†Semgrep Multimodal, Managed Scans, and Autofix on Bitbucket Cloud require a workspace access token, which is only available on Bitbucket Cloud Premium. Managed Scans and triage through PR comments also require workspace-level webhooks, which are not available on Bitbucket Cloud Free or Standard.
*Semgrep Managed Scans and triage through MR comments require access to group webhooks, which is unavailable to GitLab Free users.
Autofix is supported on all source code managers in the table above at supported plan tiers (see footnotes † and *). To use Autofix through the Semgrep Network Broker, upgrade to Network Broker 0.45.2 or later and set
allowCodeAccess to true for that SCM. This setting defaults to false. Older broker versions return a 403 allowlist error. See Use Semgrep Network Broker with Autofix.
Access limitations
You may need to add Semgrep’s IP addresses to your ingress and egress allowlists, or you can use the Network Broker, if any of the following conditions apply:- Your SCM offers security features that limit access to your resources
- Your SCM is behind a firewall or protected by network restrictions regarding access
- You are using a virtual private network (VPN)