NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
PyPI · #815 most downloaded on PyPI
Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.
Last release 3 days ago
02 Oct 2026
Ships on a steady schedule
a new release about every 2 weeks
Nearly every release is documented
notes for 54 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
6 years old
360 releases · first in 2020
One column per quarter.
…pick up a PyJWT release with fixes for known vulnerabilities, and projects that require a newer PyJWT can install Semgrep. ( gh-11953 )
bun.lock lockfiles (text format, lockfileVersion 1) paired with a package.json manifest, including the dependency relationships between packages. The deprecated binary bun.lockb format is still unsupported. (SC-2419)Pro: Stabilize file processing order in inter-file analysis, which was previously arbitrary but deterministic. We believe this is very unlikely to affect findings but there is a theoretical path by which it could in certain rare cases. (stabilize)
c grammar update (v0.24.2):
(c-v0.24.2)
cpp grammar update (v0.23.4):
(cpp-v0.23.4)
Update the html grammar to v0.23.2. (html-v0.23.2)
r grammar update (v1.3.0):
(r-v1.3.0)
sfapex grammar update (v2.3):
(sfapex-v2.3)
except A, B: and except A, B, C: (PEP 758, Python 3.14) and theexcept* forms of both are now parsed as a tuple of exception types, likeexcept (A, B):, rather than as the Python 2 except A as B: or a parseexcept* is now handled by Semgrep's primary Python parser too, soexcept A, e: is no longer read as except A as e:, even for python2.except A, B, C: is still a parse error there. TheEXPOSE ports with TCP/UDP protocols. (gh-11934)pyjwt[crypto]>=2.15.0,<3) instead of~=2.13.0, so installs pick up a PyJWT release with fixes for knownThe bundled tree-sitter C runtime is now 0.26.3. (CODE-9425)
semgrep-core exited on Windows. (windows-hang)Added native Supply Chain support for Bazel workspaces using rules_jvm_external . Semgrep now recognizes a maven_install.json pinned lockfile (version
rules_jvm_external. Semgrep now recognizes a maven_install.json pinned lockfile (versions 0.1.0 and 3, as emitted by rules_jvm_external 3.x through current) paired with a MODULE.bazel (or legacy WORKSPACE / WORKSPACE.bazel) marker as a Maven-ecosystem subproject, and attributes findings to the workspace root rather than the lockfile's directory. Workspace-declared root artifacts are identified via __INPUT_ARTIFACTS_HASH for accurate direct-vs-transitive classification; dependencies are emitted with Unknown transitivity when that field is not available. This is the first milestone of native Bazel coverage; broader ecosystem support (rules_python, rules_go, rules_js) and Bazel-aware reachability attribution follow. (SC-2008)FOOBAR(a+)\1 will skip any file that does notFOOBAR without running the regex. (scrt-979)--x-gradle-module-attribution. Enabling it can change finding IDs because finding paths change; the ID calculation is unchanged. (SC-2560)Speed up semgrep ci filtering when a deployment has many triage-ignored findings. (triage-ignored-performance)
Semgrep no longer crashes with an OCaml stack trace when a proxy environment
variable holds an unusable value. HTTP_PROXY, HTTPS_PROXY, or ALL_PROXY
set to an empty value is now ignored with a warning, and the scan
proceeds without a proxy. A non-empty value that is not a usable proxy URL
now exits with an error message, with any credentials in the URL
redacted, instead of failing inside the HTTP client.
