Back to integrations
    SASTSCA

    Semgrep integration

    Find out which Semgrep Supply Chain and Semgrep Code findings are exploitable, with the evidence behind each verdict.

    Integration details

    Primary category

    Software Composition Analysis

    Sync direction

    Semgrep ↔ Konvu

    Konvu pulls Semgrep findings once a day and on demand. Supply Chain dismissals made in Konvu set the Semgrep triage state to ignored.

    Status

    Available

    Which Semgrep findings are exploitable in your code?

    Semgrep flags vulnerable dependencies in Supply Chain and risky code patterns in Semgrep Code. Konvu investigates each finding in the context of your application and returns a verdict with the evidence that settled it. When your team dismisses a Supply Chain finding in Konvu, Konvu sets its triage state in Semgrep to ignored.

    Semgrep findings Konvu analyzes

    SCA

    Semgrep Supply Chain

    Dependency vulnerabilities, imported with the reachability result Semgrep already computed.

    SAST

    Semgrep Code

    Rule matches in your own code, tied to repositories through your Semgrep projects.

    Not imported today

    • Semgrep Secrets findings

    Access and setup

    One Semgrep API token with the Web API scope, created in your Semgrep organization settings. The same token reads findings and updates triage state. Each Semgrep deployment is its own connection.

    To read findings

    • An API token with the Web API scope

    To write back

    • No extra scope. The same Web API token sets triage state.
    • Konvu reads your code through your GitHub or GitLab connection, not through Semgrep.

    How Konvu investigates Semgrep findings

    What Konvu receives

    For Semgrep Code: the rule and the matched code. For Supply Chain: the package, version, advisory, and Semgrep's reachability result.

    What Konvu checks

    • Where the flagged data comes from, and whether a request, file, or message an attacker controls can supply it.
    • Validation, typing, or framework behavior between the source and the flagged line.
    • For Supply Chain, whether the vulnerable function is called and the conditions it needs are present.

    What decides the verdict

    Konvu returns exploitable, false positive, or inconclusive, with the reasoning behind it: the code it read, the conditions it tested, and what settled the call. When the answer depends on something only your team knows, Konvu asks a question instead of guessing.

    Illustrative example

    A SQL injection match from Semgrep Code

    A made-up service, written to show how an investigation reads. Not a customer result.

    1. 1

      Scanner finding

      A Semgrep Code rule flags a raw SQL query built with an f-string in a Python API handler. The query interpolates an order_id value.

    2. 2

      Application context

      The handler is a FastAPI route. order_id is declared as an int path parameter, so FastAPI rejects any request where it is not an integer before the handler runs.

    3. 3

      Investigation

      Konvu traces order_id from the route definition to the query. The typed path parameter is its only source, and no other code calls the handler function with a different value.

    4. 4

      Verdict

      False positive. An integer cannot carry a SQL payload into this query.

    5. 5

      Evidence

      The route signature, the data flow from the parameter to the query, and the callers Konvu checked.

    6. 6

      Where it ends up

      The verdict and evidence are recorded on the finding in Konvu. Konvu does not change Semgrep Code findings, so the team triages this one in Semgrep. A parameterized query is still a reasonable cleanup.

    Writeback and controls

    What changes in Semgrep

    • Dismissing a Supply Chain finding in Konvu sets its Semgrep triage state to ignored, with the reason "false positive" and the note "Dismissed in Konvu".
    • Reopening it in Konvu sets the triage state back to reopened.

    Who triggers it

    A person. Konvu changes triage state only when someone on your team dismisses the finding in Konvu. It does not dismiss Semgrep findings on its own.

    What stays with your team

    • Triage of Semgrep Code findings, which Konvu does not change.
    • Detailed reasoning in Semgrep. Semgrep receives the triage state and a short note, and the evidence stays on the finding in Konvu.

    Evaluation questions