NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
PyPI · #815 most downloaded on PyPI
Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.
Last release 2 days ago
02 Oct 2026
Ships on a steady schedule
a new release about every 2 weeks
Nearly every release is documented
notes for 54 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
6 years old
360 releases · first in 2020
One column per quarter.
pro: First version of inter-file (whole-program) analysis for Scala. (code-9029)
Pro: improved prefiltering for interfile rules. This allows the engine to skip interfile rules earlier in the process when we determine they cannot ma
new in some cases. (code-9047)nan as well as some more
obscure cases that were interpreted as a float instead of a string. This
might affect any area of Semgrep that deals with YAML files containing
the string nan. (yaml-float-parsing)No significant changes.
No significant changes.
PHP: When enabling option taint_assume_safe_booleans the return values of boolval, is_bool, and || will be considered safe. When enabling taint_assume
taint_assume_safe_booleans the return values of
boolval, is_bool, and || will be considered safe.
When enabling taint_assume_safe_numbers the return values of intval,
floatval, +, -, *, / and % will also be considered safe. (php)Semgrep diff scans can now query the app for which merge base to use. This fixes the issue where some diff scans on shallow clones would use the wrong
Sign in command (saf-2151)SemgrepError exception is raised and causes semgrep to fail. (silent-semgrep-error)Fix the Python parser to correctly handle and parse valid structural dictionary patterns. (gh-11100)
A warning is now printed for each exclude or include pattern found in rules
that is considered ambiguous (paths.exclude, paths.include).
Currently, a pattern that contains a middle slash such as src/*.c
is considered floating or unanchored by our implementation. In order to
be compliant with Gitignore and Semgrepignore, src/*.c
should be treated as anchored. Since many programmers are unaware of this
subtlety in the Gitignore specification, Semgrep now prints a warning asking
the user to lift the ambiguity. A user will now be asked to
change their pattern src/*.c into either /src/*.c (anchored) or
**/src/*.c (floating). This clarifies the expected behavior for readers
of Semgrep rules and will avoid problems when Semgrep rules adopt
the Gitignore/Semgrepignore behavior. (rule-paths-middle-slash-patterns)
Secrets: Validation for AWS credentials which failed due to possibly transient reasons is now retried (3 attempts max). (scrt-917)
semgrep scan in a docker container without an argument
and no target project was mounted under /src,
instead of a silent exit with code 2, a helpful error message is
now printed before exiting. (docker-mount-error)paths.exclude, paths.include) now apply to
normalized file paths relative to the project root. This makes rule selection
independent from the current work folder.
Patterns with a leading slash such as /src are now anchored instead
of being floating. For example, exclude: [ "/src" ] will exclude the target
file src/main.c but no longer excludes misc/src/main.c. (rule-paths-leading-slash-patterns)Unix.Unix_error would occasionally crash the experimental language server
on startup. (saf-2133)get_targets endpoint.
Previously, scanning large repos with the debug flag significantly ballooned
the size of the output log. (saf-2145)No significant changes.
No significant changes.
Java: Deprecated class $A partial class pattern, in favor of ` class $A { ... } ` (safe-2104)
HTTP{,S}_PROXY=... now accepts URIs without a scheme (e.g HTTP_PROXY=domain.com:port) (saf-2082)class $A partial class pattern, in favor ofclass $A { ... }
``` (safe-2104)
Fixed an issue where Semgrep would segfault if --trace was passed and the number of jobs was greater than 1
--trace was passed and the
number of jobs was greater than 1pro: typescript: Prevent stack overflows and out-of-memory issues when reading TS configs. (code-8678)
Missing version constraints in yarn.lock descriptors no longer raise parsing errors (sc-2293)
Dependency resolution errors that result from local builds are now reported in the scan log by default. (SC-2442)
--json. (SC-2458).semgrepignore excludes to be applied to Secrets product scans. Now, Semgrep will once again scan files that have been excluded from Code and SSC scans for possible leaked secrets. (SAF-2067)semgrep ci logs in GitLab would return an incorrect URL
with the wrong &ref=... argument. (saf-959)Fixed an issue present since v1.117.0 that led .semgrepignore excludes to be applied to Secrets product scans. Now, Semgrep will once again scan files
.semgrepignore excludes to be applied to Secrets product scans. Now, Semgrep will once again scan files that have been excluded from Code and SSC scans for possible leaked secrets. (SAF-2067)Parallelizes rule validation to improve performance when scanning with many rule files. (SAF-2061)
ALL_PROXY, HTTP_PROXY, HTTPS_PROXY,
NO_PROXY, PROXY_USERNAME and PROXY_PASSWORD for all networking (including
that done via the OCaml components). Moreover, the environment variable
OCAML_EXTRA_CA_CERTS should now allow additional CA certs to be used for
network operations done by OCaml components. (code-8157)build.gradle.kts files as build.gradle. (SC-2209)requires: of the form not A, could produce findings with an empty
list of traces, potentially causing a crash. We now recognize the issue and
prevent the crash from happening. (code-8531)f"" was not matched by the pattern "...". (gh-10047)metavariable-type. Concretely, "2 * groups" was not considered an int, where groups is an int. Additionally adds type inference for mod, floor division, and pow. (gh-9855)…when the actually used direct dependency was not vulnerable. (SC-2088)
Adds support for the UV package manager in Supply Chain scans. (SC-1900)
pro: Fixed inter-file naming bug affecting Go's struct-methods that could result in false negatives.
