error. See [Use Semgrep Network Broker with Autofix](/semgrep-ci/network-broker#use-semgrep-network-broker-with-autofix). +To use [Autofix](/semgrep-code/triage-remediation/autofix) or [Supply Chain Autofix](/semgrep-supply-chain/autofix) through the [Semgrep Network Broker](/semgrep-ci/network-broker), upgrade to Network Broker 0.45.2 or later and set `allowCodeAccess` to `true` for that SCM. This setting defaults to `false`. Older broker versions return a 403 allowlist error. See [Use Semgrep Network Broker with Autofix](/semgrep-ci/network-broker#use-semgrep-network-broker-with-autofix). + +## Minimum versions for self-hosted SCMs + +Semgrep relies on APIs that these versions introduced. Earlier versions aren't supported. + +| SCM | Minimum version | Recommended version | +| :--- | :--- | :--- | +| GitHub Enterprise Server | 3.9 | — | +| GitLab Self-Managed | 15.5 | 16.5, for [inline MR comments](#recommended-gitlab-version) | +| Bitbucket Data Center | 8.8 | 8.18, so Autofix can open draft PRs | ## Recommended GitLab version From 899d62422982f6989f3dfded089ee30fa4f52093 Mon Sep 17 00:00:00 2001 From: matthewdean-semgrep <198649744+matthewdean-semgrep@users.noreply.github.com> Date: Tue, 6 Oct 2026 19:12:45 -0700 Subject: [PATCH 02/14] docs(scm): nest recommended GitLab version under minimum versions Co-Authored-By: Claude Opus 5.5 --- docs/getting-started/scm-support.mdx | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/docs/getting-started/scm-support.mdx b/docs/getting-started/scm-support.mdx index f76da6453c..b87426e197 100644 --- a/docs/getting-started/scm-support.mdx +++ b/docs/getting-started/scm-support.mdx @@ -76,7 +76,7 @@ Semgrep relies on APIs that these versions introduced. Earlier versions aren't s | GitLab Self-Managed | 15.5 | 16.5, for [inline MR comments](#recommended-gitlab-version) | | Bitbucket Data Center | 8.8 | 8.18, so Autofix can open draft PRs | -## Recommended GitLab version +### Recommended GitLab version For GitLab Self-Managed, Semgrep recommends **GitLab 16.5 or later** for integrations that use unified diffs, including inline merge request comments from [Semgrep Agentic Workflows](/workflows/overview). From 0c7195b9415151e4e56bad1416126f3a3963f94f Mon Sep 17 00:00:00 2001 From: matthewdean-semgrep <198649744+matthewdean-semgrep@users.noreply.github.com> Date: Tue, 6 Oct 2026 19:13:51 -0700 Subject: [PATCH 03/14] docs(scm): drop the Network Broker Autofix note duplicated on the Autofix pages Co-Authored-By: Claude Opus 5.5 --- docs/getting-started/scm-support.mdx | 2 -- 1 file changed, 2 deletions(-) diff --git a/docs/getting-started/scm-support.mdx b/docs/getting-started/scm-support.mdx index b87426e197..d3b4301cf6 100644 --- a/docs/getting-started/scm-support.mdx +++ b/docs/getting-started/scm-support.mdx @@ -64,8 +64,6 @@ These columns cover multiple plans: -To use [Autofix](/semgrep-code/triage-remediation/autofix) or [Supply Chain Autofix](/semgrep-supply-chain/autofix) through the [Semgrep Network Broker](/semgrep-ci/network-broker), upgrade to Network Broker 0.45.2 or later and set `allowCodeAccess` to `true` for that SCM. This setting defaults to `false`. Older broker versions return a 403 allowlist error. See [Use Semgrep Network Broker with Autofix](/semgrep-ci/network-broker#use-semgrep-network-broker-with-autofix). - ## Minimum versions for self-hosted SCMs Semgrep relies on APIs that these versions introduced. Earlier versions aren't supported. From 8c5b3c41aa39ccd4c2ecccff7f876b604bf19b20 Mon Sep 17 00:00:00 2001 From: