Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
56 changes: 30 additions & 26 deletions docs/getting-started/scm-support.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -4,37 +4,33 @@ sidebarTitle: "Supported SCMs"
description: "Semgrep supports the following source code managers (SCM) and plans to varying degrees. Please review the information for your specific SCM and plan to see what Semgrep features are available to you."
---

These columns cover multiple plans:
## Features

These columns cover the following plans:

- **GitHub**: Free, Pro, Team, and Enterprise Cloud
- **GitLab**: Free, Premium, Ultimate, and GitLab Dedicated / Dedicated for Government
- **GitLab Self-Managed**: Free, Premium, and Ultimate
- **Bitbucket Cloud**: Free, Standard, and Premium

✅ Supported. ❌ Not supported. ⚠️ Supported only on some plans or versions; see the version shown or the note marked next to it.
✅ Supported  ·  ❌ Not supported  ·  ⚠️ Certain plans (see below)

<div className="scm-support-matrix">

| Feature | <span>GitHub</span> | <span>GitHub Enterprise Server</span> | <span>GitLab</span> | <span>GitLab Self-Managed</span> | <span>Bitbucket Cloud</span> | <span>Bitbucket Data Center</span> | <span>Azure DevOps Cloud</span> | <span>Azure DevOps Server</span> | <span>Cursor Origin<a href="#note-cursor-origin-beta" title="Cursor Origin support is in beta">§</a></span> |
| :--- | :---: | :---: | :---: | :---: | :---: | :---: | :---: | :---: | :---: |
| Diff-aware scans | ✅ | ✅ | ✅ | ✅ | ✅ | <a href="#note-bitbucket-data-center-version" title="Requires Bitbucket Data Center 8.8 or later">⚠️&nbsp;8.8+</a> | ✅ | ❌ | ✅ |
| Sending findings to Semgrep AppSec Platform | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ❌ | ✅ |
| Default branch identification | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ❌ | ✅ |
| Pull request comments | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ❌ | ✅ |
| Triage through PR or MR comments | ✅ | ✅ | <a href="#note-gitlab-free" title="Not available on GitLab Free">⚠️*</a> | ✅ | <a href="#note-bitbucket-cloud-premium" title="Requires Bitbucket Cloud Premium">⚠️†</a> | <a href="#note-bitbucket-data-center-version" title="Requires Bitbucket Data Center 8.8 or later">⚠️&nbsp;8.8+</a> | ✅ | ❌ | ❌ |
| Semgrep Managed Scans | ✅ | ✅ | <a href="#note-gitlab-free" title="Not available on GitLab Free">⚠️*</a> | <a href="#note-gitlab-free" title="Not available on GitLab Free">⚠️*</a> | <a href="#note-bitbucket-cloud-premium" title="Requires Bitbucket Cloud Premium">⚠️†</a> | ✅ | ✅ | ❌ | ✅ |
| Semgrep Multimodal | ✅ | ✅ | ✅ | ✅ | <a href="#note-bitbucket-cloud-premium" title="Requires Bitbucket Cloud Premium">⚠️†</a> | ✅ | ✅ | ❌ | ✅ |
| Generic secrets (requires Semgrep Multimodal) | ✅ | ✅ | ✅ | ✅ | <a href="#note-bitbucket-cloud-premium" title="Requires Bitbucket Cloud Premium">⚠️†</a> | ✅ | ✅ | ❌ | ✅ |
| Autofix | ✅ | ✅ | ✅ | ✅ | <a href="#note-bitbucket-cloud-premium" title="Requires Bitbucket Cloud Premium">⚠️†</a> | ✅ | ✅ | ✅ | ❌ |
| Query console | ✅ | ✅ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ✅ |
| Semgrep Network Broker | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ❌ |
| Semgrep Agentic Workflows | ✅ | ✅ | ✅ | <a href="#note-gitlab-inline-comments" title="Inline MR comments require GitLab 16.5 or later">✅‡</a> | ✅ | ✅ | ✅ | ✅ | ❌ |

