Semgrep (Preview)
Overview
Heeler uses Semgrep to support its static analysis security testing (SAST) capabilities. Information harvested from Semgrep is contextualized and surfaced when examining a service's Security analysis under SAST Findings. For example, after selecting the service data-warehouse, you can see its SAST Findings under Security.

Requirements
Permission to view Semgrep Settings
Permission to generate Semgrep API token
Semgrep Integration Information
Navigate to Settings
Navigate to Tokens and select API Tokens
Select Create new token

Add meaningful Secrets name, e.g.,
Heeler Integration Token
, (or leave default)Copy Secrets value
Update Token scopes
Agent (CI) — ✅
Web API — ✅
Save

Heeler Integration Setup
Select the
icon from the top navigation
Navigate to the Integrations tab
Click Add Integration and select Semgrep

Enter the requested information into the modal
Name - Add meaningful name, e.g.,
Company Semgrep Integration
. It does not have to match the name used in Semgrep settingsAPI Key - Value from step above

Confirm successful connection

Last updated
Was this helpful?