matthewdean-semgrep <198649744+matthewdean-semgrep@users.noreply.github.com> Date: Tue, 6 Oct 2026 19:17:03 -0700 Subject: [PATCH 04/14] docs(scm): fold the GitLab 16.5 explanation into the minimum versions section Co-Authored-By: Claude Opus 5.5 --- docs/getting-started/scm-support.mdx | 6 +++--- docs/styles.css | 11 +++++++---- 2 files changed, 10 insertions(+), 7 deletions(-) diff --git a/docs/getting-started/scm-support.mdx b/docs/getting-started/scm-support.mdx index d3b4301cf6..0cd17e580f 100644 --- a/docs/getting-started/scm-support.mdx +++ b/docs/getting-started/scm-support.mdx @@ -74,11 +74,11 @@ Semgrep relies on APIs that these versions introduced. Earlier versions aren't s | GitLab Self-Managed | 15.5 | 16.5, for [inline MR comments](#recommended-gitlab-version) | | Bitbucket Data Center | 8.8 | 8.18, so Autofix can open draft PRs | -### Recommended GitLab version + ## Access limitations diff --git a/docs/styles.css b/docs/styles.css index f41c378334..d466455c25 100644 --- a/docs/styles.css +++ b/docs/styles.css @@ -101,9 +101,10 @@ h1 { text-decoration: none !important; } -/* Footnote targets of the matrix's ⚠️ links: clear the sticky header and mark +/* Notes that the SCM support tables link to: clear the sticky header and mark the note the reader just jumped to. */ -[id^="note-"] { +[id^="note-"], +#recommended-gitlab-version { scroll-margin-top: 8rem; margin-block: 1rem; padding: 0.25rem 0.5rem; @@ -111,10 +112,12 @@ h1 { border-radius: 6px; } -[id^="note-"] > p { +[id^="note-"] > p, +#recommended-gitlab-version > p { margin: 0; } -[id^="note-"]:target { +[id^="note-"]:target, +#recommended-gitlab-version:target { background-color: rgba(202, 138, 4, 0.14); } From 5ee274cdaeb47feca340be1cfbe791a894459b30 Mon Sep 17 00:00:00 2001 From: matthewdean-semgrep <198649744+matthewdean-semgrep@users.noreply.github.com> Date: Tue, 6 Oct 2026 19:17:29 -0700 Subject: [PATCH 05/14] docs(scm): add a Compatibility matrix heading Co-Authored-By: Claude Opus 5.5 --- docs/getting-started/scm-support.mdx | 2 ++ 1 file changed, 2 insertions(+) diff --git a/docs/getting-started/scm-support.mdx b/docs/getting-started/scm-support.mdx index 0cd17e580f..262d316ae1 100644 --- a/docs/getting-started/scm-support.mdx +++ b/docs/getting-started/scm-support.mdx @@ -4,6 +4,8 @@ sidebarTitle: "Supported SCMs" description: "Semgrep supports the following source code managers (SCM) and plans to varying degrees. Please review the information for your specific SCM and plan to see what Semgrep features are available to you." --- +## Compatibility matrix + These columns cover multiple plans: - **GitHub**: Free, Pro, Team, and Enterprise Cloud From 1e0ab297ffba9057ffb264da12718a0a057d52e8 Mon Sep 17 00:00:00 2001 From: matthewdean-semgrep <198649744+matthewdean-semgrep@users.noreply.github.com> Date: Tue, 6 Oct 2026 19:19:36 -0700 Subject: [PATCH 06/14] docs(scm): tighten the matrix legend and plan list intro Co-Authored-By: Claude Opus 5.5 --- docs/getting-started/scm-support.mdx | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/docs/getting-started/scm-support.mdx b/docs/getting-started/scm-support.mdx index 262d316ae1..04c5d14e44 100644 --- a/docs/getting-started/scm-support.mdx +++ b/docs/getting-started/scm-support.mdx @@ -6,14 +6,14 @@ description: "Semgrep supports the following source code managers (SCM) and plan ## Compatibility matrix -These columns cover multiple plans: +These columns cover the following plans: - **GitHub**: Free, Pro, Team, and Enterprise Cloud - **GitLab**: Free, Premium, Ultimate, and GitLab Dedicated / Dedicated for Government - **GitLab Self-Managed**: Free, Premium, and Ultimate - **Bitbucket Cloud**: Free, Standard, and Premium -✅ Supported. ❌ Not supported. ⚠️ Supported only on some plans; select it to see which. +✅ Supported  ·  ❌ Not supported  ·  ⚠️ Some plans only (select it for details)