Previously, adding a pattern-inside like
func ($THING $TYPE) $FUNC(...) $R { ... }
to a taint rule could cause some findings to incorrectly stop being reported. (code-7767)
PRO: Fixed the issue with type matching when a type has a type parameter, e.g., matching the pattern std::vector<$T> with the code std::vector<int> v in C++. (code-8443)
Make Nuget dependency child parsing case insensitive (sc-2355)
Fixed bug where direct dev depenencies were not marked as direct when parsing package-lock.json projects. (sc-dev)
pro: Improved handling of tsconfig.json in instances where multiple typescript "projects" (i.e., separately rooted source directories with their own c
tsconfig.json in instances where multiple
typescript "projects" (i.e., separately rooted source directories with their
own configurations not joined by a single tsconfig.json with project
references) are being scanned as one project under semgrep. This should result
in better name/module resolution in TypeScript. (code-7798)include, exclude and files properties in
tsconfig.json. Projects which use more than one tsconfig in a given directory
which apply to different sets of files under that directory should see
improvements in name/module resolution. (code-7798-a)-j1 and it can be overridden by the user. (interfile-num-jobs)--disable-nosem was not properly causing nosemgrep'd findings
to be uploaded to the App. (saf-1982)Fix bug introduced in Semgrep 1.120.0 causing interfile analyses to run out of memory due to too many parallel jobs. The default setting had been acci
-j1 and it can be overridden by the user. (interfile-num-jobs)Added a few new entries in the .semgrepignore default file (e.g., _cargo, _opam, .svn) (semgrepignore)
--x-semgrepignore-filename to change the name of .semgrepignore files to something else. This can be used to scan a subproject in a separate semgrep invocation as the rest of the containing project. (semgrepignore-filename)-j setting so as to take into account the cgroup
CPU quota on Linux. This will affect Docker and other containerized
environments that share resources on the same host. Use the new command
semgrep show resources --experimental to show the default setting. (saf-1950)python: Semgrep will now perform dataflow analysis within and through comprehensions. (saf-1560)
semgrep show project-root is now provided to display
the project root path associated with a scan root. This is useful for
troubleshooting Semgrepignore (v2) issues. (saf-1936)tainting: Apply taint_assume_safe_numbers and taint_assume_safe_booleans
earlier when considering to track taint through class fields and function
parameters. If the field/parameter has a number/Boolean type and the
corresponding option is set, it will just not be tracked. In some cases this
can help with performance.
Also added short/Short to the list of integer types recognized by
taint_assume_safe_numbers. (code-8345)
IDE: The Semgrep VS Code Extension will no longer hang on Getting code actions from Semgrep...
on saving a file, when updating rules. (saf-1954)
Pro: Failure to parse a package.json file when analysing JavaScript or TypeScript is no longer a fatal error. (code-8227)
Pro: Failure to parse a package.json file when analysing JavaScript or
TypeScript is no longer a fatal error. (code-8227)
taint-mode: Fixed bug in taint "auto-cleaning" where we automatically clean the LHS of an assigmnet if the RHS is clean, provided that the LHS is not subject to any "side-effects". In some cases, this could cause the taint analysis to timeout. Some combinations of rules and repos will see a major perf improvement, in other cases it may not be noticeable. (code-8288)
In a Semgrep rule's metadata section, two fields may provide URLs:
source: populated dynamically by the Semgrep registry serving the rule, it's a URL that
offers information about the rule.source-rule-url: optional string, a URL for the source of inspiration for the rule.The SARIF format supports only one URL under the field helpUri.
