NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
PyPI · #772 most downloaded on PyPI
Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.
Last release today
02 Oct 2026
Ships on a steady schedule
a new release about every 2 weeks
Nearly every release is documented
notes for 54 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
6 years old
360 releases · first in 2020
One column per quarter.
## 1.31.1 - 2023-07-07 No significant changes.
No significant changes.
Make CLI hit the new endpoint for the reliable fixed status on the Semgrep app. (cod-16)
Make CLI hit the new endpoint for the reliable fixed status on the Semgrep app. (cod-16)
feat(rule syntax): Metavariable Type Extension for Semgrep Rule Syntax 2.0
This PR introduces the changes made in Semgrep rule syntax 1.0 to version 2.0 as well.
rules:
rules:
Rust: Added the ability to taint macro calls through its arguments, in macro calls with multiple arguments. (pa-2902)
Add severity and suggested upgrade versions to Supply Chain findings (sc-772)
Added support for pnpm lockfile versions >= 6.0 (sc-824)
(sc-866)
() => {}). (gh-7353)…form $1, $2`, etc, but this should be considered deprecated behavior, and that functionality will be taken away in a future release. Named capturing g…
feat(rule syntax): Support metavariable-type field for Kotlin, Go, Scala
metavariable-type field is now supported for Kotlin, Go and Scala. (gh-8147)
feat(rule syntax): Support metavariable-type field for csharp, typescript, php, rust
metavariable-type field is now supported for csharp, typescript, php, rust. (gh-8164)
Pattern syntax: You may now introduce metavariables from parts of regular
expressions using pattern-regex, by using regular expression with
named capturing groups (see https://www.regular-expressions.info/named.html)
Now, such capture group metavariables must be explicitly named. So for instance, the pattern:
pattern-regex: "foo-(?P<X>.*)"
binds what is matched by the capture group to the metavariable $X,
which can be used as normal.
pattern-regex patterns with capture groups, such
as
pattern-regex: "(.*)"
will still introduce metavariables of the form $1, $2, etc, but this
should be considered deprecated behavior, and that functionality will be
taken away in a future release. Named capturing groups should be primarily
used, instead. (pa-2765)
Rule syntax: Errors during rule parsing are now better. For instance,
parsing will now complain if you miss a hyphen in a list of patterns,
or if you try to give a string to patterns or pattern-either. (pa-2877)
JS/TS: Now, patterns of records with ellipses, like:
{ $X: ... }
properly match to records of anonymous functions, like:
{
func: () => { return 1; }
}
``` (pa-2878)
feat(rule syntax): Support metavariable-type field for Kotlin, Go, Scala
metavariable-type field is now supported for Kotlin, Go and Scala. (gh-8147)
feat(rule syntax): Support metavariable-type field for csharp, typescript, php, rust
metavariable-type field is now supported for csharp, typescript, php, rust. (gh-8164)
Pattern syntax: You may now introduce metavariables from parts of regular
expressions using pattern-regex, by using regular expression with
named capturing groups (see https://www.regular-expressions.info/named.html)
Now, such capture group metavariables must be explicitly named. So for instance, the pattern:
pattern-regex: "foo-(?P<X>.*)"
binds what is matched by the capture group to the metavariable $X,
which can be used as normal.
pattern-regex patterns with capture groups, such
as
pattern-regex: "(.*)"
will still introduce metavariables of the form $1, $2, etc, but this
should be considered deprecated behavior, and that functionality will be
taken away in a future release. Named capturing groups should be primarily
used, instead. (pa-2765)
Rule syntax: Errors during rule parsing are now better. For instance,
parsing will now complain if you miss a hyphen in a list of patterns,
or if you try to give a string to patterns or pattern-either. (pa-2877)
JS/TS: Now, patterns of records with ellipses, like:
{ $X: ... }
properly match to records of anonymous functions, like:
{
func: () => { return 1; }
}
``` (pa-2878)
feat(rule syntax): Metavariable Type Extension for Semgrep Rule Syntax
We've added a dedicated field for annotating the type information of metavariables. By adopting this approach, instead of relying solely on language-specific casting syntax, we provide an additional way to enhance the overall usability by eliminating the need to write redundant type cast expressions for a single metavariable.
Moreover, the new syntax brings other benefits, including improved support for target languages that lack built-in casting syntax. It also promotes a unified approach to expressing type, pattern, and regex constraints for metavariables, resulting in improved consistency across rule definitions.
Current syntax:
rules:
- id: no-string-eqeq
severity: WARNING
message: find errors
languages:
- java
patterns:
- pattern-not: null == (String $Y)
- pattern: $X == (String $Y)
Added syntax:
rules:
- id: no-string-eqeq
severity: WARNING
message: find errors
languages:
- java
patterns:
- pattern-not: null == $Y
- pattern: $X == $Y
- metavariable-type:
metavariable: $Y
type: String
``` (gh-8119)
feat(rule syntax): Support metavariable-type field for Python
metavariable-type field is now supported for Python too. (gh-8126)
New --experimental flag to switch to a new implementation of Semgrep entirely written in OCaml with faster startup time, incremental display of matches, AST and registry caching, a new interactive mode and more. Not all features of the legacy Python Semgrep have been ported though. (osemgrep)
Matching: Writing a pattern which is a sequence of statements, such as
foo();
...
bar();
now allows matching to sequences of statements within objects, classes, and related language constructs, in all languages. (pa-2754)
taint_assume_safe_{booleans,numbers} options.