From 359adb21986775180977c9a479b51165ba69957e Mon Sep 17 00:00:00 2001 From: matthewdean-semgrep <198649744+matthewdean-semgrep@users.noreply.github.com> Date: Tue, 6 Oct 2026 19:20:53 -0700 Subject: [PATCH 07/14] docs(scm): reword the warning legend entry Co-Authored-By: Claude Opus 5.5 --- docs/getting-started/scm-support.mdx | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/docs/getting-started/scm-support.mdx b/docs/getting-started/scm-support.mdx index 04c5d14e44..87132e5f1e 100644 --- a/docs/getting-started/scm-support.mdx +++ b/docs/getting-started/scm-support.mdx @@ -13,7 +13,7 @@ These columns cover the following plans: - **GitLab Self-Managed**: Free, Premium, and Ultimate - **Bitbucket Cloud**: Free, Standard, and Premium -✅ Supported  ·  ❌ Not supported  ·  ⚠️ Some plans only (select it for details) +✅ Supported  ·  ❌ Not supported  ·  ⚠️ Certain plans (see below)
From 1c91801c61d17396458e74be29c2001d90aac5a7 Mon Sep 17 00:00:00 2001 From: matthewdean-semgrep <198649744+matthewdean-semgrep@users.noreply.github.com> Date: Tue, 6 Oct 2026 19:29:48 -0700 Subject: [PATCH 08/14] docs(scm): cover Code and Supply Chain Autofix in one row The two rows only differed on Bitbucket Data Center, where Supply Chain Autofix clones from the wrong host. AIENG-3408 fixes that before this merges. Co-Authored-By: Claude Opus 5.5 --- docs/getting-started/scm-support.mdx | 5 ++--- 1 file changed, 2 insertions(+), 3 deletions(-) diff --git a/docs/getting-started/scm-support.mdx b/docs/getting-started/scm-support.mdx index 87132e5f1e..2c85656a64 100644 --- a/docs/getting-started/scm-support.mdx +++ b/docs/getting-started/scm-support.mdx @@ -28,8 +28,7 @@ These columns cover the following plans: | Semgrep Managed Scans | ✅ | ✅ | ⚠️* | ⚠️* | ⚠️† | ✅ | ✅ | ❌ | ✅ | | Semgrep Multimodal | ✅ | ✅ | ✅ | ✅ | ⚠️† | ✅ | ✅ | ❌ | ✅ | | Generic secrets (requires Semgrep Multimodal) | ✅ | ✅ | ✅ | ✅ | ⚠️† | ✅ | ✅ | ❌ | ✅ | -| Autofix | ✅ | ✅ | ✅ | ✅ | ⚠️† | ✅ | ✅ | ❌ | ❌ | -| Supply Chain Autofix | ✅ | ✅ | ✅ | ✅ | ⚠️† | ❌ | ✅ | ❌ | ❌ | +| Autofix (Code and Supply Chain) | ✅ | ✅ | ✅ | ✅ | ⚠️† | ✅ | ✅ | ❌ | ❌ | | Query console | ✅ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | | Semgrep Network Broker | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ❌ | ❌ | | Semgrep Agentic Workflows | ✅ | ✅ | ✅ | ✅‡ | ✅ | ✅ | ✅ | ❌ | ❌ | @@ -38,7 +37,7 @@ These columns cover the following plans:
-†Semgrep Multimodal, Managed Scans, Autofix, and Supply Chain Autofix on Bitbucket Cloud require a [workspace access token](https://support.atlassian.com/bitbucket-cloud/docs/create-a-workspace-access-token/), which is only available on **Bitbucket Cloud Premium**. Managed Scans and triage through PR comments also require workspace-level webhooks, which are not available on Bitbucket Cloud Free or Standard. +†Semgrep Multimodal, Managed Scans, and Autofix on Bitbucket Cloud require a [workspace access token](https://support.atlassian.com/bitbucket-cloud/docs/create-a-workspace-access-token/), which is only available on **Bitbucket Cloud Premium**. Managed Scans and triage through PR comments also require workspace-level webhooks, which are not available on Bitbucket Cloud Free or Standard.