Previously, Semgrep populated the SARIF helpUri field only with metadata.source.
This fix is to use metadata.source if available, otherwise falling back to metadata.source-rule-url.
Contributed by @candrews. (gh-10891)
Add temporary backward compatibility in Semgrepignore v2 for patterns that start with ./. For example, the pattern ./*.py should be written as /*.py t
./. For example, the pattern ./*.py should be written as
/*.py to have the desired effect of excluding the .py files
located in the same directory as the .semgrepignore file containing
the pattern.
To minimize surprises for users switching to Semgrepignore v2,
we'll be interpreting automatically ./*.py as /*.py for the time
being so as to match the legacy Semgrepignore v1 behavior. Users should not
rely on this since it doesn't comply with the Gitignore/Semgrepignore
standard and will be removed in the future. (tolerate-semgrepignore-v1-dotslash).gitignore files. There can now
be multiple .semgrepignore files in the project. The .semgrepignore file
in the current folder is no longer consulted unless it in the project.
Negated patterns are now supported such as !scanme.py as with Gitignore.
Some bugs were fixed. (use-semgrepignore-v2)* and ? to match file names with a leading period. This matches the behavior of Gitignore and Semgrepignore v1. (semgrepignore-dotfiles)Use value of $XDG_CACHE_HOME before hardcoded ~/.cache for semgrep_version file (gh-4465)
Pro Engine now more accurately tracks the scope of Python local variables. For example, the following code defines two z variables that should be trac
Pro Engine now more accurately tracks the scope of Python local variables. For
example, the following code defines two z variables that should be tracked
separately.
z = 1
def foo():
z = 2
a = z
The Pro engine now correctly recognizes that the z assigned to a is the one
defined in the local scope, not the global scope. (code-8114)
Semgrep will no longer fail a diff scan if there is a relative safe directory (saf-1851)
TypeScript parser now allows ellipses in class bodies. For example, you can write the pattern like: ` class $C { ... $FUNC() { ... } ... } ` (code-824
class $C {
...
$FUNC() { ... }
...
}
``` (code-8242)
return foo() as one such sink. (code-8199)--gitlab-secrets output has been updated to conform to GitLab JSON schema (scrt-849)--semgrepignore-v2 changed to be closer to the legacy
Semgrepignore v1. .gitignore files are no longer loaded automatically
as part of the Semgrepignore v2 exclusion mechanism.
Loading a .gitignore file must be done
by placing :include .gitignore in the .semgrepignore file
as was the case with Semgrepignore v1. (semgrepignore-v1-compat)This was used by semgrep-action which has been deprecated. (semgrep-action)
.semgrepignore file lookup using the SEMGREP_R2C_INTERNAL_EXPLICIT_SEMGREPIGNORE environment variable. This was used by semgrep-action which
has been deprecated. (semgrep-action)django). (code-8146)pro: Inter-file analysis will now process Javascript and Typescript files together, so that taint can be tracked across both languages. (code-8076)
pro: Inter-file analysis will now process Javascript and Typescript files together, so that taint can be tracked across both languages. (code-8076)
Pro: new metavariable-name operator which allows for expressing a constraint
against the fully qualified name or nearest equivalent of a metavariable
(useful mainly in JavaScript and TypeScript, where there is no first-class
syntax for this, or where such names or pseudo-names containt symbols which
cannot appear in identifiers). Requires pro naming passes and works best with
interfile naming.
Additional documentation forthcoming. (code-8121)
Fixed a regression in pro interfile mode where type inference for the var
keyword in Java was not functioning correctly. (code-7991)
PRO: Fix the range not found error when using a metavariable pattern match on
a typed metavariable. For example, the following metavariable pattern rule will
no longer trigger the error:
patterns:
- pattern: ($FOO $VAR).bar()
- metavariable-pattern:
metavariable: $FOO
pattern-either:
- pattern: org.foo.Foo
``` (code-8007)
lsp will no longer send diagnostics where the message is MarkupContent since
our current implementation does not discriminate on the client capability for
recieiving such diagnostics (to-be-added in 3.18). (code-8120)
Yarn.lock parser now correctly denotes NPM organization scope. (sc-2107)
Packages in Package.resolved without a version are now ignored. (sc-2116)
Updated Package.swift parser to support:
Pyproject.toml files are now parsed using a toml parser (tomli). (sc-2054)
..., PAT, ... patterns. (saf-682)pro: Semgrep can now dynamically resolve dependencies for Python projects using pip, allowing it to determine transitive dependencies automatically. (
git worktree remove more gracefully.
