Semgrep
Connect Semgrep to Iru Compliance Automation to collect findings, deployments, and policy evidence.
Iru connects to Semgrep to confirm code is scanned before it ships, with every finding tracked through to closure. It reads SAST findings, scan coverage, and rule enforcement status directly.
Key Capabilities
- Verify all projects are scanned
- Confirm critical and high findings are remediated within SLA
- Check that security rules are enforced in CI/CD
- Show that no blocking findings reach production
Evidence Collected
- SAST findings by severity
- Scan coverage across projects
- Remediation tracking
- Rule enforcement status