From 396825b41969c1c8073f2f6f9de371ed15d65445 Mon Sep 17 00:00:00 2001 From: matthewdean-semgrep <198649744+matthewdean-semgrep@users.noreply.github.com> Date: Tue, 6 Oct 2026 19:32:41 -0700 Subject: [PATCH 09/14] docs(scm): label the Autofix row plainly Co-Authored-By: Claude Opus 5.5 --- docs/getting-started/scm-support.mdx | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/docs/getting-started/scm-support.mdx b/docs/getting-started/scm-support.mdx index 2c85656a64..91c58ac669 100644 --- a/docs/getting-started/scm-support.mdx +++ b/docs/getting-started/scm-support.mdx @@ -28,7 +28,7 @@ These columns cover the following plans: | Semgrep Managed Scans | ✅ | ✅ | ⚠️* | ⚠️* | ⚠️† | ✅ | ✅ | ❌ | ✅ | | Semgrep Multimodal | ✅ | ✅ | ✅ | ✅ | ⚠️† | ✅ | ✅ | ❌ | ✅ | | Generic secrets (requires Semgrep Multimodal) | ✅ | ✅ | ✅ | ✅ | ⚠️† | ✅ | ✅ | ❌ | ✅ | -| Autofix (Code and Supply Chain) | ✅ | ✅ | ✅ | ✅ | ⚠️† | ✅ | ✅ | ❌ | ❌ | +| Autofix | ✅ | ✅ | ✅ | ✅ | ⚠️† | ✅ | ✅ | ❌ | ❌ | | Query console | ✅ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | | Semgrep Network Broker | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ❌ | ❌ | | Semgrep Agentic Workflows | ✅ | ✅ | ✅ | ✅‡ | ✅ | ✅ | ✅ | ❌ | ❌ | From 13fc45df591b9c0823dabe99cd76de83b32607d0 Mon Sep 17 00:00:00 2001 From: matthewdean-semgrep <198649744+matthewdean-semgrep@users.noreply.github.com> Date: Tue, 6 Oct 2026 19:36:11 -0700 Subject: [PATCH 10/14] docs(scm): remove the Azure DevOps Server column Semgrep can't connect to Azure DevOps Server, so every cell in its column was unsupported. Co-Authored-By: Claude Opus 5.5 --- docs/getting-started/scm-support.mdx | 36 ++++++++++++---------------- 1 file changed, 15 insertions(+), 21 deletions(-) diff --git a/docs/getting-started/scm-support.mdx b/docs/getting-started/scm-support.mdx index 91c58ac669..375fb58804 100644 --- a/docs/getting-started/scm-support.mdx +++ b/docs/getting-started/scm-support.mdx @@ -17,21 +17,21 @@ These columns cover the following plans:
-| Feature | GitHub | GitHub Enterprise Server | GitLab | GitLab Self-Managed | Bitbucket Cloud | Bitbucket Data Center | Azure DevOps Cloud | Azure DevOps Server‖ | Cursor Origin§ | -| :--- | :---: | :---: | :---: | :---: | :---: | :---: | :---: | :---: | :---: | -| Diff-aware scans | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ❌ | ✅ | -| Sending findings to Semgrep AppSec Platform | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ❌ | ✅ | -| Links from findings to source code | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ❌ | ✅ | -| Default branch identification | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ❌ | ✅ | -| Pull request comments | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ❌ | ✅ | -| Triage through PR or MR comments | ✅ | ✅ | ⚠️* | ⚠️* | ⚠️† | ✅ | ✅ | ❌ | ❌ | -| Semgrep Managed Scans | ✅ | ✅ | ⚠️* | ⚠️* | ⚠️† | ✅ | ✅ | ❌ | ✅ | -| Semgrep Multimodal | ✅ | ✅ | ✅ | ✅ | ⚠️† | ✅ | ✅ | ❌ | ✅ | -| Generic secrets (requires Semgrep Multimodal) | ✅ | ✅ | ✅ | ✅ | ⚠️† | ✅ | ✅ | ❌ | ✅ | -| Autofix | ✅ | ✅ | ✅ | ✅ | ⚠️† | ✅ | ✅ | ❌ | ❌ | -| Query console | ✅ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | -| Semgrep