Instead of erroring, we continue to scan so that the user can still get results, but
log the error. It also adds a guard so that this failure is less likely to happen
and will include more debugging information when it does. (sms-521)More testing of pnpm-lock.yaml dependency parsing. (gh-2999)
class A extends B with C with D, the order
of precedence is D, C, B, and A. (code-7891)Semgrep can dynamically resolve dependencies for C# Solutions denoted by *.csproj (sc-2015)
See 1.105.0 Changelog:
Supply chain diff scans now skip resolving dependencies for subprojects without changes. (SC-2026)
pro: Fixed bug in inter-file matching of subtypes. When looking to match some
type A, Semgrep will match any type B that is a subtype of A, but in certain
situations this did not work. (code-7963)
taint-mode: Make traces record assignments that transfer taint via shapes.
For example, in code like:
B b = new B(taint);
B b1 = b;
sink(b1.getTaintedData());
The assignment b1 = b should be recorded in the trace but previously it was not. (code-7966)
Python: Parser updated to the most recent tree-sitter grammar. Parse rate from 99.8% -> 99.998%. (saf-1810)
pro: taint: Support for lambdas as callbacks.
pro: taint: Support for lambdas as callbacks.
var tainted = source();
function withCallback1(val, callback) {
if (val) {
callback(val);
}
}
withCallback1(tainted, function (val) {
sink(val); // finding !
}); (code-7626)
pro: python: Semgrep will now consider top-level lambdas like x below for
inter-procedural analysis:
x = lambda s: sink(s) # now we get a finding !
x(taint) (gh-10731)
pip from the Semgrep Docker image. If you need it, you may install it by running apk add py3-pip. (saf-1774)withs, like this:with (
f() as a,
g() as b,
):
pass
``` (saf-1802)
Added pro-only support for parsing a dependency graph from package-lock.json v1 files (SC-1858)
semgrep test and semgrep validate commands have been
correctly documented as EXPERIMENTAL (in semgrep --help).
Those commands are not GA yet and people should still
use the semgrep scan --test and semgrep scan --validate (or
the variants without the implicit "scan") commands (unless
they want to experiment with getting results faster and are ok
with incomplete coverage of the legacy semgrep --test
and semgrep --validate). (experimental)So for instance, we would be able to determine a source-to-sink vulnerability in the following code snippet: ``` class A: def foo(self, x): sink(x)
semgrep ci to allow semgrep-app to block scans based on specific findings (SECW-2740)pro: Improved inter-file tracking of tainted global variables. (code-7054)
Python (pro-only): Taint now correctly tracks through calls to class methods
within a class, via the cls parameter.
So for instance, we would be able to determine a source-to-sink vulnerability in the following code snippet:
class A:
def foo(self, x):
sink(x)
@classmethod
def bar(cls):
cls.foo(source)
``` (saf-1765)
pro: Fixed bug when generating inter-procedural taint traces, that it could cause a call-step to be missing in the trace. (saf-1783)
Restored the "rules" field in the SARIF output, even when logged out. (saf-1794)
Pro engine now correctly distinguishes overloaded Scala methods based on their arity and parameter types, e.g., foo(x: Int, y: String) vs. foo(x: Stri
foo(x: Int, y: String) vs. foo(x: String, y: Int). (code-7870)pro: Fixed a bug in interprocedural index-sensitive taint analysis that caused false negatives when a function updated an arbitrary index, e.g.:
var x = {};
function foo(k) {
x[k] = source();
}
function test(k) {
foo(k);
sink(x); // finding here!
} (CODE-7838)
Fixed bug affecting taint tracking through static fields when mixing accesses using the class name and using an instance object, e.g.:
class C {
static String s;
}
...