Most notably, we will now use type info provided by explicit type casts, and we will
also use const-prop info to infer types. (pa-2777)Added support for post-pip0614 decorators; now semgrep accepts decorators of
the form @ named_expr_test NEWLINE, so for example with the pattern
lambda $X:$X($X):
#match 1
@omega := lambda ha:ha(ha)
def func():
return None
#match 2
@omega[lambda a:a(a)].a.b.c.f("wahoo")
def fun():
return None
``` (gh-4946)
Fixed a typing issue with go; where semgrep with the pattern '($VAR : *tau.rho).$F()` wouldn't produce a match in the following:
func f() {
i_1 := &tau.rho{}
i_2 := new(tau.rho)
i_1.shift() //miss one
i_2.left() //miss two
return 101
}
but now we don't miss those two findings! (gh-6733)
Constant propagation is now applied to stack array declarations in C; so
a pattern $TYPE $NAME[101]; will now produce two matches in the following snippet:
int main() {
int bad_len = 101;
/* match 1 */
int arr1[101];
/* match 2 */
int arr2[bad_len];
return 0;
}
``` (gh-8037)
Solidity: allow metavariables for version, as in pragma solidity >= $VER; (gh-8104)
Added support for parsing patterns of the form
#[Attr1]
#[Attr2]
In code such as
#[Attr1]
#[Attr2]
function test ()
{
echo "Test";
}
Previously, to match against multiple attributes it was required to write
#[Attr1, Attr2]
``` (pa-7398)
Added lone decorators as a valid Python semgrep pattern, so for example $NAME($X) will
generate two seperate findings here:
@hello("world")
@hi("semgrep!")
def shift():
return "left!"
``` (gh-4722)
Add tags to the python wheel for 3.10 and 3.11 (gh-8040)
JS/TS: Patterns for class properties can now have the static
and async modifiers.
For instance:
@Foo(...)
async bar(...) {
...
}
or
@Foo(...)
static bar(...) {
...
}
``` (pa-2675)
Semgrep Language Server now supports multi-folder workspaces (pa-2772)
New pre-commit hook semgrep-ci to use CI rules in pre-commit, which will pull from the rule board + block those in the block column (pa-2795)
Added support for date comparison and functionality to get current date. Currently this requires date strings to be in the format "yyyy-mm-dd" next step is to support other formats. (pa-7992)
--debug will be much less verbose by default, it will only show
internal warning and error messages. (debug-1)taint analysis: Improve handling of dataflow for tainted value propagation in class field definitions
This change resolves an issue where dataflow was not correctly accounted for when tainted values flowed through field definitions in class/object definitions. For instance, in Kotlin or Scala, singleton objects are commonly used to encapsulate executable logic, where each field definition behaves like a statement during object initialization. In order to handle this scenario, we have introduced an additional step to analyze a sequence of field definitions as a sequence of statements for taint analysis. This enhancement allows us to accurately track tainted values during object initialization. (gh-7742)
Allow any characters in file paths used to create dotted rule IDs. File path
characters that aren't allowed in rule IDs are simply removed. For example, a
rule whose ID is my-rule found in the file hello/@world/rules.yaml
becomes hello.world.my-rule. (gh-8057)
Diff aware scans now work when git state isn't clean (pa-2795)
o.setX(taint); o.getX() but now it can relate setters and getters to properties (e.g. o.setX(taint); o.x). (getters)taint_assume_safe_booleans and
taint_assume_safe_numbers to avoid propagating taint coming from expressions
with Boolean or number (integer, float) types. (pa-2777)($X: $T) with a metavariable-regex operating on $T). (pa-2822)... in multiline
mode matches the whole input rather than matching nothing many times. (gh-7881)New experimental aliengrep engine that can be used as an alternative to the
default spacegrep engine with options.generic_engine: aliengrep. (aliengrep)
Pro: Taint labels now mostly work interprocedurally, except for labeled propagators. Note that taint labels are experimental! (pa-2507)
Pro: Taint-mode now supports inter-procedural field-sensitivity for JS/TS.
For example, given this class:
class Obj {
constructor(x, y) {
this.x = x;
this.y = y;
}
}
Semgrep knows that an object constructed by new Obj("tainted", "safe") has its
x attribute tainted, whereas its y attribute is safe. (pa-2570)
(List<$T> $X) would fail to match a value of
type List<String>. (typed-mvar)On scan complete during logged in semgrep ci scans, check returned exit code to
see if should block scans. This is to support incoming features that requires
information from semgrep.dev (complete)
Extract mode: users can now choose to include or exclude rules to run on, similar to paths:. For example,
to only run on the rules example-1 and example-2, you would write
rules:
- id: test-rule
mode: extract
rules:
include:
- example-1
- example-2
To run on everything except example-1 and example-2, you would write
rules:
- id: test-rule
mode: extract
rules:
exclude:
- example-1
- example-2
``` (gh-7858)
Kotlin: Added literal metavariables, from patterns like "$FOO".
You can still match strings that only contain a single interpolated
ident by using the brace notation, e.g. "${FOO}". (pa-2755)
Increase timeout of semgrep ci upload findings network calls
and make said timeout configurable with env var SEMGREP_UPLOAD_FINDINGS_TIMEOUT (timeout)
Relaxed restrictions on symbolic propagation so that symbolic values survive
branching statements. Now (with symbolic-propagation enabled) foo(bar()) will
match match the following code:
def test():
x = bar()
if cond:
exit()
foo(x)
Previously any symbolically propagated value was lost after any kind of branching statement. (pa-2739)
catch, to
write a pattern like:
try {
...
} catch {
...
}
which will match every kind of try-catch. (gh-7807)-l dockerfile, files named dockerfile as well as Dockerfile will be scanned. (gh-7824)feat(rule syntax): Metavariable Type Extension for Semgrep Rule Syntax
feat(rule syntax): Metavariable Type Extension for Semgrep Rule Syntax
We've added a dedicated field for annotating the type information of metavariables. By adopting this approach, instead of relying solely on language-specific casting syntax, we provide an additional way to enhance the overall usability by eliminating the need to write redundant type cast expressions for a single metavariable.
Moreover, the new syntax brings other benefits, including improved support for target languages that lack built-in casting syntax. It also promotes a unified approach to expressing type, pattern, and regex constraints for metavariables, resulting in improved consistency across rule definitions.
