> ## Documentation Index
> Fetch the complete documentation index at: https://semgrep-ee9d73d8-abhijna-tec-647-weekly-release-notes.mintlify.site/llms.txt
> Use this file to discover all available pages before exploring further.

# Set up GitLab merge request comments

<Note>
  **YOUR DEPLOYMENT JOURNEY**

  * You have gained the necessary [resource access and permissions](/deployment/checklist) required for deployment.
  * You have [created a Semgrep account and organization](/deployment/create-account-and-orgs).
  * You have [connected your source code manager](/deployment/connect-scm).
  * Optionally, you have [set up SSO](/deployment/sso).
  * You have successfully added a [Semgrep job](/deployment/add-semgrep-to-ci) to your CI workflow with [diff-aware scanning](/deployment/customize-ci-jobs/#set-up-diff-aware-scans).
</Note>

Semgrep can create **merge request (MR) comments** in your GitLab repository. These comments provide a description of the issue detected by Semgrep and may offer possible solutions. These comments are a means for security teams, or any team responsible for creating standards, to help their fellow developers write safe and standards-compliant code.

## Conditions for MR comment creation

MR comments appear for the following types of scans under these conditions:

| Type of scan                               | Product name               | Trigger condition                                                                                                                                                                                                                                              | How to set up                                                                                                                                                                                                                                                                                                                                               |
| :----------------------------------------- | :------------------------- | :------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | :---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Static application security testing (SAST) | Semgrep Code               | A comment appears when Semgrep generates a finding for a rule included in a [remediation policy](/semgrep-appsec-platform/unified-policies/overview) configured to leave MR comments. This lets you customize which findings generate comments for developers. | Complete the steps in the following sections:<br /> 1. [Confirm your Semgrep account's connection and access to your source code manager](#confirm-your-semgrep-accounts-connection).<br /><br /> 2. [Configure merge request comments](#configure-mr-comments)                                                                                             |
| Software composition analysis (SCA)        | Semgrep Supply Chain (SSC) | A comment appears based on the conditions you explicitly set in a [remediation policy](/semgrep-appsec-platform/unified-policies/overview) or when Semgrep detects a [license violation](/semgrep-supply-chain/license-compliance).                            | To receive Supply Chain comments, complete the steps in [Confirm account connection and access](#confirm-your-semgrep-accounts-connection) and [set up a policy](/semgrep-supply-chain/policies). <br /><br /> To receive license violation comments, [enable dependency search](/semgrep-supply-chain/dependency-search#enable-and-use-dependency-search). |
| Secrets                                    | Semgrep Secrets            | A comment appears when Semgrep generates a finding for a rule included in a [remediation policy](/semgrep-appsec-platform/unified-policies/overview) configured to leave MR comments.                                                                          | Complete the steps in the following sections:<br /> 1. [Confirm your Semgrep account's connection and access to your source code manager](#confirm-your-semgrep-accounts-connection).<br /><br /> 2. [Configure merge request comments](#configure-mr-comments).                                                                                            |

### Confirm your Semgrep account's connection

MR comments are enabled by default for users who have connected their GitLab group to Semgrep AppSec Platform. Confirm that you have the correct connection and access:

<Steps>
  <Step>
    In your Semgrep AppSec Platform account, click **Settings > Source code managers**.
  </Step>

  <Step>
    Check that an entry for your GitLab group exists and is correct.
  </Step>
</Steps>

#### Triage through MR comments

Developers can triage Semgrep findings without leaving GitLab by responding to the MR comments authored by Semgrep. To use this feature, you must have a paid GitLab plan, and must update your source code manager (SCM) connection to use an access token with an elevated role. This allows you to enable webhooks, which Semgrep requires for the triage through MR comments feature.

Ensure that you're using one of the following GitLab plans:

* GitLab Premium
* GitLab Ultimate
* GitLab Self Managed

<Steps>
  <Step>
    Log in to GitLab, and create an access token with access to the desired GitLab groups. Assign the `api` scope and one of the following roles:

    * `Owner`
    * `Admin`
  </Step>

  <Step>
    Return to Semgrep and [<Icon icon="external-link" iconType="solid" /> sign in](https://semgrep.dev/login).
  </Step>

  <Step>
    Go to **<Icon icon="gear" iconType="solid" /> Settings > Source code managers**, and find your GitLab connection.
  </Step>

  <Step>
    Click **Update access token**.
  </Step>

  <Step>
    In the **Update access token** dialog that appears, provide the new token you created. Click **Update** to save and proceed.
  </Step>

  <Step>
    Toggle the **Incoming webhooks** setting on.
  </Step>
</Steps>

Once you've successfully enabled webhooks and the **Default developer triage permissions** toggle is on, you can change the role for the token you provide to Semgrep to one that's more restrictive, such as `Developer`.

### Configure MR comments

Once you have set up the connection between Semgrep and GitLab, you can [create a remediation policy](/semgrep-appsec-platform/unified-policies/get-started#create-a-remediation-policy) that lets you define the conditions under which Semgrep leaves a merge request comment. This customization enables you to:

In addition to setting up the connection between Semgrep and GitLab, you must assign rules to Comment or Block mode. This customization enables you to:

* Manage the amount of MR comments your developers receive.
* Ensure that only rules that meet your criteria, such as high severity or high confidence rules, produce comments visible to developers, reducing noise.

### Receive comments in your VPN or on-premise SCM

If you are behind a firewall, are using a virtual private network (VPN), or have network restrictions regarding access, you may need to add the following IP addresses to the **ingress** allowlist and **egress** allowlist:

```bash theme={null}
# Ingress IP addresses (from Semgrep to your infrastructure)
# and egress IP addresses (from your infrastructure to Semgrep)
35.166.231.235
52.35.248.246
52.34.137.110
44.225.64.41
```

#### Additional egress IP addresses

You must also add **CloudFront IP addresses** to your **egress** allowlist. Refer to [ Locations and IP address ranges of CloudFront edge servers](https://docs.aws.amazon.com/AmazonCloudFront/latest/DeveloperGuide/LocationsOfEdgeServers.html) for a list of IP addresses.

#### Test your configuration

Test that you are able to receive findings by manually triggering a scan through your CI provider.

Receiving MR comments may require additional steps depending on the custom configuration of your VPN or SCM (for example, if you use a static IP without a hostname). Reach out to [Semgrep Support](/support) with any concerns.

You've set up MR comments! Enable optional features provided in the following sections, or see [Next steps](#next-steps).

## Optional features

### Enable Rule-defined fix in GitLab repositories

[Rule-defined fix](/writing-rules/rule-defined-fix) is a Semgrep feature in which rules contain suggested fixes to resolve findings.

To enable **Rule-defined fix** for all projects in your Semgrep AppSec Platform organization, follow these steps:

<Steps>
  <Step>
    In Semgrep AppSec Platform, go to **Settings > General > Code**.
  </Step>

  <Step>
    Use the **Rule-defined fix <Icon icon="toggle-large-on" iconType="solid" />** toggle to enable this feature.
  </Step>
</Steps>

### Dataflow traces in MR comments

With **dataflow traces**, Semgrep Code provides you a visualization of the path of tainted, or untrusted, data in specific findings. This path can help you track the sources and sinks of the tainted data as they propagate through the body of a function or a method. For general information about taint analysis, see [Taint tracking](/writing-rules/data-flow/taint-mode/overview).

You can view dataflow traces in the MR comments created by Semgrep Code.

#### View the path of tainted data in MR comments

To enable dataflow traces in your MR comments, fulfill the following prerequisites:

* Set up Semgrep to post GitLab merge request comments, as described on this page.
* To get the most meaningful results of dataflow traces in MR comments, use cross-file analysis while scanning your repositories. To enable cross-file analysis, see [<Icon icon="file-lines" iconType="regular" /> Perform cross-file analysis](/semgrep-code/semgrep-pro-engine-intro).
* Not all Semgrep rules or rulesets make use of taint tracking. Ensure that you have a ruleset such as the **default ruleset** added to your **[Policies](https://semgrep.dev/orgs/-/policies)**. If this ruleset is not added, go to [https://semgrep.dev/p/default](https://semgrep.dev/p/default), and then click **Add to Policy**. You can add rules that use taint tracking from [Semgrep Registry](https://semgrep.dev/explore).

### Customize MR comments

You can customize the comments Semgrep leaves on your MR. Custom comments allow you to direct your teams to the resources they need to handle the vulnerabilities Semgrep identifies in their code. To provide custom MR comments:

<Steps>
  <Step>
    Sign in to [ Semgrep AppSec Platform](https://semgrep.dev/login?).
  </Step>

  <Step>
    Navigate to **Settings > General > Global**.
  </Step>

  <Step>
    Go to the **Custom PR/MR comments footers** section.
  </Step>

  <Step>
    Provide a custom comment for each Semgrep product whose findings you want to generate a MR comment. Semgrep supports HTML, Markdown, and plaintext links in your message.
  </Step>

  <Step>
    Click **Save changes**.
  </Step>
</Steps>

## Next steps

You've finished setting up a core deployment of Semgrep 🎉.

* Explore recommended tasks after deployment in [<Icon icon="file-text" iconType="solid" /> Beyond core deployment](/deployment/beyond-core-deployment).

## Additional references

<CardGroup>
  <Card title="Why am I not receiving PR or MR comments?" icon="file-text" href="/kb/semgrep-appsec-platform/missing-pr-comments" horizontal />

  <Card title="Why did the comments on a PR or MR not appear inline?" icon="file-text" href="/kb/semgrep-appsec-platform/inline-pr-comments" horizontal />
</CardGroup>
