Skip to main content
Supply Chain Autofix opens a PR or MR that upgrades a vulnerable dependency to a fixed version. You choose when to use Autofix by selecting Open Autofix PR on the finding’s Details page or by calling the API.
Supply Chain Autofix does not require Semgrep Multimodal or Upgrade Guidance (beta). You can open an Autofix PR or MR even if Upgrade Guidance is disabled or has not finished running. When Upgrade Guidance analysis has completed, Semgrep can include that information in the PR or MR description.

Open an Autofix PR or MR

1
In Semgrep AppSec Platform, go to Supply Chain.
2
Select a finding.
3
Click Fix > Open Autofix PR.
  • If Autofix is unavailable, Open Autofix PR does not appear in the Fix menu, or Semgrep shows a modal with setup instructions instead of opening the PR. See When Supply Chain Autofix is available.
Semgrep creates the branch and opens a PR or MR in the connected source code manager.

When Supply Chain Autofix is available

To use Supply Chain Autofix, you must meet the following requirements:

Project requirements

  • Enable Semgrep Supply Chain scans.
  • Run a full scan on a connected repository.
  • The project uses a supported ecosystem: JavaScript or Python.
  • The finding has a fixed version to upgrade to.

Repository requirements

  • Semgrep needs Contents: Read and write access to the repository so it can push a branch and open a PR or MR. See Grant read and write access.

Environment-specific requirements

What the PR or MR contains

Always included

The PR or MR always includes:
  • Changes to the manifest or lockfile needed to upgrade the dependency.
  • The dependency version Semgrep selected.
  • A summary of the finding’s severity and reachability.
  • Details about the vulnerability and links to its CVE references.
  • Relevant dependency release notes, changelogs, and commits.

Included when Upgrade Guidance is available

If Upgrade Guidance analysis has completed by the time you open the PR or MR, the description can also include affected files and functions and guidance on potential breaking changes. If analysis is still in progress or Upgrade Guidance is disabled, that information is not included. For upgrade analysis without opening a PR or MR, see Upgrade Guidance (beta).

Troubleshooting

If Autofix is unavailable, Open Autofix PR does not appear in the Fix menu, or Semgrep shows a modal with setup instructions instead of opening the PR.