Semgrep also now adds the missing scheme to a proxy URL supplied
without one; https for HTTPS_PROXY and http` otherwise. (ENGINE-2208)
Supply Chain: lockfileless Gradle scans now report a "Resource Inaccessible"
resolution error when a repository refuses a request (for example a 401 from a
private registry), instead of exiting successfully with a silently incomplete
dependency list. (sc-3358)
Nothing published for this version
Homebrew installs of Semgrep are no longer supported on Intel Macs. (ENGINE-2951)
Fixed scans run with --trace that would fail with Stdlib.Effect.Unhandled(Eio__core__Cancel.Get_context) when a secret would fail to validate (CODE-99
--trace that would fail with Stdlib.Effect.Unhandled(Eio__core__Cancel.Get_context) when a secret would fail to validate (CODE-9906)Semgrep is now built with OCaml 5.4 instead of OCaml 5.3. End users should notice no change. (ocaml-5.4)
Diff scans now report which dependency source files were added or modified relative to the merge base. (changed-dependency-sources)
--x-partial-scan-rule-id) now resolve dependencies only forsemgrep-core -version now reports the git commit that the binary was built from. (core-version-git-sha)
semgrep-core -version now reports the git commit that the binary was builtno_disk_cache memory policy (--x-mem-policy no_disk_cache) to trade higher memory usage for not caching intermediary scan data structures on disk. (no-disk-cache-memory-policy)layout at, assembly flags, global using-directives, EVM Cancun builtins) and corrected ternary/?: vs member-access precedence. (LANG-207)metavariable-regex or a binding-introducingmetavariable-pattern would emit a duplicate finding on the same range whosea hash $ALG was detected)use with a nested path (e.g. use a::b::C). It was wrongly beingAdded support for the OpenTofu .tofu file extension. Because OpenTofu uses the same HCL grammar as Terraform, .tofu files are now automatically detect
.tofu file extension. Because OpenTofu uses the same HCL grammar as Terraform, .tofu files are now automatically detected and scanned as Terraform, so they are picked up by recursive scans and Terraform rulesets (e.g. p/terraform) with no extra configuration. (ENGINE-2884)!=, case/when expressions with line breaks, and element references that take a block. (LANG-206)semgrep ci has been extended from the last 30 days to the last 90 days, to match the updated usage policy. (contributor-window-90-days)--debug is NOT passed, matching the segfault error output when --debug is passed (engine-segv)Scan Status output when no code rules will run (e.g. a
Secrets-only or Supply-Chain-only scan). The summary line no longer reports a
confusing "0 Code rules", and the "Code Rules" section now states explicitly
either that code scanning is not enabled or that there are no code rules to run,
instead of printing an empty table. (ENGINE-2878)Added support for the OpenTofu .tofu file extension. Because OpenTofu uses the same HCL grammar as Terraform, .tofu files are now automatically detect
.tofu file extension. Because OpenTofu uses the same HCL grammar as Terraform, .tofu files are now automatically detected and scanned as Terraform, so they are picked up by recursive scans and Terraform rulesets (e.g. p/terraform) with no extra configuration. (ENGINE-2884)semgrep ci has been extended from the last 30 days to the last 90 days, to match the updated usage policy. (contributor-window-90-days)Scan Status output when no code rules will run (e.g. a
Secrets-only or Supply-Chain-only scan). The summary line no longer reports a
confusing "0 Code rules", and the "Code Rules" section now states explicitly
either that code scanning is not enabled or that there are no code rules to run,
instead of printing an empty table. (ENGINE-2878)Nothing published for this version
Pro C/C++ scans now skip code inside statically-dead preprocessor branches (for example, #if 0 ... #else ... #endif). Patterns that would otherwise ma
#if 0 ... #else ... #endif). Patterns that would otherwise
match against intentionally-disabled code no longer report on it. (cpp-if-zero-filter)semgrep install-semgrep-pro now sends usage metrics so that
installation errors can be tracked. Metrics can be disabled with
--metrics off or SEMGREP_SEND_METRICS=off. Metrics payloads also
now include the method used to install the Semgrep CLI (pip, homebrew,
docker, or unknown), detected heuristically. See metrics.md for
more details of what exactly is sent. (engine-2858)#if 0 filtering now also handles cases where the directive splits a
syntactic unit. For example, a function signature toggle like #if 0 void foo(int i) { #else void foo(uint32_t i) { #endif. (engine-994)Fixed a crash at startup (Fatal error: Failed to allocate signal stack for domain 0) when running Semgrep on systems with musl 1.2.6 (e.g. Alpine 3.24) on
recent Intel CPUs whose kernel-reported minimum signal-stack size exceeds musl's
build-time SIGSTKSZ (notably AMX-capable Xeons). (ENGINE-2863)
Dockerfile: Fixed parse errors on RUN instructions that use heredoc syntax
(<<EOF, <<-EOF, quoted delimiters). (LANG-263)
metavariable-type now supports fully qualified type names in languages
where a qualified name in type position parses as an expression (e.g.
