Skip to main content
{ Reporting and Compliance / Vulnerability Management }

Semgrep Posture Report

Delivers a weekly report on Semgrep coverage, what changed, and anything in the deployment that needs attention, from failing scans to contributor licenses.

What this agent does

This read-only agent checks the health of a Semgrep deployment every week. It compares the repositories in the source code provider it is connected to with the repositories Semgrep scans, and it finds repositories that are missing, failing, or no longer scanned. It summarizes the findings that appeared, were fixed, or were ignored since last week, and any policy changes. It flags anything that needs an admin, such as failing scans, a policy moved out of blocking mode, or contributor licenses close to the limit.

The challenge

Semgrep only protects the repositories where its scans run, and gaps in coverage are easy to miss. New repositories never get the CI job, a workflow change breaks the scan, and nobody notices the missing results. A rule switched from blocking to monitoring no longer blocks pull requests. Contributor licenses run out as the team grows, and admins find out when something breaks.

The solution

The agent checks coverage, activity, policies, and licenses in one pass each week and compares them with the previous week. It lists what changed and what someone needs to act on, with the fix for each item. Provides a weekly briefing an admin can read in a few minutes.

Workflow

  1. 01

    Check coverage

    Compare the organization's repositories with the repositories Semgrep scans, and find the ones missing, failing, or not scanned recently.

  2. 02

    Check activity

    Summarize findings that appeared, were fixed, or were ignored since last week, and any policy or rule changes.

  3. 03

    Check the deployment

    Check source code connections, tokens, and contributor licenses against the plan's limits.

  4. 04

    Report

    Publish what changed and what needs action, with the fix for each item.

Agent template

# Semgrep Posture Report

## Measurable outcomes

Every week, the admin knows which repositories Semgrep is not covering, what changed in the deployment, and what needs action before it breaks. Track covered and uncovered repositories and open action items on every run.

## Procedure

Once a week, compare the active repositories in the connected source code provider, such as a GitHub organization, GitLab group, or Bitbucket workspace, with the repositories Semgrep scans. List the repositories that have never been scanned, whose last scan failed, or that have not been scanned in the last week, unless I set another window. Summarize the new Critical and High findings, the findings fixed, and the findings ignored since the last report, with the reason for each. List changes to policies and rule modes, and call out any rule moved from blocking to monitoring. Check the source code connection and API tokens, and flag any that are failing or about to expire. Compare contributor license use with the purchased count, and flag anything above 80 percent. Compare everything with last week's report, and lead with what changed. Give every action item the specific fix. Report a check it cannot run as not checked, never as fine.

## Requirements

It needs read-only Semgrep API access to the deployment and read access to the list of repositories in that source code provider, and nothing more. It never changes Semgrep settings, policies, or findings.