Network Broker | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ❌ | ❌ | -| Semgrep Agentic Workflows | ✅ | ✅ | ✅ | ✅‡ | ✅ | ✅ | ✅ | ❌ | ❌ | +| Feature | GitHub | GitHub Enterprise Server | GitLab | GitLab Self-Managed | Bitbucket Cloud | Bitbucket Data Center | Azure DevOps Cloud | Cursor Origin§ | +| :--- | :---: | :---: | :---: | :---: | :---: | :---: | :---: | :---: | +| Diff-aware scans | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | +| Sending findings to Semgrep AppSec Platform | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | +| Links from findings to source code | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | +| Default branch identification | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | +| Pull request comments | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | +| Triage through PR or MR comments | ✅ | ✅ | ⚠️* | ⚠️* | ⚠️† | ✅ | ✅ | ❌ | +| Semgrep Managed Scans | ✅ | ✅ | ⚠️* | ⚠️* | ⚠️† | ✅ | ✅ | ✅ | +| Semgrep Multimodal | ✅ | ✅ | ✅ | ✅ | ⚠️† | ✅ | ✅ | ✅ | +| Generic secrets (requires Semgrep Multimodal) | ✅ | ✅ | ✅ | ✅ | ⚠️† | ✅ | ✅ | ✅ | +| Autofix | ✅ | ✅ | ✅ | ✅ | ⚠️† | ✅ | ✅ | ❌ | +| Query console | ✅ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | +| Semgrep Network Broker | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ❌ | +| Semgrep Agentic Workflows | ✅ | ✅ | ✅ | ✅‡ | ✅ | ✅ | ✅ | ❌ |
@@ -53,12 +53,6 @@ These columns cover the following plans:
-
- -‖Semgrep can't connect to Azure DevOps Server. - -
-
§Cursor Origin support is in beta. Feature parity with other SCMs is incomplete during the beta. See [Cursor Origin Managed Scans](/deployment/managed-scanning/cursor#supported-features-and-beta-limitations). From cdd86bcbb1ea3dc893142b1949d5bd1351f5ebc2 Mon Sep 17 00:00:00 2001 From: matthewdean-semgrep <198649744+matthewdean-semgrep@users.noreply.github.com> Date: Tue, 6 Oct 2026 19:38:11 -0700 Subject: [PATCH 11/14] docs(scm): rename the matrix heading to Features Co-Authored-By: Claude Opus 5.5 --- docs/getting-started/scm-support.mdx | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/docs/getting-started/scm-support.mdx b/docs/getting-started/scm-support.mdx index 375fb58804..8de5d07f9c 100644 --- a/docs/getting-started/scm-support.mdx +++ b/docs/getting-started/scm-support.mdx @@ -4,7 +4,7 @@ sidebarTitle: "Supported SCMs" description: "Semgrep supports the following source code managers (SCM) and plans to varying degrees. Please review the information for your specific SCM and plan to see what Semgrep features are available to you." --- -## Compatibility matrix +## Features These columns cover the following plans: From aca21d45ef6eb234afd7a14f0953d3f723487546 Mon Sep 17 00:00:00 2001 From: matthewdean-semgrep <198649744+matthewdean-semgrep@users.noreply.github.com> Date: Tue, 6 Oct 2026 20:08:47 -0700 Subject: [PATCH 12/14] docs(scm): shorten the generic secrets row label Co-Authored-By: Claude Opus 5.5 --- docs/getting-started/scm-support.mdx | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/docs/getting-started/scm-support.mdx b/docs/getting-started/scm-support.mdx index 