Python's types: [a.b.C]) when the metavariable's type is determined by
type inference, such as Pro engine cross-file type resolution. (LANG-583)
Updated the ocaml-tree-sitter-core dependency to the latest main.
parser.c with the tree-sitter version that produced it.Updated Dart parser to a more recent upstream version. (LANG-579)
Aliengrep (generic mode) now uses the maintained libpcre2 10.x regular-expression library instead of the deprecated libpcre 8.x. Matching behavior is…
--x-dependency-paths flag to scan and ci that includes the full dependency path(s) for transitive supply-chain findings in --json and --sarif output. (SC-3547)metavariable-regex and metavariable-comparison (re.match()) runtimes now use the maintained libpcre2 10.x library instead of the deprecated libpcre 8.x. Matching behavior is unchanged. (eval-generic-pcre2)Added support for more operators for folding for constant propagation, including subtraction, division, bit ops, bit shifts, comparisons, and more. (c
nosemgrep_disabled field to the scan configuration so the platform can disable nosemgrep inline ignore comments org-wide for a scan. (APPEX-1122)--no-exclude-binary-files to
scan binary files as before. (ENGINE-2708)semgrep ci with --sarif now correctly populates the output's ignores
field with nosemgrep-suppressed findings, in accordance with other output
formatters. (gh-6651)Updated the ocaml-tree-sitter-core submodule to the latest upstream main, providing
(ocaml-tree-sitter-core-bump)
Pro: Added experimental cross-file (interfile) analysis for Gosu, enabling taint tracking across multiple Gosu source files. (gosu-interfile)
0x_dead_beef, 0o_755, 0b_1010_1010). (LANG-533)def and class definitions. (LANG-536)~/.semgrep/settings.yml's stored
token when the current scan's token is supplied via the SEMGREP_APP_TOKEN
envvar. (SEC-2240)semgrep ci scans originating from a pre-commit hook will no longer fail with
Unable to create '<tmp>/.git/index.lock': Not a directory in certain cases. (engine-2736)--x-no-python-schema-validation is still accepted as a no-op with a deprecation warning, and will be removed in a future release. (x-rule-validation)
--max-match-context-size option to limit the number of characters of source code included as context for each match in the output. This prevents matches in minified files (e.g., minified JavaScript where the entire file is a single line) from producing enormous output Set to 0 for unlimited, which is the default value. (ENGINE-2117)--x-no-python-schema-validation with a value-taking --x-rule-validation=full|core-only|none flag. The default (full) preserves existing Python rule validation behavior; core-only matches the old flag's semantics (disables Python rule validation and uses semgrep-core RPC validation only); none skips both pre-validation passes, surfacing rule errors at scan-time. --x-no-python-schema-validation is still accepted as a no-op with a deprecation warning, and will be removed in a future release. (x-rule-validation)validation_error results on HTTP secret validators (Facebook, Slack, Stripe, Google, Cloudflare, etc.) by retrying transient network failures, mirroring the retry behavior already present for AWS validators. (SCRT-965)Dart: typed metavariables ($X as T) and metavariable-type, metavariable binding inside string interpolations, and function-definition patterns that ma
$X as T) and metavariable-type,
metavariable binding inside string interpolations, and function-definition
patterns that match Dart function definitions. (gh-11678)>=2.35 to >=2.34, allowing users on distros
that ship glibc 2.34 (e.g RHEL 9 & AL2023) to install the semgrep wheel. (gh-11622)Baseline diff scans (semgrep ci and --baseline-commit) no longer treat every finding on a file as newly introduced when rule(s) failed during the baseline run.
Per-rule failures (for example a timeout for a single rule) on baseline analysis now hide only that rule's matches on that file from the "new vs baseline" comparison. Other rules on the same file are still taken in comparison for the "new vs baseline" comparison.
Per-file, rule-independent failures now hide all findings on that file from the "new vs baseline" comparison. (LANG-515)
Fixed a yarn.lock parse error on Yarn Berry entries written in YAML explicit-key form. Affected lockfiles previously failed to parse. (SC-3479)
The (beta) SBT resolver with --allow-local-builds now correctly identifies dependencies as part of the Maven ecosystem. (SC-3522)
Fix --sarif-output and --sarif causing nosemgrep-suppressed findings to be reported in CLI scan output and to block scans. Suppressed findings are now correctly excluded from terminal text output, the scan-summary count, and the CLI's exit code. (engine-1824)
Fixed a bug that could cause unreliable target filtering in parallel scans. (gh-6313)
Dart: improved parser fidelity for Dart 3 grammar features and routed
pattern parsing for statements beginning with await, rethrow, and other
statement keywords. Eliminates a large class of PartialParsing errors on
real-world pub.dev packages. (gh-11678)
semgrep-core-proprietary so the binary works when semgrep install-semgrep-pro is invoked, and semgrep is installed via Homebrew. (pro-binary-homebrew)<case>.named_ast.expect golden files for tests/intrafile/maturity/ fixtures, exercised by Unit_maturity_named_asts. (LANG-287)Updated PHP target parsing to support grammar changes from PHP 8.1-8.5 (LANG-380)
semgrep ci startup time with App-provided rules by avoiding duplicate semgrep-core rule validation during CLI rule loading while preserving config-style failures for invalid rules. (ci-rule-validation-startup)json.dumps([rule.raw])) but was being created with a .yaml suffix.
