Semgrep integration
Find out which Semgrep Supply Chain and Semgrep Code findings are exploitable, with the evidence behind each verdict.
Integration details
Primary category
Software Composition Analysis
Sync direction
Semgrep ↔ Konvu
Konvu pulls Semgrep findings once a day and on demand. Supply Chain dismissals made in Konvu set the Semgrep triage state to ignored.
Status
Available
Which Semgrep findings are exploitable in your code?
Semgrep flags vulnerable dependencies in Supply Chain and risky code patterns in Semgrep Code. Konvu investigates each finding in the context of your application and returns a verdict with the evidence that settled it. When your team dismisses a Supply Chain finding in Konvu, Konvu sets its triage state in Semgrep to ignored.
Semgrep findings Konvu analyzes
SCA
Semgrep Supply Chain
Dependency vulnerabilities, imported with the reachability result Semgrep already computed.
SAST
Semgrep Code
Rule matches in your own code, tied to repositories through your Semgrep projects.
Not imported today
- Semgrep Secrets findings
Access and setup
One Semgrep API token with the Web API scope, created in your Semgrep organization settings. The same token reads findings and updates triage state. Each Semgrep deployment is its own connection.
To read findings
- An API token with the
Web APIscope
To write back
- No extra scope. The same
Web APItoken sets triage state.
- Konvu reads your code through your GitHub or GitLab connection, not through Semgrep.
How Konvu investigates Semgrep findings
What Konvu receives
For Semgrep Code: the rule and the matched code. For Supply Chain: the package, version, advisory, and Semgrep's reachability result.
What Konvu checks
- Where the flagged data comes from, and whether a request, file, or message an attacker controls can supply it.
- Validation, typing, or framework behavior between the source and the flagged line.
- For Supply Chain, whether the vulnerable function is called and the conditions it needs are present.
What decides the verdict
Konvu returns exploitable, false positive, or inconclusive, with the reasoning behind it: the code it read, the conditions it tested, and what settled the call. When the answer depends on something only your team knows, Konvu asks a question instead of guessing.
Illustrative example
A SQL injection match from Semgrep Code
A made-up service, written to show how an investigation reads. Not a customer result.
- 1
Scanner finding
A Semgrep Code rule flags a raw SQL query built with an f-string in a Python API handler. The query interpolates an order_id value.
- 2
Application context
The handler is a FastAPI route. order_id is declared as an int path parameter, so FastAPI rejects any request where it is not an integer before the handler runs.
- 3
Investigation
Konvu traces order_id from the route definition to the query. The typed path parameter is its only source, and no other code calls the handler function with a different value.
- 4
Verdict
False positive. An integer cannot carry a SQL payload into this query.
- 5
Evidence
The route signature, the data flow from the parameter to the query, and the callers Konvu checked.
- 6
Where it ends up
The verdict and evidence are recorded on the finding in Konvu. Konvu does not change Semgrep Code findings, so the team triages this one in Semgrep. A parameterized query is still a reasonable cleanup.
Writeback and controls
What changes in Semgrep
- Dismissing a Supply Chain finding in Konvu sets its Semgrep triage state to ignored, with the reason "false positive" and the note "Dismissed in Konvu".
- Reopening it in Konvu sets the triage state back to reopened.
Who triggers it
A person. Konvu changes triage state only when someone on your team dismisses the finding in Konvu. It does not dismiss Semgrep findings on its own.
What stays with your team
- Triage of Semgrep Code findings, which Konvu does not change.
- Detailed reasoning in Semgrep. Semgrep receives the triage state and a short note, and the evidence stays on the finding in Konvu.
Evaluation questions
The technical detail
More integrations
View allArnica
Add exploitability verdicts with evidence to Arnica SCA and SAST findings, and send approved SCA dismissals back to Arnica.
- SCA
- SAST
- ASPM
Black Duck
Get an exploitability verdict with evidence for Black Duck Polaris SCA findings and Coverity SAST findings.
- SCA
- SAST
Checkmarx
Send Checkmarx One SCA and SAST results to Konvu for an exploitability verdict with evidence, through the Konvu API or a report upload.
- SAST
- SCA
GitHub
Prioritize GitHub CodeQL and Dependabot alerts by adding exploit context to each finding.
- SAST
- SCA
- Ticketing & Messaging
GitLab
Add exploitability analysis to GitLab's built-in SAST and SCA pipeline findings.
- SCA
- SAST
- Ticketing & Messaging
Snyk
Find out which Snyk Open Source and Snyk Code findings are exploitable in your code, with the evidence behind each verdict.
- SCA
- SAST
- Container Security