8de5d07f9c..e7a8aed848 100644 --- a/docs/getting-started/scm-support.mdx +++ b/docs/getting-started/scm-support.mdx @@ -27,7 +27,7 @@ These columns cover the following plans: | Triage through PR or MR comments | ✅ | ✅ | ⚠️* | ⚠️* | ⚠️† | ✅ | ✅ | ❌ | | Semgrep Managed Scans | ✅ | ✅ | ⚠️* | ⚠️* | ⚠️† | ✅ | ✅ | ✅ | | Semgrep Multimodal | ✅ | ✅ | ✅ | ✅ | ⚠️† | ✅ | ✅ | ✅ | -| Generic secrets (requires Semgrep Multimodal) | ✅ | ✅ | ✅ | ✅ | ⚠️† | ✅ | ✅ | ✅ | +| Generic secrets | ✅ | ✅ | ✅ | ✅ | ⚠️† | ✅ | ✅ | ✅ | | Autofix | ✅ | ✅ | ✅ | ✅ | ⚠️† | ✅ | ✅ | ❌ | | Query console | ✅ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | | Semgrep Network Broker | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ❌ | From 312a83e25a6a883fa81d82d57da64dbc8c15b651 Mon Sep 17 00:00:00 2001 From: matthewdean-semgrep <198649744+matthewdean-semgrep@users.noreply.github.com> Date: Tue, 6 Oct 2026 20:10:51 -0700 Subject: [PATCH 13/14] docs(scm): drop the source-code links row Co-Authored-By: Claude Opus 5.5 --- docs/getting-started/scm-support.mdx | 1 - 1 file changed, 1 deletion(-) diff --git a/docs/getting-started/scm-support.mdx b/docs/getting-started/scm-support.mdx index e7a8aed848..7471c807d4 100644 --- a/docs/getting-started/scm-support.mdx +++ b/docs/getting-started/scm-support.mdx @@ -21,7 +21,6 @@ These columns cover the following plans: | :--- | :---: | :---: | :---: | :---: | :---: | :---: | :---: | :---: | | Diff-aware scans | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | | Sending findings to Semgrep AppSec Platform | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | -| Links from findings to source code | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | | Default branch identification | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | | Pull request comments | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | | Triage through PR or MR comments | ✅ | ✅ | ⚠️* | ⚠️* | ⚠️† | ✅ | ✅ | ❌ | From 148ebb265257a9ddd5cc4a9a8e04616d8a464b9c Mon Sep 17 00:00:00 2001 From: matthewdean-semgrep <198649744+matthewdean-semgrep@users.noreply.github.com> Date: Tue, 6 Oct 2026 20:12:02 -0700 Subject: [PATCH 14/14] docs(scm): state the version floors without claiming why Co-Authored-By: Claude Opus 5.5 --- docs/getting-started/scm-support.mdx | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/docs/getting-started/scm-support.mdx b/docs/getting-started/scm-support.mdx index 7471c807d4..c7a7e25096 100644 --- a/docs/getting-started/scm-support.mdx +++ b/docs/getting-started/scm-support.mdx @@ -60,11 +60,11 @@ These columns cover the following plans: ## Minimum versions for self-hosted SCMs -Semgrep relies on APIs that these versions introduced. Earlier versions aren't supported. +Semgrep doesn't support versions older than the minimum. | SCM | Minimum version | Recommended version | | :--- | :--- | :--- | -| GitHub Enterprise Server | 3.9 | — | +| GitHub Enterprise Server | 3.9 | 3.10, for fine-grained personal access tokens | | GitLab Self-Managed | 15.5 | 16.5, for [inline MR comments](#recommended-gitlab-version) | | Bitbucket Data Center | 8.8 | 8.18, so Autofix can open draft PRs |