{"repo":"Decurity/semgrep-smart-contracts","free":true,"listed":false,"github":"https://github.com/Decurity/semgrep-smart-contracts","clone":"git clone https://github.com/Decurity/semgrep-smart-contracts.git","description":"Semgrep rules for smart contracts based on DeFi exploits","language":"Solidity","stars":713,"topics":["defi","security","semgrep","solidity","ethereum"],"license":null,"category":"blockchain-web3","readme_excerpt":"Semgrep rules for smart contracts In this repository you can find semgrep rules that look for patterns of vulnerabilities in smart contracts based on actual DeFi exploits as well as gas optimization rules that can be used as a part of the CI pipeline. The rules are part of the semgrep registry under p/smart-contracts. Disclaimer Currently semgrep supports Solidity in experimental mode. Some of the rules may not work until Solidity is in beta at least. Scanning Important: Some of the rules utilize the taint mode, which is restricted to the same function in the open-source version of semgrep. To take advantage of intra-procedural taint analysis, you must include the --pro flag with each command. Please note that this requires semgrep Pro. 1) By cloning the repository: 2) By using semgrep registry: 3) In your CI: Create run-semgrep.yaml in .github/workflows with the following contents: run-semgrep.yaml Testing Each rule is accompanied by an actual vulnerable source code that was targeted by an exploit. Vulnerable lines are marked with // ruleid: ... In case a rule is not yet supported by semgrep, you will find // todoruleid: ... Run tests: Validate rules: Feel free to submit any issues with the precision and quality of the rules! Security Rules Rule ID Targets Description --- --- --- compound-borrowfresh-reentrancy Compound, Ola Finance, Hundred Finance, Agave Function borrowFresh() in Compound performs state update after doTransferOut() compound-sweeptoken-not-restricted TUSD, ","default_branch":null,"files":null,"tree":[],"storefront":"/r/Decurity","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/Decurity/semgrep-smart-contracts/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}