Use cases
Software Products E-commerce MSPs Schools Development & Marketing DevOps Agencies Help Desk
Company
Internet Status Blog Pricing Log in Get started free

Outage in Semgrep

Dynamic Maven & Gradle dependency resolution impaired

Resolved Minor
September 01, 2026 - Started 2 days ago - Lasted 1 day
Official incident page

Incident Report

Summary AI Generated

A third-party package registry's rate limiting caused less than 1% of Semgrep supply chain scans using dynamic Maven and Gradle dependency resolution to fail, resulting in incomplete or missing Supply Chain findings. The issue lasted approximately 25 hours before the registry lifted its rate limits and Semgrep deployed a caching mirror as a longer-term mitigation. Subsequent scheduled scans automatically resolved any affected findings, with no customer action required.

A small number (<1%) of supply chain scans that dynamically resolve dependencies for gradle and maven projects have been failing since August 28, due to rate limiting applied by a public package registry. Affected projects may show incomplete or missing Supply Chain findings. We are rolling out a caching mirror to reduce the impact of these rate limits. Subsequent scheduled scans should resolve any impacted findings. No further action from customers is required at this time.

Trusted by 1,000+ teams

The Status Page Aggregator with Early Outage Detection

Stop finding out about outages from your users. Monitor 6,320+ cloud services and get alerted the second something breaks.

IsDown status aggregator dashboard
Latest Updates ( sorted recent to last )
RESOLVED about 19 hours ago - at 09/03/2026 12:10AM

Dynamic maven & gradle scans are now operating as normal.

MONITORING 1 day ago - at 09/02/2026 04:25PM

The third party registry's rate limits have been lifted, and impact to scans appears mitigated.

IDENTIFIED 2 days ago - at 09/01/2026 10:55PM

Under one percent of supply chain scans that dynamically resolve dependencies for gradle and maven projects have been failing, due to rate limiting applied by a third-party package registry.

Affected projects may show incomplete or missing Supply Chain findings. We are rolling out a caching mirror to reduce the impact of these rate limits. Subsequent scheduled scans should resolve any impacted findings. No further action from customers is required at this time

IDENTIFIED 2 days ago - at 09/01/2026 10:50PM

A small number (<1%) of supply chain scans that dynamically resolve dependencies for gradle and maven projects have been failing since August 28, due to rate limiting applied by a public package registry.

Affected projects may show incomplete or missing Supply Chain findings. We are rolling out a caching mirror to reduce the impact of these rate limits. Subsequent scheduled scans should resolve any impacted findings. No further action from customers is required at this time.

The Status Page Aggregator with Early Outage Detection

With IsDown, you can monitor all your critical services' official status pages from one centralized dashboard and receive instant alerts the moment an outage is detected. Say goodbye to constantly checking multiple sites for updates and stay ahead of outages with IsDown.

Start free trial

No credit card required · Cancel anytime · 6320 services available

Integrations with Slack Microsoft Teams Google Chat Datadog PagerDuty Zapier Discord Webhook