Skip to main content

17 docs tagged with "Semgrep Supply Chain"

View all tags

Apache Maven

Set up Semgrep Supply Chain to correctly detect packages in Maven.

Jenkins UI

Configure Jenkins to send the correct branch name to Semgrep AppSec Platform.

License compliance

Semgrep Supply Chain can detect and list a package's license. Prevent or exempt certain packages from being used based on their licenses.

Manage policies

Use policies to define the conditions in which developers are notified of a finding or potentially blocked from merging their PR or MR.

Overview

Learn how Semgrep leverages its engine to scan open source dependencies with high-signal rules.

SBOM

Generate a CycloneDX JSON or XML SBOM to view all repository dependencies.