Semgrep incident
Dynamic Maven & Gradle dependency resolution impaired
Semgrep experienced a notice incident on September 1, 2026 affecting Managed Scans, lasting 1d 1h. The incident has been resolved; the full update timeline is below.
Affected components
Update timeline
- identified Sep 01, 2026, 10:50 PM UTC
A small number (<1%) of supply chain scans that dynamically resolve dependencies for gradle and maven projects have been failing since August 28, due to rate limiting applied by a public package registry. Affected projects may show incomplete or missing Supply Chain findings. We are rolling out a caching mirror to reduce the impact of these rate limits. Subsequent scheduled scans should resolve any impacted findings. No further action from customers is required at this time.
- identified Sep 01, 2026, 10:55 PM UTC
Under one percent of supply chain scans that dynamically resolve dependencies for gradle and maven projects have been failing, due to rate limiting applied by a third-party package registry. Affected projects may show incomplete or missing Supply Chain findings. We are rolling out a caching mirror to reduce the impact of these rate limits. Subsequent scheduled scans should resolve any impacted findings. No further action from customers is required at this time
- monitoring Sep 02, 2026, 04:25 PM UTC
The third party registry's rate limits have been lifted, and impact to scans appears mitigated.
- resolved Sep 03, 2026, 12:10 AM UTC
Dynamic maven & gradle scans are now operating as normal.