Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.
-
Updated
Mar 15, 2023 - OCaml
Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.
Define and run pattern-based custom linting rules.
Semgrep rules registry
A collection of my Semgrep rules to facilitate vulnerability research.
Generic SAST Library
Semgrep CI is a specialized Docker image for running Semgrep in CI environments. It can either be used stand-alone or connected with Semgrep App for centralized rule and findings management.
An extension to use Semgrep inside Burp Suite.
Semgrep extension for Visual Studio Code
Documentation of Semgrep: a fast, open-source, static analysis tool.
Semgrep rules specific to Frappe Framework
GitHub Actions master template and GitHub Actions Reusable Workflows
My custom semgrep rules
Custom semgrep rules registry
Semgrep rules to identify GWT attack surface
Ricerca che mostra come scrivere regole per SemGrep per cercare SQL Injection nei plugin di Wordpress che usano action AJAX
Combine multiple popular python security tools and generate reports or output into different formats
semgrep rules for flakiness, missed error handling and antipatterns.
Add a description, image, and links to the semgrep topic page so that developers can more easily learn about it.
To associate your repository with the semgrep topic, visit your repo's landing page and select "manage topics."