Current syntax:
rules:
- id: no-string-eqeq
severity: WARNING
message: find errors
languages:
- java
patterns:
- pattern-not: null == (String $Y)
- pattern: $X == (String $Y)
Added syntax:
rules:
- id: no-string-eqeq
severity: WARNING
message: find errors
languages:
- java
patterns:
- pattern-not: null == $Y
- pattern: $X == $Y
- metavariable-type:
metavariable: $Y
type: String
``` (gh-8119)
feat(rule syntax): Support metavariable-type field for Python
metavariable-type field is now supported for Python too. (gh-8126)
New --experimental flag to switch to a new implementation of Semgrep entirely written in OCaml with faster startup time, incremental display of matches, AST and registry caching, a new interactive mode and more. Not all features of the legacy Python Semgrep have been ported though. (osemgrep)
Matching: Writing a pattern which is a sequence of statements, such as
foo();
...
bar();
now allows matching to sequences of statements within objects, classes, and related language constructs, in all languages. (pa-2754)
taint_assume_safe_{booleans,numbers} options.
Most notably, we will now use type info provided by explicit type casts, and we will
also use const-prop info to infer types. (pa-2777)@ named_expr_test NEWLINE, so for example with the pattern
lambda $X:$X($X):#match 1
@omega := lambda ha:ha(ha)
def func():
return None
#match 2
@omega[lambda a:a(a)].a.b.c.f("wahoo")
def fun():
return None
``` (gh-4946)
func f() {
i_1 := &tau.rho{}
i_2 := new(tau.rho)
i_1.shift() //miss one
i_2.left() //miss two
return 101
}
but now we don't miss those two findings! (gh-6733)$TYPE $NAME[101]; will now produce two matches in the following snippet:int main() {
int bad_len = 101;
/* match 1 */
int arr1[101];
/* match 2 */
int arr2[bad_len];
return 0;
}
``` (gh-8037)
pragma solidity >= $VER; (gh-8104)#[Attr1]
#[Attr2]
In code such as#[Attr1]
#[Attr2]
function test ()
{
echo "Test";
}
Previously, to match against multiple attributes it was required to write#[Attr1, Attr2]
``` (pa-7398)
Added lone decorators as a valid Python semgrep pattern, so for example $NAME($X) will generate two seperate findings here: ` @hello("world") @hi("sem
Added lone decorators as a valid Python semgrep pattern, so for example $NAME($X) will
generate two seperate findings here:
@hello("world")
@hi("semgrep!")
def shift():
return "left!"
``` (gh-4722)
Add tags to the python wheel for 3.10 and 3.11 (gh-8040)
JS/TS: Patterns for class properties can now have the static
and async modifiers.
For instance:
@Foo(...)
async bar(...) {
...
}
or
@Foo(...)
static bar(...) {
...
}
``` (pa-2675)
Semgrep Language Server now supports multi-folder workspaces (pa-2772)
New pre-commit hook semgrep-ci to use CI rules in pre-commit, which will pull from the rule board + block those in the block column (pa-2795)
Added support for date comparison and functionality to get current date. Currently this requires date strings to be in the format "yyyy-mm-dd" next step is to support other formats. (pa-7992)
--debug will be much less verbose by default, it will only show
internal warning and error messages. (debug-1)taint analysis: Improve handling of dataflow for tainted value propagation in class field definitions
This change resolves an issue where dataflow was not correctly accounted for when tainted values flowed through field definitions in class/object definitions. For instance, in Kotlin or Scala, singleton objects are commonly used to encapsulate executable logic, where each field definition behaves like a statement during object initialization. In order to handle this scenario, we have introduced an additional step to analyze a sequence of field definitions as a sequence of statements for taint analysis. This enhancement allows us to accurately track tainted values during object initialization. (gh-7742)
Allow any characters in file paths used to create dotted rule IDs. File path
characters that aren't allowed in rule IDs are simply removed. For example, a
rule whose ID is my-rule found in the file hello/@world/rules.yaml
becomes hello.world.my-rule. (gh-8057)
Diff aware scans now work when git state isn't clean (pa-2795)
PHP: Added composer ecosystem parser (gh-7734)
In Java, Semgrep can now track taint through more getters and setters. It could already relate setters to getters (e.g. o.setX(taint); o.getX() but no
o.setX(taint); o.getX() but now it can relate setters and getters to properties (e.g. o.setX(taint); o.x). (getters)taint_assume_safe_booleans and
taint_assume_safe_numbers to avoid propagating taint coming from expressions
with Boolean or number (integer, float) types. (pa-2777)($X: $T) with a metavariable-regex operating on $T). (pa-2822)Fix regexps potentially vulnerable to ReDoS attacks in Python code for parsing git URLs. Sets maximum length of git URLs to 1024 characters since pars…
... in multiline
mode matches the whole input rather than matching nothing many times. (gh-7881)Yarn v1: fix parsing for package headers without version constraints (sc-749)
New experimental aliengrep engine that can be used as an alternative to the default spacegrep engine with options.generic_engine: aliengrep. (aliengre
New experimental aliengrep engine that can be used as an alternative to the
default spacegrep engine with options.generic_engine: aliengrep. (aliengrep)
Pro: Taint labels now mostly work interprocedurally, except for labeled propagators. Note that taint labels are experimental! (pa-2507)
Pro: Taint-mode now supports inter-procedural field-sensitivity for JS/TS.
For example, given this class:
class Obj {
constructor(x, y) {
this.x = x;
this.y = y;
}
}
Semgrep knows that an object constructed by new Obj("tainted", "safe") has its
x attribute tainted, whereas its y attribute is safe. (pa-2570)
(List<$T> $X) would fail to match a value of
type List<String>. (typed-mvar)On scan complete during logged in semgrep ci scans, check returned exit code to see if should block scans. This is to support incoming features that r
On scan complete during logged in semgrep ci scans, check returned exit code to
see if should block scans. This is to support incoming features that requires
information from semgrep.dev (complete)
Extract mode: users can now choose to include or exclude rules to run on, similar to paths:. For example,
to only run on the rules example-1 and example-2, you would write
rules:
- id: test-rule
mode: extract
rules:
include:
- example-1
- example-2
To run on everything except example-1 and example-2, you would write
rules:
- id: test-rule
mode: extract
rules:
exclude:
- example-1
- example-2
``` (gh-7858)
Kotlin: Added literal metavariables, from patterns like "$FOO".
