SEMGREP
Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.
Lightweight static analysis (SAST) tool. Pattern-based code scanning for security vulnerabilities, bugs, and anti-patterns. Supports 30+ languages.
INSTALLATION#
pip install semgrep # Or: brew install semgrep # Or: docker pull semgrep/semgrep
BASIC USAGE#
# Scan with community rules (auto-detect language) semgrep scan --config auto # Scan specific directory semgrep scan --config auto /path/to/code # Scan specific file semgrep scan --config auto myfile.py # Specific ruleset semgrep scan --config p/python semgrep scan --config p/javascript semgrep scan --config p/java semgrep scan --config p/golang semgrep scan --config p/security-audit semgrep scan --config p/owasp-top-ten semgrep scan --config p/cwe-top-25 # Multiple configs semgrep scan --config p/security-audit --config p/python # Custom rule file semgrep scan --config my-rules.yml
POPULAR RULESETS#
p/security-audit # General security checks p/owasp-top-ten # OWASP Top 10 p/cwe-top-25 # CWE Top 25 p/ci # CI-friendly ruleset p/default # Recommended defaults p/python # Python-specific p/javascript # JavaScript-specific p/typescript # TypeScript-specific p/java # Java-specific p/golang # Go-specific p/ruby # Ruby-specific p/php # PHP-specific p/csharp # C#-specific p/rust # Rust-specific p/secrets # Hardcoded secrets p/sql-injection # SQL injection patterns p/xss # XSS patterns p/command-injection # Command injection
OUTPUT OPTIONS#
semgrep scan --config auto --json # JSON semgrep scan --config auto --sarif # SARIF semgrep scan --config auto --junit-xml # JUnit XML semgrep scan --config auto --emacs # Emacs format semgrep scan --config auto --vim # Vim format semgrep scan --config auto -o results.json --json # Severity filter semgrep scan --config auto --severity ERROR semgrep scan --config auto --severity ERROR --severity WARNING # Quiet semgrep scan --config auto --quiet
CUSTOM RULES#
# rules/my-rule.yml
rules:
- id: hardcoded-password
pattern: password = "..."
message: Hardcoded password detected
languages: [python]
severity: ERROR
- id: sql-injection
patterns:
- pattern: |
cursor.execute("..." + $VAR)
message: Possible SQL injection via string concatenation
languages: [python]
severity: ERROR
- id: insecure-hash
pattern: hashlib.md5(...)
message: MD5 is cryptographically weak
languages: [python]
severity: WARNING
metadata:
cwe: ["CWE-327"]
owasp: ["A02:2021"]
# Pattern operators
pattern: # Match exact pattern
patterns: # All must match (AND)
pattern-either: # Any can match (OR)
pattern-not: # Must NOT match
pattern-inside: # Match within context
pattern-not-inside: # NOT within context
pattern-regex: # Regex pattern
# Run custom rules
semgrep scan --config rules/my-rule.yml
IGNORING FINDINGS#
# Inline ignore
def func():
password = "secret" # nosemgrep: hardcoded-password
# Ignore file (.semgrepignore)
vendor/
node_modules/
*.test.js
*.spec.py
# Skip specific rules
semgrep scan --config auto --exclude-rule python.django.security.audit.xss
CI/CD INTEGRATION#
# GitHub Actions # - uses: semgrep/semgrep-action@v1 # with: # config: p/security-audit # Exit code semgrep scan --config auto --error # Exit 1 on findings # Baseline (differential scanning) semgrep scan --config auto --baseline-commit HEAD~1
TIPS#
- --config auto is the easiest starting point - p/security-audit covers the most common vulns - Custom rules are YAML — easy to write and share - Pattern syntax matches actual code structure (not regex) - Semgrep is fast — suitable for pre-commit and CI/CD - SARIF output for GitHub security tab integration - --baseline-commit for incremental scanning (only new code) - Supports 30+ languages with the same rule syntax - Semgrep Pro adds inter-file and inter-function analysis - Combine with Trivy/Checkov for full security coverage