C o = new C();
C.s = taint;
sink(o.s); // finding ! (CODE-7871)
No more RPC error when using --sarif with some join-mode rules. Moreover, regular rules without the 'languages:' field will be skipped instead of aborting the whole scan. (gh-10723)
Fix the date format used in --gitlab-sast option to match the spec and not use the RFC 3339. Thanks to Elias Haeussler for the fix. (saf-1755)
Improved logic for interfile analysis in TypeScript projects using project references. (code-7677)
The pro engine now handles duplicate function names in C. When duplicate functions are found, we assume that any of the duplicated functions could be
The pro engine now handles duplicate function names in C. When duplicate
functions are found, we assume that any of the duplicated functions could be
called. For example, if the function foo is defined in two different files,
taint errors will be reported for both instances:
// "a/test.h"
void foo(int x) {
//deepruleid: dup-symbols
sink(x);
}
// "b/test.h"
void foo(int x) {
//deepruleid: dup-symbols
sink(x);
}
// "main.c"
#ifdef HEADER_A
#include "a/test.h"
#else
#include "b/test.h"
#endif
int main() {
int x = source();
foo(x);
}
``` (code-7654)
[: such as [:a-z]. (saf-1693)semgrep scan: anchored semgrepignore patterns for folders such
as /tests are now honored properly. Such patterns had previously no
effect of target file filtering. (semgrepignore-anchored-dirs)Remove deprecated --enable-experimental-requirements flag. Functionality has been always enabled since Semgrep 1.93.0. (ssc-1903)
--enable-experimental-requirements flag. Functionality has
been always enabled since Semgrep 1.93.0. (ssc-1903)osemgrep with the Pro Engine now correctly runs rules with proprietary languages (saf-1686)pro: taint-mode: Semgrep should no longer confuse a return in a lambda with a return in its enclosing function.
pro: taint-mode: Semgrep should no longer confuse a return in a lambda with
a return in its enclosing function.
E.g. In the example below the return value of foo is NOT tainted:
function foo() {
bar(() => taint);
return ok;
} (code-7657)
OCaml: matching will now recognized "local open" so that a pattern like
Foo.bar ... will now correctly match code such as let open Foo in bar 1
or Foo.(bar 1) in addition to the classic Foo.bar 1. (local_open)
Project files lacking sufficient read permissions are now skipped gracefully by semgrep. (saf-1598)
Semgrep will now print stderr and additional debugging info when semgrep-core exits with a fatal error code but still returns a json repsonse (finishes scanning) (saf-1672)
semgrep ci should parse correctly git logs to compute the set of contributors even if some authors have special characters in their names. (saf-1681)
The existing experimental flag --enable-experimental-requirements is now deprecated and will be removed in a future release. (gh-2441)
require) in arbitrary
expression contexts. Notably, in-line use of require should now be linked to
the correct module. For instance, the pattern foo.bar should now match
against require('foo').bar and taint is likewise similarily tracked. (code-7485)semgrep ci output now includes a list of all secrets rules which
generated at least one blocking finding (similar to Code) (code-7663)--allow-dynamic-dependency-resolution for dynamic resolution of Maven and Gradle dependencies for projects that do not have lockfiles (in Semgrep Pro only). (gh-2389)--enable-experimental-requirements is now deprecated and
will be removed in a future release. (gh-2441)Pro: taint-mode: Semgrep has now basic support to track taint through callbacks, when they lead to a sink, e.g.:
Pro: taint-mode: Semgrep has now basic support to track taint through callbacks, when they lead to a sink, e.g.:
function unsafe_callback(x) {
sink(x); // finding here now !
}
function withCallback(val, callback) {
callback(val);
}
withCallback(taint, unsafe_callback); (code-7476)
New subcommand dump-cst for tree-sitter languages available via semgrep show. This shows the concrete syntax tree for a given file. (code-7653)
Pro only: Updated C# parser supporting all versions of the language up to 13.0 (.NET 9) (saf-1610)
Added support for the Move-on-sui language! (sui)
Pro-only: semgrep test now supports the --pro flag to not only use pro languages
but also run the tests with the --pro-intrafile engine flag. If a finding
is detected only by the pro engine, please use proruleid: instead of ruleid:
and if an OSS finding is actually a false positive for the pro engine, please
add the prook: to your test annotation. (test_pro)
pro: dataflow: Fixed a bug that could cause a class constructor to not be analyzed in the correct dependency order, potentially leading to FNs. (code-7649)
Display an ✘ instead of a ✔ in the scan status print out when scanning with Semgrep OSS code is not enabled. (grow-422)
semgrep will no longer randomly segfault when --trace is on with -j > 2 (saf-1590)
Previously, semgrep fails when --trace-endpoint is specified, but --trace is not.
