Semgrep incident

Dynamic Maven & Gradle dependency resolution impaired

Notice Resolved View vendor source →

Semgrep experienced a notice incident on September 1, 2026 affecting Managed Scans, lasting 1d 1h. The incident has been resolved; the full update timeline is below.

Started
Sep 01, 2026, 10:50 PM UTC
Resolved
Sep 03, 2026, 12:10 AM UTC
Duration
1d 1h
Detected by Pingoru
Sep 01, 2026, 10:50 PM UTC

Affected components

Managed Scans

Update timeline

  1. identified Sep 01, 2026, 10:50 PM UTC

    A small number (<1%) of supply chain scans that dynamically resolve dependencies for gradle and maven projects have been failing since August 28, due to rate limiting applied by a public package registry. Affected projects may show incomplete or missing Supply Chain findings. We are rolling out a caching mirror to reduce the impact of these rate limits. Subsequent scheduled scans should resolve any impacted findings. No further action from customers is required at this time.

  2. identified Sep 01, 2026, 10:55 PM UTC

    Under one percent of supply chain scans that dynamically resolve dependencies for gradle and maven projects have been failing, due to rate limiting applied by a third-party package registry. Affected projects may show incomplete or missing Supply Chain findings. We are rolling out a caching mirror to reduce the impact of these rate limits. Subsequent scheduled scans should resolve any impacted findings. No further action from customers is required at this time

  3. monitoring Sep 02, 2026, 04:25 PM UTC

    The third party registry's rate limits have been lifted, and impact to scans appears mitigated.

  4. resolved Sep 03, 2026, 12:10 AM UTC

    Dynamic maven & gradle scans are now operating as normal.