In November 2025, Semgrep delivered a major update that directly impacts how large enterprises in the United States and globally manage application security, DevSecOps, and software quality programs. These updates enhance risk prioritization, governance, supply chain security, and developer productivity.
Cnapp Integrations with Cortex and Sysdig
Semgrep now integrates with Cortex and Sysdig CNAPP platforms to analyze deployment status and internet exposure for vulnerabilities. This allows enterprises to prioritize findings based on actual production impact, focusing remediation efforts on exposed services. Security leaders can now report on exploitable vulnerabilities instead of theoretical issues. DevOps teams can align remediation sprints with runtime exposure, reducing noisy backlogs and improving SLA compliance.
Cnapp Integration Validation and Health Visibility
Semgrep introduces a Validate button and clearer connection status for CNAPP integrations, showing the last successful sync and error details. Enterprise security teams benefit from stronger governance, simplified audit preparation, and reduced blind spots. On-call SREs and platform engineers can now verify integration health instantly, reducing the need for cross-team tickets.
GitHub App Installation via Non-Admin Links
Non-admin users can now complete Semgrep GitHub App installation using install-request links. This accelerates rollout across large organizations, especially in the United States, where global GitHub admins often slow adoption. Delegated administration models are supported, allowing business units to deploy security tools quickly without compromising enterprise control.
Unified Product Settings Page for Better Governance
All Semgrep product settings are now centralized on a single settings page. Security and platform leaders can review global configurations, integration policies, and data retention from one location. This simplifies audits, reduces configuration drift, and helps administrators troubleshoot issues efficiently. New administrators also onboard faster, with less reliance on tribal knowledge.
Stronger RBAC and Access Controls
Semgrep fixes previous RBAC issues and prevents users from removing their own access. Enterprises benefit from cleaner separation of duties, better compliance alignment, and more accurate dashboards. Team-based project ownership is now fully reflected in reporting, and administrators gain visibility into all projects, including legacy repositories.
Rich Public API for Projects and Views
Semgrep expands its Public API to allow updates and deletion of saved views, filtering of projects by status, modification of primary branches, and management of project tags. Scan metadata now includes commit and enabled product information. This enables automation, centralized governance, and precise traceability across large SDLC platforms.
Improved Token Management Performance
API and CLI token pages are now paginated, ensuring better performance for large enterprises managing hundreds of tokens. Admins can efficiently rotate, revoke, and audit tokens. This enhances security hygiene and supports the scaling of automated CI/CD pipelines without UI lag or timeouts.
Malicious Dependency Detection in Semgrep Supply Chain
Semgrep Supply Chain now detects malware, typosquatting, and credential-stealing packages, backed by over 80,000 rules. Enterprises can strengthen supply chain defenses, prevent compromised builds, and reduce financial and reputational risk. Developers gain real-time guardrails when integrating third-party libraries.
Control Over Malicious Dependency Rules and Jira Automation
Teams can toggle malicious dependency rules and automatically create Jira tickets for findings. Enterprises gain policy flexibility and integrated remediation workflows. AppSec leads can roll out scans in high-risk environments first, while Jira automations route tickets to the right teams for rapid response.
Accurate Supply Chain Data and Dependency Search
Semgrep fixes severity display, manifest support, paging, and dependency counts. Enterprises benefit from reliable risk posture, reduced misestimation of vulnerabilities, and future-proof scanning. Security analysts can trust severity levels for dashboards and policy creation, while developers get complete search results for dependency issues.
Semgrep Assistant Automated Analysis and Explanations
Semgrep Assistant now automatically analyzes all Critical and High severity findings and provides detailed rule explanations. Enterprises reduce triage overhead, improve auditability of AI decisions, and speed remediation. Developers understand threat models quickly, and AppSec engineers maintain consistent workflows without unexpected auto-triage effects.
Language-Specific Static Analysis for Go, Rust, and Scala
Semgrep improves taint tracking in Go, type alias handling in Rust, and match-expression analysis in Scala. Enterprises gain better coverage in modern high-performance tech stacks, reducing blind spots. Developers receive more accurate findings, fewer false positives, and better integration of secure coding practices into pipelines.
Smarter Branch Diffing via SCM
Semgrep now uses source code managers to determine branch changes for incremental scans. Enterprises implementing shift-left strategies benefit from accurate differential scanning, faster CI pipelines, and improved governance in complex network setups. Developers see findings related only to their changes, reducing friction.
Semgrep Assistant and MCP Hook Flag for Claude Code Agent
Semgrep integrates with Claude Code Agent using the MCP hook flag, triggering scans post-AI coding actions. Enterprises embedding AI-assisted development benefit from built-in security validation. Developers receive instant feedback, and AppSec teams enforce compliance automatically in AI-driven workflows.
Enterprise Benefits of Semgrep November 2025 Update
Semgrep 2025 updates deliver risk-based prioritization, supply chain protection, AI-assisted analysis, centralized governance, and automation-friendly APIs. Enterprises achieve stronger DevSecOps efficiency, reduced developer friction, and improved security posture across SDLC pipelines.
Recommended Next Steps with Merito
- Conduct risk-based AppSec workshops to map CNAPP, Supply Chain, and Assistant features to enterprise pipelines and compliance requirements.
- Implement API workflows, Jira automations, SCM integration, RBAC design, and token governance.
- Drive developer adoption with language-specific rules, Semgrep Assistant explanations, and malicious dependency guardrails, tracking key metrics for executive reporting.

.png&w=2560&q=75)