PREREQUISITES
- You have completed a Semgrep core deployment.
- You have set rules to Comment or Block mode in your Policies page.
- Azure DevOps Cloud
- Bitbucket Cloud
- GitHub
- GitLab
Building context for Semgrep Multimodal requires Azure DevOps permissions, specifically code access granted through an access token you generate through Azure DevOps. Ensure that the token has the following scopes:After enabling Semgrep Multimodal, you can configure the AI provider and enable additional features:
Code: Read & writePull Request Threads: Read & write
Enable Multimodal
Sign in to Semgrep AppSec Platform.
- Scan with AI-powered detection: Run AI-powered scans to identify complex business logic flaws, such as insecure direct object references (IDORs) and broken authorization issues. Enabling Semgrep Multimodal does not automatically run AI-powered scans.
- Weekly priority emails: Send weekly summary emails to organization admins highlighting the top three backlog priorities across all findings.
- Noise filter for Code PR/MR comments: Filter out findings identified as false positives. You can choose to suppress PR or MR comments entirely or display informational comments indicating that a finding is a false positive.
- Suggested fix: Enable Multimodal-generated autofix suggestions in PR and MR comments. You can also set a minimum confidence threshold for AI-generated fixes when a rule does not include a human-authored autofix.