OCaml's Parse_rule.parse_file dispatches purely on file extension, so this
routed every TR rule through Yaml_to_generic.parse_yaml_file (the slow YAML
path) instead of Fast_json.parse_program (the new hand-written RFC 8259
parser). Switching the suffix to .json lines the suffix up with the actual
content and lets every TR rule parse take the fast path. (tr-json-suffix)pro: Improved support for tracking taint through nested functions. (LANG-95)
semgrep_findings tool: added a refs parameter to filter findings by branch (defaults to the primary branch when not specified), and made autotriage_verdict optional so that findings without an AI verdict can also be returned. (engine-2723)import and importstr now reject paths that resolve outside the
rule file's parent directory. (ENGINE-2727)Authorization header
values from git error messages and from the captured tracebacks sent to
the fail-open telemetry endpoint, preventing leaks of secrets like
CI_JOB_TOKEN from a failed git fetch in GitLab CI. Also closes
ENGINE-2731 (raw, unsanitized tracebacks in fail-open telemetry). (ENGINE-2728)semgrep ci no longer transmits SCM tokens to the Semgrep Platform. (ENGINE-2729)~/.semgrep/semgrep.log or $SEMGREP_LOG_FILE) now respects the requested log level instead of always being written at DEBUG. This narrows the surface for credentials to land on disk via CI runner filesystems or job artifacts; pass --debug to restore the previous behavior. (ENGINE-2730)imports
or runtime function calls that recurse forever. (ENGINE-2727-dos)Scala 3.4+ trait parameters are now parsed correctly. (lang-73)
SEMGREP_LOG_SRCS=cohttp.client. (ENGINE-2712)Scala: Added tree-sitter parser for improved parsing accuracy with pfff fallback. (LANG-255)
Semgrep now reports an error instead of silently returning zero findings when target file discovery fails (e.g., due to a git ls-files failure). (ENGI
Added support for a supply chain hook for the Semgrep Plugin (supply-chain-hook)
--no-x-run-taint-once as a flag. (engine-2468)SEMGREP_DISABLE_CONFIG_DOWNLOAD_V2=1 to fall back to the legacy endpoint. (SMS-2284)codeFlows. (engine-2570)pro: Improved taint tracking through lambda calls. (LANG-268)
$C.getInstance(...), and then
use metavariable-type on $C to check its type. (LANG-271)metavariable-type. (LANG-271)The Kotlin tree-sitter parser has been updated to the latest available grammar significantly improving Kotlin support in Semgrep. (kotlin-parser)
semgrep ci when run in a git repo with no remote origin set (gh-11342)Added support for (agentic) hooks in Windsurf. (windsurf-hooks)
Removed the experimental and undocumented command semgrep install-ci. (osemgrep-install-ci)
Migrate from publishing a single Linux wheel with the platform tag musllinux_1_0_<arch>.manylinux2014_<arch> to publishing two separate wheels:
(pypi-linux-tag)
--secrets-timeout flag. (engine-2593)Fix crash on Windows when running semgrep ci with --debug and no blocking findings. The Windows subprocess path incorrectly raised an exception for al
semgrep ci with --debug and no blocking findings. The Windows subprocess path incorrectly raised an exception for all pysemgrep exit codes (including 0), which was silently swallowed in normal mode but propagated as a fatal error when --debug was active. (ENGINE-2491)-j) (engine-2512)semgrep scan $(git ls-files '*.py')) caused one semgrep-core
subprocess to be spawned per file. Roots that are not directories are now
handled directly in Python without any subprocess overhead. (gh-11404)Nothing published for this version
Semgrep core is now optimized with flambda (flambda)
for-yield (LANG-193)def f (a: t) =
foo()
bar()
``` (lang-194)
Hooks (for both Claude Code and Cursor) now pull custom rules from the registry (custom-rules-hooks)
Hooks (for both Claude Code and Cursor) now pull custom rules from the registry (custom-rules-hooks)
Turned on DNS rebinding protection for the MCP server (dns-check)