</div>

<div id="note-bitbucket-data-center-version">

Diff-aware scans and triage through PR comments require Bitbucket Data Center version 8.8 or later.
| Feature | <span>GitHub</span> | <span>GitHub Enterprise Server</span> | <span>GitLab</span> | <span>GitLab Self-Managed</span> | <span>Bitbucket Cloud</span> | <span>Bitbucket Data Center</span> | <span>Azure DevOps Cloud</span> | <span>Cursor Origin<a href="#note-cursor-origin-beta" title="Cursor Origin support is in beta">§</a></span> |
| :--- | :---: | :---: | :---: | :---: | :---: | :---: | :---: | :---: |
| Diff-aware scans | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ |
| Sending findings to Semgrep AppSec Platform | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ |
| Default branch identification | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ |
| Pull request comments | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ |
| Triage through PR or MR comments | ✅ | ✅ | <a href="#note-gitlab-free" title="Not available on GitLab Free">⚠️*</a> | <a href="#note-gitlab-free" title="Not available on GitLab Free">⚠️*</a> | <a href="#note-bitbucket-cloud-premium" title="Requires Bitbucket Cloud Premium">⚠️†</a> | ✅ | ✅ | ❌ |
| Semgrep Managed Scans | ✅ | ✅ | <a href="#note-gitlab-free" title="Not available on GitLab Free">⚠️*</a> | <a href="#note-gitlab-free" title="Not available on GitLab Free">⚠️*</a> | <a href="#note-bitbucket-cloud-premium" title="Requires Bitbucket Cloud Premium">⚠️†</a> | ✅ | ✅ | ✅ |
| Semgrep Multimodal | ✅ | ✅ | ✅ | ✅ | <a href="#note-bitbucket-cloud-premium" title="Requires Bitbucket Cloud Premium">⚠️†</a> | ✅ | ✅ | ✅ |
| Generic secrets | ✅ | ✅ | ✅ | ✅ | <a href="#note-bitbucket-cloud-premium" title="Requires Bitbucket Cloud Premium">⚠️†</a> | ✅ | ✅ | ✅ |
| Autofix | ✅ | ✅ | ✅ | ✅ | <a href="#note-bitbucket-cloud-premium" title="Requires Bitbucket Cloud Premium">⚠️†</a> | ✅ | ✅ | ❌ |
| Query console | ✅ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ |
| Semgrep Network Broker | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ❌ |
| Semgrep Agentic Workflows | ✅ | ✅ | ✅ | <a href="#note-gitlab-inline-comments" title="Inline MR comments require GitLab 16.5 or later">✅‡</a> | ✅ | ✅ | ✅ | ❌ |

</div>

Expand Down Expand Up @@ -62,13 +58,21 @@ Diff-aware scans and triage through PR comments require Bitbucket Data Center ve

</div>

[Autofix](/semgrep-code/triage-remediation/autofix) is supported on all source code managers in the table above at supported plan tiers (see footnotes † and *). To use Autofix through the [Semgrep Network Broker](/semgrep-ci/network-broker), upgrade to Network Broker 0.45.2 or later and set `allowCodeAccess` to `true` for that SCM. This setting defaults to `false`. Older broker versions return a 403 allowlist error. See [Use Semgrep Network Broker with Autofix](/semgrep-ci/network-broker#use-semgrep-network-broker-with-autofix).
## Minimum versions for self-hosted SCMs

Semgrep doesn't support versions older than the minimum.

## Recommended GitLab version
| SCM | Minimum version | Recommended version |
| :--- | :--- | :--- |
| GitHub Enterprise Server | 3.9 | 3.10, for fine-grained personal access tokens |
| GitLab Self-Managed | 15.5 | 16.5, for [inline MR comments](#recommended-gitlab-version) |
| Bitbucket Data Center | 8.8 | 8.18, so Autofix can open draft PRs |

For GitLab Self-Managed, Semgrep recommends **GitLab 16.5 or later** for integrations that use unified diffs, including inline merge request comments from [Semgrep Agentic Workflows](/workflows/overview).
<div id="recommended-gitlab-version">

GitLab introduced unified diff API support in version 16.5. The [`unidiff` option](https://docs.gitlab.com/api/repositories/#compare-branches-tags-or-commits) provides the file headers that Semgrep needs to associate added lines with a file. On older versions, workflow issues may appear in merge request summary comments instead of inline comments.
GitLab 16.5 added the [`unidiff` option](https://docs.gitlab.com/api/repositories/#compare-branches-tags-or-commits), which gives Semgrep the file headers it needs to place inline merge request comments from [Semgrep Agentic Workflows](/workflows/overview). On older versions, workflow issues appear in the merge request summary comment instead.

</div>

## Access limitations

Expand Down
11 changes: 7 additions & 4 deletions docs/styles.css
Original file line number Diff line number Diff line change
Expand Up @@ -101,20 +101,23 @@ h1 {
text-decoration: none !important;
}

/* Footnote targets of the matrix's ⚠️ links: clear the sticky header and mark
/* Notes that the SCM support tables link to: clear the sticky header and mark
the note the reader just jumped to. */
[id^="note-"] {
[id^="note-"],
#recommended-gitlab-version {
scroll-margin-top: 8rem;
margin-block: 1rem;
padding: 0.25rem 0.5rem;
margin-inline: -0.5rem;
border-radius: 6px;
}

[id^="note-"] > p {
[id^="note-"] > p,
#recommended-gitlab-version > p {
margin: 0;
}

[id^="note-"]:target {
[id^="note-"]:target,
#recommended-gitlab-version:target {
background-color: rgba(202, 138, 4, 0.14);
}
Loading