You can still match strings that only contain a single interpolated
ident by using the brace notation, e.g. "${FOO}". (pa-2755)
Increase timeout of semgrep ci upload findings network calls
and make said timeout configurable with env var SEMGREP_UPLOAD_FINDINGS_TIMEOUT (timeout)
Relaxed restrictions on symbolic propagation so that symbolic values survive
branching statements. Now (with symbolic-propagation enabled) foo(bar()) will
match match the following code:
def test():
x = bar()
if cond:
exit()
foo(x)
Previously any symbolically propagated value was lost after any kind of branching statement. (pa-2739)
catch, to
write a pattern like:
try {
...
} catch {
...
}
which will match every kind of try-catch. (gh-7807)-l dockerfile, files named dockerfile as well as Dockerfile will be scanned. (gh-7824)Add support for language Cairo 1.0 (develop). Thanks to Frostweeds (Romain Jufer) for his contribution! (gh-7757)
semgrep ci scans, report lockfile parse errors to display in webUI (lockfileparse)C sets its field x to a
tainted value, given o = new C(), Semgrep will know that o.getX() is tainted. (pa-2570)Failure "Call AST_utils.with_xxx_equal to avoid this error." (gh-7694)
Scala: Most Scala 3 features can now be parsed (pa-2748)
Pro: Taint: Added support for simple cases of interprocedural taint labels (pa-2708)
semgrep --pro still requires a single target, but this target no longer
needs to be a directory, it can be an individual file too. (misc-1)metavariable-pattern operator in one rule may cause a finding to be missed, and
the file being reported as partially analyzed. However, that error did not affect
any other rules, and even the affected rule may be able to produce some findings. (pa-2683)get<name> methods in a
loop. (pro-56)Java: Private static variables that are defined just once in a static block, even if they are not declared final, will be considered as final by const
Java: Private static variables that are defined just once in a static block,
even if they are not declared final, will be considered as final by
constant-propagation. (pa-2228)
Scala: Can now parse indented matches, like:
e match case foo => "foo" case bar => "bar" (pa-2687)
Scala: Can now parse arguments with using, as well as splatted arguments.
E.g. foo(using bar) and foo(1, 2, bar*) (pa-2688)
Scala: Added parsing of enum constructs. (pa-2691)
Scala: Can now parse given definitions (pa-2692)
Scala: Can now parse exports (pa-2693)
Scala: Can now parse top-level definitions (as added in Scala 3) (pa-2694)
Scala: Can now parse indented for expression, such as
for _ <- 5 yield ... (pa-2695)
The title of Supply Chain findings will now consist of the package name and CVE, instead of just the rule's UUID. (sc-580)
diff the outputs of two runs. (pa-2700)CLI: Setting Semgrep-specific environment variables for metadata (like SEMGREP_REPO_NAME, SEMGREP_REPO_URL, SEMGREP_PR_ID, and friends) now properly works on GitHub and GitLab CI scans.
If not set, functionality is same as before. (pa-2644)
CLI: Fixed a bug where repositories with a dot in the name would cause semgrep ci scans to crash (pa-2655)
Metavariable comparison: Added support for , the exponentiation operator. (gh-7474)
Metavariable comparison: Added support for **, the exponentiation operator. (gh-7474)
Pro: Java: Semgrep is now able to track the propagation of taint from the arguments of a method, to the object being called. So e.g. given a method
public void foo(int x) {
this.x = x;
}
and a call o.foo(tainted), Semgrep will be able to track that the field
x of o has been tainted. (pa-2570)
Kotlin: Class fields will now receive the correct types, and be found by typed metavariables correctly
This applies to examples such as:
class Foo {
var x : int
}
for the variable x (pa-2684)
Supply Chain support for package-lock.json version 3 (sc-586)
metavariable-pattern: When used with the nested language key, if there was an
error parsing the metavariable's content, that error could abort the analysis
of the current file. If there were other rules that were going to produce findings
on that file, those findings were not being reported. (gh-7271)
Matching: Fixed a bug where explicit casts of expressions would produce two matches to other explicit casts.
So for instance, a pattern (int $X) in Java would match twice to (int) 5. (gh-7403)
taint-mode: Given x = tainted, then x.a = safe, then x.a.b = tainted, Semgrep
did not report sink(x.a.b). Because x.a was clean, that made Semgrep disregard
the tainting of any field of x.a such as x.a.b. This now works as expected. (pa-2486)
When using metavariable-pattern to match embedded PHP code, Semgrep was
unconditionally adding the <?php opening to the embedded code. When
<?php was already present, this caused parsing errors. (pa-2696)
Lockfile-only supply chain findings correctly include line numbers in their match data, improving the appearence of CLI output (sc-658)
Increase timeout for semgrep install-semgrep-pro to avoid failures when the download is slow. (timeout)
Fixed the range reported by findings for YAML files that include an anchor, so that the match does not include the original location of the snippet bound to the anchor. (yaml-alias)
Fix an issue that could lead to a crash when printing findings that contain snippets that look like markup to the Rich Python library (rich-markup-cra
Scala: Added proper parsing for Scala 3 style imports (pa-2678)
taint_assume_safe_comparisons, disabled by default, that
prevents comparison operators to propagate taint, so e.g. tainted != "something"
will not be considered tainted. Note that this a syntactic check, if the operator
is overloaded to perform a different operation this will not be detected. (pa-2645)Kotlin: Added support for typed metavariables. You can write a pattern like: ($X : String) to find all instances of expressions with type String. (pa-
using, and soft modifiers like inline and open. (pa-2672)maven_dep_tree.txt files
that are made of multiple smaller maven_dep_tree.txt files concatenated with cat. (maven-dep-forest)foo="true") (gh-7344)On full sca scans with dep search feature on, send dependency data for dep search (depsearch)
On full sca scans with dep search feature on, send dependency data for dep search (depsearch)
metavariable-comparison: Added support for bitwise operators ~, &, | and ^. (gh-7284)
Taint: pattern-propagators now have optional fields requires and label,
which are used identically to their counterparts in pattern-sources and pattern-sinks, for the experimental taint labels feature.