Now, we relax this requirement a bit. In this case, we disable tracing, print out a warning, and continue to scan. (sms-550)
Type inference in the Pro engine has been improved for class fields in TypeScript that are assigned a new instance but lack an explicit type definitio
class Foo { private readonly bar = new Bar(); }, the type of
bar is inferred to be Bar. (code-7635)rich.errors.LiveError where attempting to display multiple progress bars
raises an exception as flagged in #10562. (grow-414)-n to sometimes not match code -n. (saf-1592)Expanded support for requirement lockfiles. Semgrep will now find any *requirement*.txt file and lockfiles in a requirements folder (/requirements/*.t
*requirement*.txt
file and lockfiles in a requirements folder (**/requirements/*.txt). This functionality
will be gated behind the --enable-experimental-requirements CLI flag. (sc-1752)CMD $...ARGS now behaves like CMD ... and matches
any CMD instruction that uses the array syntax such as CMD ["ls"]. This
fix also applies to the other command-like instructions RUN
and ENTRYPOINT. (gh-9726)Foo() will now be inferred properly to be of type Foo. (saf-1537)Fix crash on certain SCA parse errors caused by an access to an unbound variable. (gh-2259)
…method can be called. For example, tainted input vulnerabilities in both implementation classes can now be detected in the following code:
The dataflow analysis in the Pro engine can now track method invocations on variables of an interface type, safely assuming that any implementation of the method can be called. For example, tainted input vulnerabilities in both implementation classes can now be detected in the following code:
public interface MovieService {
String vulnerableInjection(String input);
}
public class SimpleImpl implements MovieService {
@Override
public String vulnerableInjection(String input) {
return sink(input);
}
}
public class MoreImpl implements MovieService {
@Override
public String vulnerableInjection(String input) {
return sink(input);
}
}
public class AppController {
private MovieService movieService;
public String pwnTest(String taintedInput) {
return movieService.vulnerableInjection(taintedInput);
}
}
``` (code-7435)
Type inference for constructor parameter properties in TypeScript is now
supported in the Pro engine. For example, the taint analysis can recognize that
sampleFunction is defined in AbstractedService class in the following code:
export class AppController {
constructor(private readonly abstractedService: AbstractedService) {}
async taintTest() {
const src = source();
await this.abstractedService.sampleFunction(src);
}
}
``` (code-7597)
Semgrep now infers more accurate type information for class fields in TypeScript. This improves taint tracking for dependency injection in TypeScript,
Semgrep now infers more accurate type information for class fields in TypeScript. This improves taint tracking for dependency injection in TypeScript, such as in the following example:
export class AppController {
private readonly abstractedService: AbstractedService;
constructor(abstractedService: AbstractedService) {
this.abstractedService = abstractedService;
}
async taintTest() {
const src = taintedSource();
await this.abstractedService.sinkInHere(src);
}
}
``` (code-7591)
Semgrep's interfile analysis (available with the Pro Engine) now ships with information about Python's standard library, improving its ability to resolve names and types in Python code and therefore its ability to produce findings. (py-libdefs)
Added support for comparing Golang pre-release versions. With this, strict core versions, pseudo-versions and pre-release versions can all be compared to each other. (sc-1739)
--pro) Semgrep will
now try to recover from it and continue the interfile analysis without falling back
immediately to intrafile analysis. This allows using --max-memory with --pro in
a more effective way. (flow-81)pro: taint-mode: Restore missing taint findings after having improved index- sensitivity:
def foo(t):
x = third_party_func(t)
return x
def test1():
t = ("ok", taint)
y = foo(t)
sink(y) # now it's found! (code-7486)
The Semgrep proprietary engine added a new entropy analyzer entropy_v2 that supports strictness options. (gh-1641)
For example, the tainted input vulnerability can now be detected in the following code:
The taint analysis can now track method invocations on variables of an interface type, when there is a single implementation. For example, the tainted input vulnerability can now be detected in the following code:
public interface MovieService {
String vulnerableInjection(String input);
}
@Service
public class MovieServiceImpl implements MovieService {
@Override
public String vulnerableInjection(String input) {
return sink(input);
}
}
@RestController("/")
public class SpringController {
@Autowired
private MovieService movieService;
@GetMapping("/pwn")
public String pwnTest(@RequestParam("input") String taintedInput) {
return movieService.vulnerableInjection(taintedInput);
}
}
When there are multiple implementations, the taint analysis will not follow any of them. We will add handling of cases with multiple implementations in upcoming updates. (code-7434)
Uses of values imported via ECMAScript default imports (e.g., import example from 'mod';) can now be matched by qualified name patterns (e.g.,
mod.default). (code-7463)
Pro: taint-mode: Allow (experimental) control taint to propagate through returns.