Environment variables can now be passed to third-party package managers invoked as part of --allow-local-builds dependency resolution via the environment variable SEMGREP_LOCAL_BUILD_ENV, which accepts a JSON object with string keys and string values. (SC-3163)
Memory management policies
A memory policy defines how OCaml's garbage collector should be configured for
a scan. There are two initial policies: "aggressive", the current behaviour,
which trades longer scan times for lower memory use, and "balanced", which
finds a middle ground between reclaiming heap memory in short order while
limiting how often the garbage collector runs. The policy can be configured
via the --x-mem-policy CLI flag for the pro engine; this flag is unused in
the OSS engine. (engine-2055)
Added experimental support for the OpenFGA authorization language. Thanks to Alex Useche (@hex0punk) for the contribution! (gh-11347)
Allows case insensitive string comparisons using lower() and upper() like this:
- metavariable-comparison:
metavariable: $VALUE
comparison: upper(str($VALUE)) == "SEMGREP"
(gh-11502)
Blocking findings that are outputted in the CI output are now labelled as such. (#4394)
Added progress indicators for symbol analysis calculation and upload during CI scans (sc-3103)
glom to at least version 23.3, which includes a fix to a SyntaxWarning
warning log. (gh-11460)Connecting to the Semgrep MCP server via streamableHttp now requires OAuth. (saf-2453)
pipenv to uv for ./cli package management (uv)-alpha in 1.2.3-alpha. (sc-3001)Added a warning in --debug mode when a user runs a parallel scan with a larger value for -j/--jobs than the number of CPUs we detect the host has made
Target objects. Performance should improve on
large repo scans proportionally to the number of files in the repo. (gh-5407)semgrep ci no longer applies autofixes to disk, even when the "Suggest autofixes" toggle in the app is enabled. (saf-2446)Performance: subproject discovery in Supply Chain scans is no longer significantly slowed down by the presence of Git-untracked files resulting in fas
Gradle lockfiles of the form gradle*.lockfile are now supported. Previously, only lockfiles named exactly gradle.lockfile were supported. (SC-2999)
gradle*.lockfile are now supported. Previously, only lockfiles named exactly gradle.lockfile were supported. (SC-2999)semgrep login now supports a --force flag, which ignores existing tokens and starts a new login session. The MCP setup workflow has been updated to use --force too. (saf-2392)Added support for Cursor post-code-generation hooks via new record-file-edit and stop-cli-scan semgrep mcp flags (cursor-hooks)
record-file-edit and stop-cli-scan semgrep mcp flags (cursor-hooks)skipped_paths field to CI scan results to report files that failed to scan due to errors (timeout, OOM, etc.), preventing the app from incorrectly marking findings in those files as fixed (gh-5122)semgrep ci. (sc-2927)mcp python-sdk from 1.16.0 to 1.23.3 (mcp-version)semgrep ci regardless of app settings is now possible with
--x-enable-transitive-reachability (or --x-tr)
and --x-disable-transitive-reachability. (tr-flags)No significant changes.
No significant changes.
No significant changes.
No significant changes.
Added optional user-prompting for classifying findings as true/false positives via MCP Elicitation in the MCP server (behind SEMGREP_FINDINGS_ELICITAT
let ... in expressions in OCaml is now reported. Previously, the location of the let was omitted. This is mainly relevant for autofix. (ocaml-let)Fix issue that could lead to validation failures for certain well-formed rules, such as those with emoji in their messages. (incid-293)
pro: interfile scans no longer default to -j 1; instead, the number of available CPUs on the system is polled as part of a heuristic to determine how
No significant changes.
No significant changes.