For instance, we can define:
pattern-propagators:
- pattern: |
$TO.foo($FROM)
from: $FROM
to: $TO
requires: A
replace-labels: [A, C]
label: B
to denote a propagator which only propagates from $FROM to $TO if $FROM has taint label A. In addition, it converts any taints from $TO with labels A or C to have label B.
If label is not specified, the to is tainted with the same label of taint
that $FROM has. If requires is not specified, it does not require $FROM to
have a particular label of taint.
Additionally, replace-labels only restricts the label being propagated if
the output label is specified. (pa-1633)
taint-mode: Java: Support for basic field sensitivity via getters and setters.
Given obj.setX(tainted), Semgrep will identify that a subsequent obj.getX()
carries the same taint as tainted. It will also differentiate between
obj.getX() and obj.getY(). Note that Semgrep does not examine the definitions
for the getter or setter methods, and it does not know whether e.g. some other
method obj.clearX() clears the taint that obj.setX(tainted) adds. (pa-2585)
Pro Engine: Semgrep CLI will now download a version of Semgrep Pro Engine compatible with the current version of Semgrep CLI, as opposed to the most recently released version.
This behavior is only supported for Semgrep 1.12.1 and later. Previous versions will still download the most recently released version, as before. (pa-2595)
Pro: semgrep ci will run intrafile interprocedural taint analysis by default
in differential scans (aka PR scans). (Note that interfile analysis is not run
in differential scans for performance reasons.) (pa-2565)
Remove custom entrypoint for returntocorp/semgrep Docker images, now you must explicitly call semgrep.
This won't work now: docker run -v $(pwd):/src returntocorp/semgrep scan ...
Must do this instead: docker run -v $(pwd):/src returntocorp/semgrep semgrep scan ... (pa-2642)
Changed Maven version comparison to more closely reflect usage, so versions with more than 3 increments will not be treated as plain strings (sc-656)
The AST dump produced by semgrep-core is now usable from Python with the provided ATD interface and the Python code derived from it with atdpy. (gh-7296)
Terraform: Nested blocks can now be used as sources and sinks for taint.
For instance, the block x in
resource $A $B { x { ... } } (pa-2475)
CLI: The scan progress bar now shows progress with higher granularity, and has fewer big jumps when using the Pro Engine.
The abstract unit of 'tasks' has been removed, and now only a percentage number will be displayed. (pa-2526)
Fix an error with rule targeting for extract mode. Previously, if a ruleset had two rules, the first being the extract rule, the second being the rule to run, no rules would run on the extracted targets. Additionally, with multiple rules the wrong rule might be run on the extracted target, causing errors. Now, in extract mode all the rules for the destination language will be run. (pa-2591)
Metrics: logged in semgrep ci scans now send metrics, as our Privacy.md indicates
(previously they incorrectly did not, which made it harder for us to track failure events) (pa-2592)
Rust: Basic let-statement bindings (such as let x = tainted) now properly
carry taint. (pa-2605)
Improved error reporting for rule parsing by correctly reporting parse errors instead of engine errors in certain cases. (pa-2610)
Taint: Fixed an issue where an error could be thrown if semgrep-core's output contained a dataflow trace without a sink. (pa-2625)
Julia: Properly allow string literal metavariables like "$A" to be patterns. (pa-2630)
Add new hashes of a match (finding) to send to the app:
taint-mode: Historically, the matching of taint sinks has been somewhat imprecise.
For example, sink(ok if tainted else ok) was flagged. Recently, we made sink-
matching more precise for sinks like sink(...) declaring that any argument of
a given function is a sink. Now we make it more precise when specific arguments of
a function are sinks, like:
pattern-sinks:
- patterns:
- pattern: sink($X, ...)
- focus-metavariable: $X
So sink(ok1 if tainted else ok2), sink(not_a_propagator(tainted)), and
sink(some_array[tainted]), will not be reported as findings. (pa-2477)
The --gitlab-sast and --gitlab-secrets output formats have been upgraded.
The output is now valid with the GitLab v15 schema,
while staying valid with the GitLab v14 schema as well.
Code findings now include the confidence of the rule.
Supply Chain findings now include the exposure type. (sc-635)
if (cond && x = 42) S1; S2 to be interpreted as
x = 42; if (cond && x) S1; S2, thus incorrectly flagging x as a constant
inside S2. (gh-7199)class $X : Foo will also match class Stuff : Bar, Foo). (gh-7248)sink(sanitizer(source) if source else ok) will not be
incorrectly reported as a tainted sink. This follows a previous attempt at fixing
these issues in version 1.1.0. (pa-2509)pattern-not within metavariable-pattern in some cases. (pa-2510)--oss-only previously required --oss-only true to be passed. This PR fixes
it so that --oss-only will invoke the oss engine. Note that --oss-only true
will no longer be supported (pa-2587)Detect BITBUCKET_TOKEN from environment to authenticate with the Bitbucket API. (app-3691)
BITBUCKET_TOKEN from environment to authenticate with the Bitbucket API. (app-3691)by-side-effect, just like sources and
sanitizers. However, the default value of by-side-effect for propagators is true
(unlike for sources or sanitizers). When using rule option
taint_assume_safe_functions: true, this allows to specify functions that must
propagate taint, for example: pattern-propagators:
- by-side-effect: false
patterns:
- pattern-inside: $F(..., $X, ...)
- focus-metavariable: $F
- pattern-either:
- pattern: unsafe_function
from: $X
to: $F
Without by-side-effect: true, unsafe_function itself would be tainted by side-
effect, and subsequent invokations of this function, even if the arguments were safe,
would be tainted. (pa-2400)final class attributes.