Now this taint rule:
pattern-sources:
- control: true
pattern: taint()
pattern-sinks:
- pattern: sink()
It is able to find this:
def foo():
taint()
def test():
foo()
sink() # now it is found! (code-7490)
A new flag --max-log-list-entries allows to control the maximum number of entries that will be shown in the log (e.g., list of rule ids, list of skipped files). A zero or negative value disables this filter. The previous hardcoded limit was at 100 (and now becomes a default value). (max_log_list_entries)
--debug mode,
without the need to set SEMGREP_LOG_SRCS=process_limits. (logging)Fixed inter-file constant propagation to prevent some definitions from being incorrectly identified as constant, when they are modified in other parts of the codebase. (code-6793)
pro: taint-mode: Fixed bug in taint signature instantiation that could cause an update to a field in a nested object to not be tracked.
For example, in the code below, Semgrep knew that Nested.update updates the
fld attribute of a Nested object. But due to this bug, Semgrep would not know that Wrapper.updateupdated thefldattribute of thenestedobject attribute in aWrapper` object.
public class Nested {
private String fld;
public void update(String str) {
fld = str;
}
// ...
}
public class Wrapper {
private Nested nested;
public void update(String str) {
this.nested.update(str);
}
// ...
} (code-7499)
Fixed incorrect range matching parametrized type expressions in Julia (gh-10467)
Fixed an edge case that could lead to a failure to name or type imported Python symbols during interfile analysis. (py-imports)
Fix overly-aggressive match deduplication that could, under certain circumstances, lead to findings being closed and reopened in the app. (saf-1465)
Fixed regex-fix numbered capture groups, where it used to be the case that
a replacement: regex with numbered capture groups like \1\2\3 would effectivly
be the same as \1\1\1.
After the fix:
# src.py
12345
pattern: $X
fix-regex:
regex: (1)(2)(3)(4)(5)
replacement: \5\4\3\2\1
actually results in the fix
54321
``` (saf-1497)
Semgrep now recognizes files ending with the extention .tfvars as terraform files (saf-1481)
.tfvars as terraform files (saf-1481)Fixed an error with julia list comprehentions where the pattern:
[$A for $B in $C]
would match
[x for y in z]
However we would only get one binding [$A/x]
Behavior after fix: we get three bindings [$A/x,$B/y,$C/z] (saf-1480)
## 1.84.1 - 2024-08-07 No significant changes.
No significant changes.
We switch from magenta to yellow when highlighting matches with the medium or warning severity. We now use magenta for cricical severity to be consist
Dockerfile: Allow Semgrep Ellipsis (...) in patterns for HEALTHCHECK commands. (saf-1441)
Added testsuite/ as a filepath to the default value for .semgrepignore. (gh-1876)
testsuite/ as a filepath to the default value for .semgrepignore. (gh-1876)Fixed metavariable comparison in step mode.
Used to be that the rule:
steps:
- languages: [python]
patterns:
- pattern: x = f($VAR);
- languages: [generic]
patterns:
- pattern-either:
- patterns:
- pattern: HI $VAR
Wouldn't match, as one is an identifier, and the other an expression that has a string literal. The fix was chainging the equality used. (saf-1061)
The --debug option will now display logging information from the semgrep-core binary directly, without waiting that the semgrep-core program finish. (
C++: Scanning a project with header files (.h) now no longer causes a spurious warnings that the file is being skipped, or not analyzed. (code-6899)
Semgrep will now be more strict (as it should be) when unifying identifiers.
Patterns like the one below may not longer work, particularly in Semgrep Pro:
patterns:
- pattern-inside: |
class A:
...
def $F(...):
...
...
...
- pattern-inside: |
class B:
...
def $F(...):
...
...
...
Even if two classes A and B may both have a method named foo, these methods
are not the same, and their ids are not unifiable via $F. The right way of doing
this in Semgrep is the following:
patterns:
- pattern-inside: |
class A:
...
def $F1(...):
...
...
...
- pattern-inside: |
class B:
...
def $F2(...):
...
...
...
- metavariable-comparison:
comparison: str($F1) == str($F2)
We use a different metavariable to match each method, then we check whether they have the same name (i.e., same string). (code-7336)
In the app, you can configure Secrets ignores separately from Code/SSC ignores. However, the files that were ignored by Code/SSC and not Secrets were still being scanned during the preprocessing stage for interfile analysis. This caused significantly longer scan times than expected for some users, since those ignored files can ignore library code. This PR fixes that behavior and makes Code/SSC ignores apply as expected. (saf-1087)
Fixed typo that prevented users from using "--junit-xml-output" flag and added a tests that invokes the flag. (saf-1437)
OSemgrep now can take --exclude-minified-files to skip minified files. Additionally --no-exclude-minified-files will disable this option. It is off by
OSemgrep now can take --exclude-minified-files to skip minified files. Additionally --no-exclude-minified-files will disable this option. It is off by default. (cdx-460)
Users are now required to login before using semgrep scan --pro.