Fix issue that could lead to validation failures for certain well-formed rules, such as those with emoji in their messages. (incid-293)
Semgrep will no longer rarely crash when --trace is passed. (incid-280)
Users can opt into the legacy method with the --x-parmap CLI flag, and this deprecates the --x-eio flag (since it is now the default behaviour). (saf-…
--x-parmap CLI flag, and this deprecates the --x-eio
flag (since it is now the default behaviour). (saf-2271)-k/ --hook flag to enable Semgrep scans via Claude Code Agent post-tool hooks (saf-2279)semgrep scan or semgrep ci, the progress bar now always ends at 100%. (SAF-2079)type declaration. (gh-11283)Nothing published for this version
Nothing published for this version
Nothing published for this version
Pro: improved taint handling of match expressions in Scala. In examples like `scala val x = taint match { case Some(t) => t case None => return "examp
match expressions in Scala. In examples likeval x = taint match {
case Some(t) => t
case None => return "example"
}
dataflow should now track taint from taint to x. (code-9085)case $M -> ... :? ... +& test +& ... => ... patterns. (code-9131)--allow-local-builds is passed. (SC-2899)Rule parsing in 1.139.0 was switched to happen solely in semgrep-core. This caused some users to exit with code 7, so this change has been reverted. (
pro: scala: http4s-specific support for $M -> ... / $X / ... patterns (code-9114)
$M -> ... / $X / ... patterns (code-9114)return statement.
More expressions, such as string interpolation, are now correctly identified as implicitly returned. (code-9101)@), so
e.g. case $X @ ... => ... is now a valid pattern. (code-9130)scala: Allow partial case patterns such as case 1 => ... to easily match individual case clauses within a match-expression. (code-9118)
case 1 => ... to easily match
individual case clauses within a match-expression. (code-9118)3.14 support. (gh-11250)setup_semgrep_mcp now supports Claude Code. (saf-2261)0.5f or 1.0d, and Rust literals like 0.5f32 or 1.0f64 would fail to parse and could not be compared. (gh-7968)semgrep/semgrep images should now contain golang v1.24 instead of v1.23 (saf-2240)streamable-http tranport method. (saf-2264)--pro-intrafile scans will now add built-in taint propagators, like --pro does, hence producing extra findings. For example, in Java, list.add(taint)
list.add(taint) will now
make list tainted even if the rule does not explicitly request that. Scan times
should not be generally affected in a significant way. (code-9103){ ... } to match partial functions like { case 1 => "1" }. (code-9106)dockerfile language (gh-11091)config parameter from the semgrep_scan tools, to prevent
agents from inserting unwanted config files to scan with. (saf-2258){ case ... => ... } patterns. (code-9111)$X > 1 or $Y > 1 or $Z > 1 would previously always evaluate to false. Now, it will behave as expected. (gh-11209)semgrep_scan tool, when invoking the RPC-based
scanning approach, would return JSON output not consistent with the CLI tool. (saf-2250)semgrep_findings tool now gives a suitable error message when erring due
to insufficient permissions on standard semgrep login tokens. (saf-2254)pro: scala: Method dispatching through traits (code-9092)
SEMGREP_APP_TOKEN from any request made to non semgrep URLs
passed to -f/-c/--config during config/rules fetching. (gh-11016)var $X = $FUNC($REQ, $RES, ...) {...}
no longer fails to parse. (saf-2159)tsconfig.json matching for Typescript projects
that contain multiple tsconfig.jsons. (saf-2163)Semgrep no longer fails to validate a config when a rule lang is capitalized (Introduced 1.137.0) (saf-2247)
…That repository will be *deprecated* as of this release, and future MCP contributions / issues should go into this repo. (saf-2239)
semgrep mcp subcommand, which runs the Semgrep MCP server, which previously
used to live at https://github.com/semgrep/mcp. That repository will be deprecated
as of this release, and future MCP contributions / issues should go into this repo. (saf-2239)\# and \ in glob patterns found in
Semgrepignore and included Gitignore files. (fix-glob-escape)pkg_resources is deprecated warning by bumping opentelemetry-*
packages (gh-11069)semgrep mcp subcommand, which runs the Semgrep MCP server, which previously
used to live at https://github.com/semgrep/mcp. That repository will be deprecated
as of this release, and future MCP contributions / issues should go into this repo. (saf-2239)\# and \ in glob patterns found in
Semgrepignore and included Gitignore files. (fix-glob-escape)pkg_resources is deprecated warning by bumping opentelemetry-*
packages (gh-11069)## 1.136.0 - 2025-09-09 No significant changes.
No significant changes.
## 1.135.0 - 2025-09-03 No significant changes.
No significant changes.
Your coding agent can read these notes before it upgrades. Set up the MCP server →