Skip to content

xaviercho/semgrep-rules

 
 

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

semgrep-rules

powered by semgrep Semgrep community slack

branch using semgrep docker image test status
develop returntocorp/semgrep:develop semgrep-rules-test-develop

Welcome! This repository is the standard library for Semgrep rules. There are many more rules available in the Semgrep Registry written by Semgrep, Inc. and other contributors. The Semgrep Registry includes rules from this repository and additional rules that are accessible within Semgrep Cloud Platform. If there is a specific rule you are looking for, see the Semgrep registry search. To contribute, find details about contributing in the Contributing to Semgrep rules documentation.

Using Semgrep rules repository

Run existing and custom Semgrep rules locally with the Semgrep command line interface (Semgrep CLI) or continuously with Semgrep in CI while using Semgrep App. To start using Semgrep rules, see Semgrep tutorial, Getting started with Semgrep CLI, and Getting started with Semgrep App.

Contributing

We welcome Semgrep rule contributions directly to this repository! When you submit your contribution to the semgrep-rules repository we’ll ask you to make Semgrep, Inc. a joint owner of your contributions. While you still own copyright rights to your rule, joint ownership allows Semgrep, Inc. to license these contributions to other Semgrep Registry users pursuant to the LGPL 2.1 under the Commons Clause. See full license details.

Note: To contribute, review the Contributing to Semgrep rules documentation.

You can also contact us at [email protected] to make Semgrep rule contributions. We will import your rules for everyone to use!

Additional information

Help

Join Slack for the fastest answers to your questions! Or contact the team at [email protected].

GitHub action to run tests

If you fork this repository or create your own, you can add a special semgrep -rules-test GitHub Action to your workflow that will automatically test your rules using the latest version of Semgrep. See our semgrep-rules-test.

Rulesets

Rulesets are groups of rules organized by purpose, language, or framework sourced from the Semgrep Registry. If you want to modify existing rulesets or create your own, please contact us at [email protected].

Releases

No releases published

Packages

No packages published

Languages

  • Solidity 19.1%
  • HCL 18.4%
  • Java 13.6%
  • Python 13.2%
  • JavaScript 8.5%
  • Jsonnet 5.1%
  • Other 22.1%