Previously, semgrep will tell the users to log in, but the scan will still continue.
With this change, semgrep will tell the users to log in and stop the scan. (saf-1137)
The language server no longer scans large or minified files (cdx-460)
Pro: Improved module resolution for Python. Imports like from a.b import c where
c is a module will now be resolved by Semgrep. And, if a module cannot be found
in the search path, Semgrep will try to heuristically resolve the module by matching
the module specifier against the files that are being scanned. (code-7069)
A scan can occasionally freeze when using tracing with multiprocesses.
This change disables tracing when scanning each target file unless the scan runs in a single process. (saf-1143)
Improved error handling for rules with invalid patterns. Now, scans will still complete and findings from other rules will be reported. (saf-789)
The "package-lock.json" parser incorrectly assumed that all paths in the "packages" component of "package-lock.json" started with "node_modules/".
In reality, a dependency can be installed anywhere, so the parser was made more flexible to recognize alternative locations ("node_modules", "lib", etc). (sc-1576)
Preliminary support for the Move on Aptos language (see https://aptos.dev/move/move-on-aptos for more info on this language). Thanks a lot to Zhiping
tainting: Fixed bug in --pro-intrafile that caused Semgrep to confuse a parameter
with a top-level function with no arguments that happened to have the same name:
def foo
taint
end
def bar(foo)
sink(foo) # no more FP here
end (code-6923)
Fixed fatal errors on files containing nosemgrep annotation without any rule ID after. (nosemgrep_exn)
Matching explanations: Focus nodes now appear after filter nodes, which is the correct order of execution of pattern nodes. Filter nodes are now unreversed. (saf-1127)
Autofix: Previews in the textual CLI output will now join differing lines with a space, rather than joining with no whitespace whatsoever. (saf-1135)
Secrets: resolved some rare instances where historical scans would skip blobs depending on the structure of the local copy of the repository (i.e., blobs were only skipped if the specific copy of the git store had a certain structure). (scrt-630)
Matching of fully qualified type names in the metavariable-type operator has been improved. For example:
Matching of fully qualified type names in the metavariable-type operator has been improved. For example:
from a.b import C
x = C()
The type of x will match both a.b.C and C.
- pattern: $X = $Y()
- metavariable-type:
metavariable: $X
types:
- a.b.C # or C
``` (code-7269)
Symbolic propagation now works on decorator functions, for example:
x = foo
@x() # this is now matched by pattern `@foo()`
def test():
pass (code-6634)
Fixed an issue where Python functions with annotations ending in endpoint,
route, get, patch, post, put, delete, before_request or
after_request (i.e., ones we associate with Flask) were incorrectly analyzed
with the Code product in addition to the Secrets product when present in a file
being ignored for Code analysis but included for Secrets. (scrt-609)
Semgrep will now report the id of the organization associated with logged in users when reporting metrics in the language server (cdx-508)
Semgrep will now report the id of the organization associated with logged in users when reporting metrics in the language server (cdx-508)
Pro: taint-mode: Improved index-sensitive taint tracking for tuple/list (un)packing.
Example 1:
def foo():
return ("ok", taint)
def test():
x, y = foo()
sink(x) # nothing, no FP
sink(y) # finding
Example 2:
def foo(t):
(x, y) = t
sink(x) # nothing, no FP
sink(y) # finding
def test():
foo(("ok", taint)) (code-6935)
Adds traces to help debug the performance of tainting. To send the traces added in the PR, pass
--trace and also set the environment variable SEMGREP_TRACE_LEVEL=trace. To send them to a
local endpoint instead of our default endpoint, use --trace-endpoint. (saf-1100)
Fixed a bug in the generation of the control-flow graph for try statements that
could e.g. cause taint to report false positives:
def test():
data = taint
try:
# Semgrep assumes that `clean` could raise an exception, but
# even if it does, the tainted `data` will never reach the sink !
data = clean(data)
except Exception:
raise Exception()
# `data` must be clean here
sink(data) # no more FP (flow-78)
The language server (and semgrep --experimental) should not report anymore errors from the metrics.semgrep.dev server such as "cannot read property 'map' of undefined". (metrics_error)
Fixed a bug in the gemfile.lock parser which causes Semgrep to miss direct dependencies whose package name does not end in a version constraint. (sc-1568)
Your coding agent can read these notes before it upgrades. Set up the MCP server →