← All cheat sheets

SEMGREP

Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.

Lightweight static analysis (SAST) tool. Pattern-based code scanning
for security vulnerabilities, bugs, and anti-patterns. Supports 30+ languages.

INSTALLATION#

pip install semgrep
# Or: brew install semgrep
# Or: docker pull semgrep/semgrep

BASIC USAGE#

# Scan with community rules (auto-detect language)
semgrep scan --config auto

# Scan specific directory
semgrep scan --config auto /path/to/code

# Scan specific file
semgrep scan --config auto myfile.py

# Specific ruleset
semgrep scan --config p/python
semgrep scan --config p/javascript
semgrep scan --config p/java
semgrep scan --config p/golang
semgrep scan --config p/security-audit
semgrep scan --config p/owasp-top-ten
semgrep scan --config p/cwe-top-25

# Multiple configs
semgrep scan --config p/security-audit --config p/python

# Custom rule file
semgrep scan --config my-rules.yml
p/security-audit           # General security checks
p/owasp-top-ten            # OWASP Top 10
p/cwe-top-25               # CWE Top 25
p/ci                       # CI-friendly ruleset
p/default                  # Recommended defaults
p/python                   # Python-specific
p/javascript               # JavaScript-specific
p/typescript               # TypeScript-specific
p/java                     # Java-specific
p/golang                   # Go-specific
p/ruby                     # Ruby-specific
p/php                      # PHP-specific
p/csharp                   # C#-specific
p/rust                     # Rust-specific
p/secrets                  # Hardcoded secrets
p/sql-injection            # SQL injection patterns
p/xss                      # XSS patterns
p/command-injection         # Command injection

OUTPUT OPTIONS#

semgrep scan --config auto --json            # JSON
semgrep scan --config auto --sarif           # SARIF
semgrep scan --config auto --junit-xml       # JUnit XML
semgrep scan --config auto --emacs           # Emacs format
semgrep scan --config auto --vim             # Vim format
semgrep scan --config auto -o results.json --json

# Severity filter
semgrep scan --config auto --severity ERROR
semgrep scan --config auto --severity ERROR --severity WARNING

# Quiet
semgrep scan --config auto --quiet

CUSTOM RULES#

# rules/my-rule.yml
rules:
  - id: hardcoded-password
    pattern: password = "..."
    message: Hardcoded password detected
    languages: [python]
    severity: ERROR

  - id: sql-injection
    patterns:
      - pattern: |
          cursor.execute("..." + $VAR)
    message: Possible SQL injection via string concatenation
    languages: [python]
    severity: ERROR

  - id: insecure-hash
    pattern: hashlib.md5(...)
    message: MD5 is cryptographically weak
    languages: [python]
    severity: WARNING
    metadata:
      cwe: ["CWE-327"]
      owasp: ["A02:2021"]

# Pattern operators
pattern:                    # Match exact pattern
patterns:                   # All must match (AND)
pattern-either:             # Any can match (OR)
pattern-not:                # Must NOT match
pattern-inside:             # Match within context
pattern-not-inside:         # NOT within context
pattern-regex:              # Regex pattern

# Run custom rules
semgrep scan --config rules/my-rule.yml

IGNORING FINDINGS#

# Inline ignore
def func():
    password = "secret"  # nosemgrep: hardcoded-password

# Ignore file (.semgrepignore)
vendor/
node_modules/
*.test.js
*.spec.py

# Skip specific rules
semgrep scan --config auto --exclude-rule python.django.security.audit.xss

CI/CD INTEGRATION#

# GitHub Actions
# - uses: semgrep/semgrep-action@v1
#   with:
#     config: p/security-audit

# Exit code
semgrep scan --config auto --error          # Exit 1 on findings

# Baseline (differential scanning)
semgrep scan --config auto --baseline-commit HEAD~1

TIPS#

  - --config auto is the easiest starting point
  - p/security-audit covers the most common vulns
  - Custom rules are YAML — easy to write and share
  - Pattern syntax matches actual code structure (not regex)
  - Semgrep is fast — suitable for pre-commit and CI/CD
  - SARIF output for GitHub security tab integration
  - --baseline-commit for incremental scanning (only new code)
  - Supports 30+ languages with the same rule syntax
  - Semgrep Pro adds inter-file and inter-function analysis
  - Combine with Trivy/Checkov for full security coverage