See https://semgrep.dev/s/DG6v. (pa-2551)Fix local scan hyperlinks by asking git for remote.origin.url if repo_url not provided (gh-7144)
--verbose when the contents of a metavariable fails to parse. (pa-2537)(optional) would fail to parse (sc-622)"resolved": false as a result of a bug in NPM will now parse (sc-npm-bug)CLI: No longer reports rules as being run with a lack of interfile: true when interfile analysis was not requested. (pa-2528)
interfile: true when interfile
analysis was not requested. (pa-2528)Pro: Removed already deprecated flags --deep (now --pro), --interfile (now --pro), and --interproc (now --pro-intrafile). Also removed already depreca…
--deep (now --pro), --interfile (now --pro),
and --interproc (now --pro-intrafile). Also removed already deprecated command
install-deep-semgrep (now install-semgrep-pro). (pa-2518)--deep (now --pro), --interfile (now --pro),
and --interproc (now --pro-intrafile). Also removed already deprecated command
install-deep-semgrep (now install-semgrep-pro). (pa-2518)metavariable-pattern clauses, which could lead to matches being incorrectly
displayed. (extracted-metavar-loc)semgrep --validate for metavariables like $1, $2.
Previously, it blocked rules that it shouldn't. (validate-regex-mvar)This means a log4j rule must now use org.apache.logging.log4j:log4j-core instead of just log4j-core. This change is backwards incompatible, in that an…
metavariable-pattern now persist to outside of the metavariable-pattern (pa-2490)--pro will now enable all Pro features, including Apex, inter-procedural taint
analysis, and also inter-file analysis for supported languages. For Apex support only
(and more languages in the future) now use --pro-languages. For intra-file analysis
only now use --pro-intrafile. Flags --interproc and --interfile are now
deprecated. (pa-2488)org.apache.logging.log4j:log4j-core instead of just log4j-core. This change is backwards incompatible, in that any Java Supply Chain rules not taking into account will stop producing any findings, since the packages parsed from lockfiles will include the org, but the old rules will not. (sc-maven-org)--dataflow-traces in the CLI, to reduce
confusion over where the findings fall between the dataflow traces. (pa-2471)install-semgrep-pro to the list of commands in the semgrep --help help text. (pa-2505)metavariable-pattern now persist to outside of the metavariable-pattern (pa-2490)language: generic to run (and
potentially match) on any metavariable binding kind, not just strings. For
example, with the pattern foo($...ARGS), it is now possible to use a
metavariable-pattern on $...ARGS with language: generic, and match using
generic mode against whatever text $...ARGS is bound to.
(metavar-pattern-generic)$...X${1 + 2}
(template-metavar-ellipsis)--pro will now enable all Pro features, including Apex, inter-procedural taint
analysis, and also inter-file analysis for supported languages. For Apex support only
(and more languages in the future) now use --pro-languages. For intra-file analysis
only now use --pro-intrafile. Flags --interproc and --interfile are now
deprecated. (pa-2488)org.apache.logging.log4j:log4j-core instead of just log4j-core. This change is backwards incompatible, in that any Java Supply Chain rules not taking into account will stop producing any findings, since the packages parsed from lockfiles will include the org, but the old rules will not. (sc-maven-org)--dataflow-traces in the CLI, to reduce
confusion over where the findings fall between the dataflow traces. (pa-2471)install-semgrep-pro to the list of commands in the semgrep --help help text. (pa-2505)Pro: If the "Semgrep Pro Engine" toggle is enabled in App, semgrep ci will add support for Apex in all scans (including diff scans). (pa-2462)
semgrep ci will add
support for Apex in all scans (including diff scans). (pa-2462)Experimental support for Clojure, Lisp, and Scheme. (gh-3328)
"=~/hello/" now support the
full PCRE syntax, including backreferences and other advanced features
not supported by ocaml-re. (gh-6913)Experimental support for Clojure, Lisp, and Scheme. (gh-3328)
"=~/hello/" now support the
full PCRE syntax, including backreferences and other advanced features
not supported by ocaml-re. (gh-6913)…are multiple copies of this library at different vulnerable versions. (sc-549)
--test to process entire file trees rather than single files (gh-5487)metavariable-pattern operator on text that may look like (or in fact be)
machine generated, such as an RSA key contained in a legit file. Now, when the
analysis is requested within a metavariable-pattern operator, Generic mode
will always match any text even if it looks like machine generated. (pa-2386)--pro and --interproc. Using --pro you can
enable Apex support, and with --fast-deep you can enable intra-file inter-procedural
taint analysis. Also, --deep has been renamed to --interfile. Note that to use
any of the Pro features you must first run semgrep install-semgrep-pro while being
logged in. (pa-2440)* and **, thus both
sink(*tainted) and sink(**tainted) will result in findings. (gh-6920)semgrep-core-proprietary executable. (pa-2417)Python: Constant propagation will now recognize the idiom cond and X or Y, as well as True and X and False or X. So e.g. cond and "a" or "b" will be i
cond and X or Y,
as well as True and X and False or X. So e.g. cond and "a" or "b" will
be identified as a constant string. (gh-6079)semgrep install-semgrep-pro. This engine is still invoked using the
--deep flag, but please expect changes to the CLI in the near future.
The new Semgrep PRO engine adds support for Apex! (pa-2389)$F(x) match eval(x). Previously, eval was special-cased and metavariable function call patterns would not match it. (gh-6877)--dataflow-traces by default when --deep is specified (pa-2274)Removed the poor support for reading dependencies from pom.xml files. Instead semgrep will try to read dependencies from a maven_dep_tree.txt file, wh
mvn dependency:tree -DoutputFile=maven_dep_tree.txt (sc-pom)Use the GitHub REST API when possible to compute the merge base for semgrep ci, improving performance on shallow clones of large repositories. (gha-mergebase)
YAML: Fixed a bug where metavariables matching YAML double-quoted strings would not capture the entire range of the string, and would
not contain the double-quotes. Also added the ability to properly use patterns like "$FOO", which will unpack the contents of the matched string. (pa-2332)
Fixed a race condition related to the parsing cache that could lead to internal errors (pa-2335)
YAML: Fixed a bug where literal or folded blocks would not be parsed properly.
