In Flashduty On-call
You can get the integration push URL in either of two ways.
Use a dedicated integration
- In the Flashduty console, select Channel and open a channel
- Select Configuration → Integrations → Private integration, then click Add an integration
- Select Semgrep and click Save
- Open the integration card and copy the push URL
Use a shared integration
- In the Flashduty console, go to Integration Center → Alert Events
- Select Semgrep and enter an integration name
- Configure the default route and choose a channel; you can add more rules under Routes after creation
- Click Save and copy the generated push URL
In Semgrep
You need admin access to Semgrep AppSec Platform.
1
Create a webhook integration
- In Semgrep AppSec Platform, click Settings → Integrations → Add integration and select Webhook
- Enter an integration name in Name
- Paste the full Flashduty push URL, including
integration_key, into Webhook URL - Signature Secret is optional (at least 15 characters). If you set one, Semgrep sends an
X-Semgrep-Signature-256header with every delivery; Flashduty does not verify it and authenticates with theintegration_keyin the URL - Click Subscribe
2
Turn notifications on in a policy
Create or edit a policy in Unified Policies, click Add action → Call a webhook, and select the webhook integration. The policy’s filters (severity, confidence, projects) decide which findings are sent to Flashduty. Semgrep requires at least one condition before it saves a policy, for example Confidence is any of High, Medium, Low.To receive supply chain incidents, turn on the Early notification for Supply Chain incidents policy and select the same webhook integration.
3
Save and verify
- In Settings → Integrations, click Test on the webhook integration and confirm Flashduty returns success. The test posts
[{"text":"Test Notification","username":"Semgrep"}]; Flashduty returns success and opens a separate Info alert titled “Semgrep test notification” that you close by hand - Commit code that matches a rule and run a scan, then confirm Flashduty receives a new alert
Payloads and recovery
Semgrep sends three kinds of objects, and one request can carry several:
Semgrep sends a finding only the first time it is detected and never sends update or fixed notifications, so Flashduty alerts do not recover automatically. Turn on the channel’s auto-resolve timeout (7 days suggested), or close alerts by hand after the issue is fixed.
Alert Key
The Alert Key is computed from the object type and the ID above, so a repeated delivery of the same finding merges, and a finding ID never merges with an incident ID that has the same number. Changes to the rule name or severity do not change the Alert Key. An object without its ID causes the whole request to be rejected.
Severity
A finding’s
severity is a number derived from the rule severity:
Supply chain incidents that affect your projects are always Critical.
Labels
Findings:
Supply chain incidents:
Every alert carries
source=semgrep and event_type (finding or supply_chain_incident). The alert description is the rule’s message; code snippets are not sent.
Troubleshooting
- Flashduty returns an invalid-parameter error: check that the webhook URL is complete and includes
integration_key; the error is also returned when a finding lacksnumeric_idor an incident lacksincident_id - No alerts arrive: check that the policy has a Call a webhook action; Semgrep notifies only the first time a finding is detected, so existing findings are not re-sent
- Alerts never close: Semgrep sends no recovery notification, so turn on the channel’s auto-resolve timeout
- Too many alerts: raise the severity or confidence filter in the Semgrep policy