{"repo":"semgrep/semgrep-rules","free":true,"listed":false,"github":"https://github.com/semgrep/semgrep-rules","clone":"git clone https://github.com/semgrep/semgrep-rules.git","description":"Semgrep Community Edition rules, maintained by Semgrep and the community. Free to use under the Semgrep Rules License.","language":"HCL","stars":1228,"topics":["static-analysis","grep-like","program-analysis","security","security-scanner","semgrep","semgrep-rules","semgrep-registry"],"license":null,"category":"security-tools","readme_excerpt":"semgrep-rules Welcome! This repository contains Semgrep's Community Edition rules. In addition to the rules in this repository, the Semgrep Registry offers proprietary Pro rules that offer additional language coverage, and unlock crossfile and deep dataflow analysis. - Find rules: search for Community Edition and Pro rules through the Semgrep registry search. - Use rules: Scan your code with these rules through Semgrep AppSec Platform - Contribute to rules: see Contributing to Semgrep rules for more information. Using the Semgrep rules repository To start writing and using Semgrep rules, see Learn Semgrep syntax and Writing rules. Then, run existing and custom Semgrep rules locally with the Semgrep command line interface (Semgrep CLI) or continuously with Semgrep in CI while using Semgrep AppSec Platform. Writing Semgrep rules See Writing rules for information including: - Pattern syntax, describing what Semgrep patterns can do in detail, and example use cases of the ellipsis operator, metavariables. - Rule syntax, describing Semgrep YAML rule files, which can have multiple patterns, detailed output messages, and autofixes. The syntax allows the composition of individual patterns with boolean operators. You can also learn how to write rules using the interactive, example-based Semgrep rule tutorial. Contributing We welcome Semgrep rule contributions directly to this repository! When submitting your contribution, you grant Semgrep, Inc. a license to use, modify, and distribute","default_branch":null,"files":null,"tree":[],"storefront":"/r/semgrep","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/semgrep/semgrep-rules/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}