So for instance, in:
key: |
string goes here
A metavariable matching the contents of the string value might not be correct. (pa-2347)
Julia: Greatly improved parsing support (pa-2362)
Go: fix NoTokenLocation for metavariables matching function type without an argument (e.g. func()) (gh-6715)
func()) (gh-6715)foo(cond ? new A() : this.a) (pa-2328)Fixed rare crash that could occur due to stale file caches when temp file names overlap (cache-invalidation)
foo("$VAR")) (gh-6311)super(...) patterns (gh-6638)new $X.Foo() will now match
new a.b.Foo(). (pa-2296)require calls (require-match)JSON output: Added a max_memory_bytes field to the semgrep --time output which corresponds to the amount of memory allocated during the OCaml phase of
max_memory_bytes field to the semgrep --time output which corresponds to the amount of memory allocated during the OCaml phase of Semgrep. This is useful for telemetry purposes. (pa-2075)taint-mode: In 0.94.0 we made that when a pattern-source (or pattern-sanitizer)
matched a variable exactly, this was understood as that variable being tainted
(sanitized, resp.) by side-effect. For example, given tainted(x) we would taint x
by side-effect, and subsequent occurrences of x were also considered tainted.
This allowed to write rules like c.lang.security.use-after-free.use-after-free
in a very succint way, and it also addressed some limitations of the workarounds that
were being used to simulate this until then.
This worked well initially, or so we thought, until in 0.113.0 we added
field-sensitivity to taint-mode, and in subsequent versions we made sources and
sanitizers apply by side-effect to more kinds of l-values than just simple variables.
It was then that we started to see regressions that were fairly unintuitive for users.
For example, if $_GET['foo'] was a taint source, this would make $_GET itself to
be tainted by side-effect, and a subsequent expression like $_GET['bar'] was also
considered tainted.
We now correct the situation by adding the by-side-effect option to sources and
sanitizers, and requiring this option to be explicitly enabled
(that is, by-side-effect: true) in order to apply the source or the sanitizer by
side-effect. Otherwise, the default is that sources and sanitizers matching l-values
apply only to the precise occurrences that they match. (pa-1629)
taint-mode: Fixed matching of pattern-sinks to be more precise, so that e.g.
it will no longer report sink(ok1 if tainted else ok2) as a tainted sink, as
the expression passed to the sink is actually not tainted. (pa-2142)
CLI: Separated experimental rules from normal rules in semgrep --debug output. (pa-2159)
Taint: Fixed an issue where findings with the same sink would be identified as the same, and cause only one of them to be reported, even if they had different sources. (pa-2208)
DeepSemgrep: When the "DeepSemgrep" setting is enabled in Semgrep App, semgrep ci
will try to run the analysis using the DeepSemgrep engine. But if this engine was
not installed, semgrep ci failed. Now semgrep ci will automatically try to
install DeepSemgrep if it is not already present. Note that, if DeepSemgrep is
already installed, semgrep ci does not attempt to upgrade it to a newer version. (pa-2226)
CLI: Made the number of jobs when using semgrep --deep default to 1. (pa-2231)
Autofix: If multiple autofixes are targeting an overlapping range, then one of them is picked arbitrarily to occur, to prevent autofixes which may produce incorrect code. (pa-2276)
DeepSemgrep: Time data now outputs properly when running semgrep --deep --time (pa-2280)
DeepSemgrep: Added a message which suggests that users update their version of DeepSemgrep, if the DeepSemgrep binary crashes (pa-2283)
Yarn 2 parse failure on versions like @storybook/react-docgen-typescript-plugin@canary. This is only present as some kind special version range specifier and never appears as a concrete version. It would only be used to check if the dependency was in the manifest file, so we just parse the version as "canary" Yarn 2 parse failure on versions like @types/ol-ext@npm:@siedlerchr/types-ol-ext@3.0.6 Yarn 2 parse failure on versions like resolve@patch:resolve@^1.1.7#~builtin<compat/resolve>. These are now just ignored, as they appear to always come with a non-patch version as well. (sc-406)
DeepSemgrep: If you have a Team tier account in Semgrep App, and you enable the _DeepSemgrep_ setting, then semgrep ci will automatically run the Deep
semgrep ci will automatically run the DeepSemgrep
engine instead of the OSS engine on full scans (but not in PR scans). (pa-2226)CLI: Added deep traces to --dataflow-traces (pa-2116)
--dataflow-traces (pa-2116)semgrep ci.
Note that unreachable findings have been non-blocking already. (sca-nonblocking)x.a.b[i].c got tainted, Semgrep would track x.a.b as tainted, and thus
x.a.b[i].d would be incorrectly considered as tainted too. Now Semgrep will
do the right thing and track x.a.b[*].c as tainted, and x.a.b[i].d will
not be considered tainted. (pa-2225)private, singly-assigned class variables now permit constant propagation (pa-2230)$X(...) match this() and super(). (this-match)DeepSemgrep: Added installation path for DeepSemgrep on M1 machines (pa-2153)
Fix yaml excessive mapping captures (gh-5698)
pattern-not, pattern-inside, and pattern-not-inside to take in arbitrary patterns (such as patterns, pattern-either, and friends) (pa-1723)## 0.121.1 - 2022-11-08 No significant changes.
No significant changes.
taint-mode: Semgrep can now track taint through l-values of the form this.x. It will also be more precise when tracking taint on l-values involving an
this.x.
It will also be more precise when tracking taint on l-values involving an
array access, previously if x.a[i] was tainted, then x itself was tainted;
now only x.a will be considered tainted. (pa-2086)metavariable-comparison and friends (pa-2088)Fail gracefully and print error message when running in unsupported Linux aarch64/arm64 environment (arm-fail)
focus-metavariable. (focus-metavariable-autofix)$x-> ... ->bar()). (gh-6183)RUN --mount=type=$TYPE,target=$TARGET .... (gh-6353)x.a.b was specified as a source/sanitizer/sink. For example, if x had been
previously tainted, then we encountered sink(x.a.b) where x.a matched a
sanitizer, there was a finding reported because x.a.b was incorrectly considered
tainted. (pa-1928)Taint mode will now track taint coming from the default values of function parameters. For example, given def test(url = "http://example.com"):, if "h
Taint mode will now track taint coming from the default values of function
parameters. For example, given def test(url = "http://example.com"):,
if "http://example.com" is a taint source (due to not using TLS), then
url will be marked as tainted during the analysis of test. (gh-6298)
taint-mode: Added two new rule options that help minimizing false positives.
