Skip to content

Update Semgrep Docker image and add justification for suppressions#292

Open
fproulx-boostsecurity wants to merge 2 commits intomainfrom
semgrep-converter-update
Open

Update Semgrep Docker image and add justification for suppressions#292
fproulx-boostsecurity wants to merge 2 commits intomainfrom
semgrep-converter-update

Conversation

@fproulx-boostsecurity
Copy link
Collaborator

This pull request updates the Docker image version used for the Semgrep post-processor in both scanners/boostsecurityio/semgrep/module.yaml and scanners/boostsecurityio/semgrep-pro/module.yaml. The change ensures both modules use the latest image for processing scan results.

Dependency updates:

  • Updated the Docker image for the Semgrep post-processor to public.ecr.aws/boostsecurityio/boost-scanner-semgrep:f27f250@sha256:1cee73b0942622296d82fcf2a85bb1e519b36fac83edb79a887d5d56dd454724 in both semgrep and semgrep-pro module configuration files. [1] [2]

Alig1493 added 2 commits March 2, 2026 10:42
Signed-off-by: Mohammed Ali Zubair <mohammed@boostsecurity.io>
* Suppression without justification is breaking validation for scan gateway processing.
* Now we add default justification messages for #nosemgrep.
@fproulx-boostsecurity fproulx-boostsecurity marked this pull request as ready for review March 2, 2026 15:44
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants