Semgrep Status
Dynamic Maven & Gradle dependency resolution impaired

Started

Resolved

Duration

1 day

ResolvedVendor link
Affected:Managed Scans

Update timeline

Resolved

Dynamic maven & gradle scans are now operating as normal.

Monitoring

The third party registry's rate limits have been lifted, and impact to scans appears mitigated.

Identified

Under one percent of supply chain scans that dynamically resolve dependencies for gradle and maven projects have been failing, due to rate limiting applied by a third-party package registry. Affected projects may show incomplete or missing Supply Chain findings. We are rolling out a caching mirror to reduce the impact of these rate limits. Subsequent scheduled scans should resolve any impacted findings. No further action from customers is required at this time

Identified

A small number (<1%) of supply chain scans that dynamically resolve dependencies for gradle and maven projects have been failing since August 28, due to rate limiting applied by a public package registry. Affected projects may show incomplete or missing Supply Chain findings. We are rolling out a caching mirror to reduce the impact of these rate limits. Subsequent scheduled scans should resolve any impacted findings. No further action from customers is required at this time.

Dynamic Maven & Gradle dependency resolution impaired — Semgrep Incident Timeline & Status — DevHelm