Qlty Software incident
Analysis builds failing for projects that use default Semgrep plugin
Qlty Software experienced a minor incident on October 8, 2026 affecting Code Analysis, lasting 1h 14m. The incident has been resolved; the full update timeline is below.
Affected components
Update timeline
- identified Oct 08, 2026, 10:17 PM UTC
Status: Identified Since 10:35 AM ET (14:35 UTC) on October 8, 2026, analysis builds fail for projects that use the Semgrep plugin. The build stops while installing Semgrep, before any analysis runs. Projects that do not use Semgrep are not affected. Coverage uploads are not affected. A workaround is available now (below). We are sorry for the disruption. What is happening Semgrep 1.144.0, the version Qlty installs by default, depends on a package called mcp that imports a private function from pydantic. pydantic 2.14.0, published at 10:34 AM ET (14:34 UTC) today, removed that function. Semgrep does not limit which pydantic version it installs, so every fresh install of Semgrep now picks up pydantic 2.14.0 and fails to start. The build log shows: ImportError: cannot import name 'eval_type_backport' from 'pydantic._internal._typing_extra' Semgrep releases 1.137.0 through 1.145.0 share this dependency and fail the same way. Releases 1.146.0 and later install correctly. Who is affected - Qlty Cloud: every analysis build for a project with Semgrep enabled fails while installing tools. Affected pull requests do not get an analysis result. - qlty CLI in CI, or on any machine installing Semgrep for the first time: `qlty check` fails while installing Semgrep. - qlty CLI on a machine where Semgrep was installed before 10:34 AM ET today: not affected. The installed copy keeps working until the tool cache is cleared. Workaround, available now in Semgrep to 1.179.0 in `.qlty/qlty.toml`: [[plugin]] name = "semgrep" version = "1.179.0" If your `qlty.toml` already has a `[[plugin]]` entry for `semgrep`, add or change its `version` line. Commit and push. The next Qlty Cloud build and the next `qlty check` run install 1.179.0, which works with pydantic 2.14.0. If you had already pinned Semgrep to a version between 1.137.0 and 1.145.0, you need to make this change yourself. Our fix changes the default version only and does not override a version you set. Semgrep 1.179.0 is 35 releases newer than 1.144.0. Its rules have changed in that time, so you may see new findings or lose some old ones after the switch. We chose 1.179.0 over a smaller jump because every Semgrep release between 1.146.0 and 1.178.0 depends on packages with open security advisories. What we are doing We are changing the default Semgrep version in the qlty CLI from 1.144.0 to 1.179.0 (https://github.com/qltysh/qlty/pull/2910). We will ship it in the next CLI release and roll it out to Qlty Cloud. After that, projects without an explicit Semgrep version build again with no change on your side. Builds that failed during the incident do not rerun on their own. Push a new commit to get a fresh result. Affected components Code Analysis (Partial outage)
- resolved Oct 08, 2026, 11:32 PM UTC
Status: Resolved This incident has been resolved. Affected components Code Analysis (Operational)