Skip to main content
YOUR DEPLOYMENT JOURNEY
Semgrep can create pull request (PR) comments in your GitHub repository. These comments provide a description of the issue detected by Semgrep and may offer possible solutions. These comments are a means for security teams, or any team responsible for creating standards to help their fellow developers write safe and standards-compliant code.

Conditions for PR comment creation

PR comments appear for the following types of scans under these conditions:

Steps to set up PR comments

Prerequisites

In addition to finishing the previous steps in your deployment journey, it is recommended to have completed a full scan on your default branch for the repository in which you want to receive comments.

Confirm your Semgrep account’s connection

Confirm that you have the correct connection and access:
1
In your Semgrep AppSec Platform account, click Settings > Source code managers.
2
Check that an entry for your GitHub org exists and is correct.

Confirm repository access

Ensure that Semgrep’s GitHub app (semgrep-app) has sufficient permissions to post PR comments:
1
Navigate to your semgrep-app settings:i. For personal accounts, navigate to the following URL https://github.com/settings/installations.ii. For organization accounts, navigate to the following URL, substituting YOUR_ORG_NAME with the name of your account: https://github.com/organizations/YOUR_ORG_NAME/settings/installations.
2
On the semgrep-app row, click Configure.
3
Check that you have granted the following permission: Read and write access to actions, pull requests, secrets, security events, and workflows.
4
Under Repository access, check that the repositories you added to Semgrep AppSec Platform are included.
For GitHub Actions users, no further steps need to be undertaken. Continue setting up PR comments by configuring comments for Semgrep Code.

Required environment variables

For CI providers aside from GitHub Actions, additional environment variables must be set:
  • SEMGREP_PR_ID is set to the PR number of the pull request on GitHub Actions.
  • SEMGREP_REPO_NAME is set to the repository name.
  • SEMGREP_REPO_URL is set to the repository URL where your project is viewable online.
These values do not have to be fixed or hardcoded. They can be variables passed to the job. For more information, see Sample CI configurations.

Configure pull request comments

Once Semgrep and GitHub are connected, you can create a remediation policy that lets you define the conditions under which Semgrep leaves a pull request comment. This customization enables you to:
  • Manage the amount of PR comments your developers receive.
  • Ensure that only rules that meet your criteria, such as high severity or high confidence rules, produce comments visible to developers, reducing noise.

Receive comments in your VPN or on-premise SCM

If you are behind a firewall, are using a virtual private network (VPN), or have network restrictions regarding access, you may need to add the following IP addresses to the ingress allowlist and egress allowlist:

Additional egress IP addresses

You must also add CloudFront IP addresses to your egress allowlist. Refer to Locations and IP address ranges of CloudFront edge servers for a list of IP addresses.

Test your configuration

Test that you are able to receive findings by manually triggering a scan through your CI provider. Receiving PR or MR comments may require additional steps depending on the custom configuration of your VPN or SCM (for example, if you use a static IP without a hostname). Reach out to Semgrep Support with any concerns. You’ve set up PR comments! Enable optional features provided in the following sections, or see Next steps.

Optional features

Enable Rule-defined fix in GitHub repositories

Rule-defined fix is a Semgrep feature in which rules contain suggested fixes to resolve findings. To enable Rule-defined fix for all projects in your Semgrep AppSec Platform organization, follow these steps:
1
In Semgrep AppSec Platform, go to Settings > General > Code.
2
Click the Rule-defined fix toggle to enable this feature.

Dataflow traces in PR comments

With dataflow traces, Semgrep Code provides you a visualization of the path of tainted, or untrusted, data in specific findings. This path can help you track the sources and sinks of the tainted data as they propagate through the body of a function or a method. For general information about taint analysis, see Taint tracking. You can view dataflow traces in the PR comments created by Semgrep Code running in your CI/CD system.

View the path of tainted data in PR comments

To enable dataflow traces feature in your CI pipeline, fulfill the following prerequisites:
  • Set up Semgrep to post GitHub PR comments, as described on this page.
  • To obtain meaningful results of dataflow traces in PR comments, use rules with taint tracking while scanning your repositories.
  • Not all Semgrep rules or rulesets make use of taint tracking. Ensure that you have a ruleset that does, such as the default ruleset, added in your Policies. To add this ruleset, navigate to https://semgrep.dev/p/default, and then click Add to Policies.
  • You can add additional rules that use taint tracking from Semgrep Registry.

Prevent developers from merging a PR with a reachable vulnerability

You can use GitHub’s feature requiring conversation resolution before merging to prevent PRs from merging when Semgrep detects a reachable finding and leaves a comment.

Customize PR comments

You can customize the comments Semgrep leaves on your PR. Custom comments allow you to direct your teams to the resources they need to handle the vulnerabilities Semgrep identifies in their code. To provide custom PR comments:
2
Navigate to Settings > General > Global.
3
Go to the Custom PR/MR comments footers section.
4
Provide a custom comment for each Semgrep product whose findings you want to generate a PR comment. Semgrep supports HTML, Markdown, and plaintext links in your message.
5
Click Save changes.

Next steps

You’ve finished setting up a core deployment of Semgrep 🎉.

Additional references

Why am I not receiving PR or MR comments?

Why did the comments on a PR or MR not appear inline?