Skip to content
| Marketplace
Sign in
Visual Studio Code>Linters>SigridNew to Visual Studio Code? Get it now.
Sigrid

Sigrid

Software Improvement Group

|
71 installs
| (1) | Free
View and manage Sigrid findings in VS Code.
Installation
Launch VS Code Quick Open (Ctrl+P), paste the following command, and press enter.
Copied to clipboard
More Info

Sigrid (Visual Studio Code)

A Visual Studio Code extension that brings Sigrid findings directly into your editor via a lightweight dashboard.

🚀 Use the Sigrid: Show Findings command to open an interactive webview panel with security, maintainability, and other findings powered by your Sigrid account.


✅ Features

  • View Sigrid findings in VS Code without leaving your editor
  • Search and filter findings directly within the Sigrid dashboard
  • Interactive dashboard with filtering, navigation, and table controls
  • Deep link from findings to the Sigrid web UI
  • Configurable Sigrid instance URL (supports self-hosted deployments)
  • Create Jira issues from selected findings (when JIRA settings are configured)
  • Create Azure DevOps work items from selected findings (when Azure DevOps settings are configured)
  • Fix with AI — hand selected findings off to a detected coding agent (Claude Code or GitHub Copilot Chat) with a generated prompt, using the Sigrid Axis plugin skills and MCP server when available
  • In-webview system onboarding — if the configured system isn't onboarded to Sigrid yet, onboard it directly from the panel without leaving VS Code

Visual Studio Code window showing the Sigrid extension dashboard with a findings panel Sigrid findings panel in VS Code with a table of findings

Sigrid extension's Open Source Health tab with filtering options


⚙️ Requirements

This extension requires a valid Sigrid account and API credentials.

You will need:

  1. A Sigrid API Key
  2. Your Sigrid Portfolio Name
  3. Your Sigrid System ID

If you don’t have these values, contact your Sigrid administrator or refer to your Sigrid documentation.


🚀 Getting Started

  1. Install the extension in VS Code.
  2. Open the Command Palette (Cmd+Shift+P / Ctrl+Shift+P) and run Sigrid: Set API Key to store your Sigrid API key securely (it is kept in VS Code's encrypted secret storage, never in plaintext settings).
  3. Open Settings and set the following configuration values:
    • sigrid-vscode.portfolioName – your Sigrid portfolio name (customer ID)
    • sigrid-vscode.system – your Sigrid system ID
    • sigrid-vscode.subsystem - (optional) your Sigrid subsystem ID
    • sigrid-vscode.sigridUrl – (optional) your Sigrid instance URL. Defaults to https://sigrid-says.com.
  4. Open the Command Palette (Cmd+Shift+P / Ctrl+Shift+P) and run:
    • Sigrid: Show Findings

If the configured system hasn't been onboarded to Sigrid yet, the panel will offer to onboard it for you — this zips your workspace and uploads it to Sigrid CI.


🧩 Extension Settings

General Settings

This extension contributes the following Sigrid-related settings:

Secrets (API keys and personal access tokens) can be stored either globally or per-workspace, so different projects can use different Sigrid/JIRA/Azure DevOps credentials. VS Code's Command Palette lets you choose the scope when running a "Set..." or "Clear..." command. Use Sigrid: Clear API Key, Sigrid: Clear JIRA Personal Access Token or Sigrid: Clear Azure DevOps Personal Access Token to remove a stored value; if a global value is also saved, it is used once the workspace one is cleared.

Your Sigrid API key is not a regular setting — run Sigrid: Set API Key from the Command Palette to store it in VS Code's encrypted secret storage.

Setting Description
sigrid-vscode.portfolioName Your Sigrid Portfolio Name (formerly customer).
sigrid-vscode.system Your Sigrid System ID.
sigrid-vscode.subsystem Your Sigrid Subsystem ID (optional).
sigrid-vscode.sigridUrl The URL of your Sigrid instance (default: https://sigrid-says.com).

Jira Settings

These settings are required only if you want to create Jira issues from Sigrid findings. Your JIRA personal access token is not a regular setting — run Sigrid: Set JIRA Personal Access Token from the Command Palette to store it in VS Code's encrypted secret storage.

Setting Description
sigrid-vscode.jiraBaseUrl Your JIRA base URL (e.g. https://jira.example.com).
sigrid-vscode.jiraUser Your JIRA username or email address.
sigrid-vscode.jiraSpaceKey The JIRA space key to create issues in (e.g. AAP).

Jira settings

AI Agents Settings

These settings control how "Fix with AI" hands findings off to Claude Code:

Setting Description
sigrid-vscode.claudeCodeHandoff How Sigrid hands findings to Claude Code: extension (default) opens the Claude Code panel with the prompt prefilled for review; terminal types the prompt into a terminal and runs it immediately. Falls back to a terminal automatically when the Claude Code extension is not installed.

GitHub Copilot Chat is detected automatically and requires no additional configuration.

Azure DevOps Settings

These settings are required only if you want to create Azure DevOps work items from Sigrid findings. Your Azure DevOps personal access token is not a regular setting — run Sigrid: Set Azure DevOps Personal Access Token from the Command Palette to store it in VS Code's encrypted secret storage.

Setting Description
sigrid-vscode.azureDevOpsOrganizationUrl Your Azure DevOps organization URL (e.g. https://dev.azure.com/myorg or https://myorg.visualstudio.com).
sigrid-vscode.azureDevOpsProjectName The Azure DevOps project to create work items in (e.g. MyProject).

🛠 Development

To build and test the extension locally:

npm run install:all
npm run build:webview
npm run compile

To start a watch build while developing:

npm run watch

To run the extension in VS Code for debugging:

  1. Open this repository in VS Code.
  2. Press F5 to start the Extension Development Host.

To build a Visual Studio Code VSIX package file:

npm run install:all
npm run package

🐞 Known Issues

  • If the panel stays blank, verify that your API credentials are correct and that your network allows requests to your Sigrid instance.
  • In the Maintainability and Open Source Health tabs, opening issues in Sigrid may not navigate to the exact finding.

📄 Release Notes

See CHANGELOG.md for a full history of changes.


📚 More Information

  • Extension documentation
  • VS Code Extension API
  • Sigrid Software Assurance Platform
  • Sigrid documentation
  • Contact us
  • Jobs
  • Privacy
  • Manage cookies
  • Terms of use
  • Trademarks
  • Your Privacy Choices
  • Consumer Health Privacy
© 2026 Microsoft