GithubHelp home page GithubHelp logo

rustfix / semgrep-rules Goto Github PK

View Code? Open in Web Editor NEW

This project forked from semgrep/semgrep-rules

0.0 0.0 0.0 7.53 MB

Semgrep rules registry

Home Page: https://semgrep.dev/registry

License: Other

Shell 0.42% JavaScript 11.05% Ruby 4.86% Python 26.82% C 0.79% PHP 9.93% Java 21.27% OCaml 0.27% Scala 1.81% Clojure 0.31% Go 9.68% C# 5.12% Rust 0.20% Elixir 0.10% Apex 1.60% Kotlin 0.87% TypeScript 2.79% Swift 0.27% Makefile 0.02% HTML 1.81%

semgrep-rules's Introduction

semgrep-rules

powered by semgrep Join Semgrep community Slack

Welcome! This repository is the standard library for open source Semgrep rules.

In addition to the rules in this repository, the Semgrep Registry offers proprietary Pro rules that enable interfile and interprocedural analysis.

Using the Semgrep rules repository

To start writing and using Semgrep rules, see Learn Semgrep syntax and Writing rules. Then, run existing and custom Semgrep rules locally with the Semgrep command line interface (Semgrep CLI) or continuously with Semgrep in CI while using Semgrep AppSec Platform.

Writing Semgrep rules

See Writing rules for information including:

  • Pattern syntax, describing what Semgrep patterns can do in detail, and example use cases of the ellipsis operator, metavariables.
  • Rule syntax, describing Semgrep YAML rule files, which can have multiple patterns, detailed output messages, and autofixes. The syntax allows the composition of individual patterns with boolean operators.

You can also learn how to write rules using the interactive, example-based Semgrep rule tutorial.

Contributing

We welcome Semgrep rule contributions directly to this repository! When submitting your contribution to this repository, we’ll ask you to make Semgrep, Inc. a joint owner of your contributions. While you still own copyright rights to your rule, joint ownership allows Semgrep, Inc. to license these contributions to other Semgrep Registry users pursuant to the LGPL 2.1 under the Commons Clause. See full license details.

Note: To contribute, review the Contributing to Semgrep rules documentation.

You can also contact us at [email protected] to make Semgrep rule contributions. We will import your rules for everyone to use!

Additional information

Help

Join Slack for the fastest answers to your questions! Or contact the team at [email protected].

GitHub action to run tests

If you fork this repository or create your own, you can add a GitHub Action to your workflow that will automatically test your rules using the latest version of Semgrep. See our semgrep-rules-test example.

Rulesets

Rulesets are groups of rules organized by purpose, language, or framework sourced from the Semgrep Registry. If you want to modify existing rulesets or create your own, please contact us at [email protected].

semgrep-rules's People

Contributors

lewisardern avatar inkz avatar colleend avatar kurt-r2c avatar semgrep-dev-pr-bot[bot] avatar 0xdc0de avatar drewdennison avatar ievans avatar enncoded avatar p4p3r avatar mschwager avatar minusworld avatar philipturnbull avatar aryx avatar mjambon avatar gabriellesc avatar semgrep-bot avatar sjord avatar artem-fedorov avatar iagoabal avatar ben-elttam avatar underyx avatar lfama avatar nbrahms avatar hex0punk avatar dependabot[bot] avatar brandonspark avatar ceefour avatar dlukeomalley avatar wingyplus avatar

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.