First one is taint_assume_safe_indexes, which makes Semgrep assume that an
array-access expression is safe even if the index expression is tainted. Otherwise
Semgrep assumes that e.g. a[i] is tainted if i is tainted, even if a is not.
Enabling this option is recommended for high-signal rules, whereas disabling it
may be preferred for audit rules. Currently, it is disabled by default for pure
backwards compatibility reasons, but this may change in the near future after some
evaluation.
The other one is taint_assume_safe_functions, which makes Semgrep assume that
function calls do NOT propagate taint from their arguments to their output.
Otherwise, Semgrep always assumes that functions may propagate taint. This is
intended to replace not conflicting sanitizers (added in v0.69.0) in the future.
This option is still experimental and needs to be complemented by other changes
to be made in future releases. (pa-1541)
--scan-unknown-extensions option is now set to false by default.
This means that from now on --skip-unknown-extensions is the default.
This is an important change that prevents many errors when using
Semgrep in a pre-commit context or in CI. (pa-1932)foo("xyz $X"). (autofix-string-metavar)taint-mode: It is now possible to use pattern-propagators to propagate taint through higher-order iterators such as forEach in Java. For example: ```y
pattern-propagators to propagate taint
through higher-order iterators such as forEach in Java. For example: pattern-propagators:
- pattern: $X.forEach(($Y) -> ...)
from: $X
to: $Y
``` (gh-5971)
pattern-propagators to propagate taint
through higher-order iterators such as forEach in Java. For example: pattern-propagators:
- pattern: $X.forEach(($Y) -> ...)
from: $X
to: $Y
``` (gh-5971)
rules: key. This change does not
affect Semgrep CLI which never accepted that relaxed format. (pa-1931)--sca to --supply-chain.
Correspondinly changed --config sca to --config supply-chain (sca-ssc)new operator, that had been broken since
version 0.98.0. You can again e.g. use the pattern new A().foo() to match
a.foo(), with a = new A(). (gh-6161)this or this.x to be a source of taint. (pa-1929)if condition or a throw (aka raise) expression/statement. (pa-1933)$X match { ... }) (gh-6131)focus-metavariable, which allows Semgrep to highlight the
values matched by multiple metavariables more easily in certain circumstances.
See the gist in the description of the original issue for an example. (gh-5686)metavariable-regex. (gh-5987)$...ARGS) in arguments (gh-6065)NamedTemporaryFile objects while their corresponding
temporary files are still in use by the core runner. Failure to explicitly hold
references to these objects on some Python implementations, such as PyPy,
results in them sometimes being garbage-collected during processing. This,
in turn, triggers removal of the temp files while they are still in use by
the core runner or the worker subprocesses, resulting in various crashes and
processing failures. (gh-6100)x.a and x.b separately, so that e.g. x.a can be
tainted at the same time as x.b is clean, hence sink(x.a) would produce
a finding but sink(x.b) would not. It is also possible for x to be tainted
while x.a is clean. We expect this to have an net positive effect by reducing
false positives. (pa-1278)import world.Hello, and create a
new Hello.internal_class(), you can match that with
new world.Hello.internal_class(). (gh-6001)semgrep --test now fails when encountering a parsing error in target code. (gh-6068)not in operator. (gh-6072)TypeError: unbound method set.intersection() needs an argument crash
that occurred when all of a scan's rules were multilang (regex or generic). (gh-6093)pattern-inside. (gh-6059)case 5: ...) (pa-1788)/.../ can now match any regexp, including regexp templates such as /hello #{name}/. (gh-5147)public Foo() { } (gh-5558)match statements (pa-1739)Previously, the following error message appears when metrics are not uploaded within the set timeout timeframe:
Error in send: HTTPSConnectionPool(host='metrics.semgrep.dev', port=443): Read timed out. (read timeout=3)
As this causes users confusion when running the CLI, the log level of the message is reduced to appear for development and debugging purposes only. Note that metrics are still successfully uploaded, but the success status is not sent in time for the curent timeout set. (app-1398)
"some string".concat(x). Previously, when x was tainted, the concat
expression was not recognized as tainted and this caused false negatives. (pa-1787)When a YAML rule file had a string that contained an ISO timestamp, that would be parsed as a datetime object, which would then be rejected by Semgrep's rule schema validator. This is now fixed by keeping strings that contain an ISO timestamp as strings. (app-2157)
When parsing PHP with tree-sitter, parse $this similar to pfff, as an IdSpecial. This makes it possible to match $this when the pattern is parsed with pfff and the program with tree-sitter. (gh-5594)
Parse die() as exit() in tree-sitter PHP. This makes pfff and tree-sitter parse die() in the same way. (gh-5880)
All: Applied a fix so that qualified identifiers can unify with metavariables. Notably, this affected Python decorators, among others. (pa-1700)
Fixed a regression in DeepSemgrep after the experimental taint labels feature was introduced in 0.106.0. This prevented DeepSemgrep from reporting taint findings when e.g. the sink was wrapped by another function. (pa-1750)
Fixed metavariable unification in JSON when one of the patterns is a single field. (pa-1763)
Changed symbolic propagation such that "redundant" matches are no longer reported as findings. For instance:
def foo():
x = g(5)
f(x)
If we are looking for the pattern g(5), we should not match on line 3,
since we will match on line 2 anyways, and this is just repeating information that
we already know.
This patch changes it so that we do not match on line 3 anymore. (pa-1772)
Semgrep now passes -j to DeepSemgrep engine so --deep became noticeably faster. (pa-1776)
taint-mode: Due to a mistake in the instantiation of a visitor, named function definitions were being analyzed twice! This is now fixed and you may observe significant speed ups in some cases. (pa-1778)
Extract mode: fixed a possible exception in normal usage introduced due to changes in handling of search/taint rules. (pa-1786)
Changed the fail-open message body (pm-194)
macos-12 is unreliable and has begun failing without
a clear explanation as to why: this downgrades to macos-11,
since 10.15 is to be depracted ~10 from now. (devop-609)semgrep ci now defaults to fail open and will always exit with exit code 0, which is equivalent to passing --suppress-errors.
To disable this behavior, you can pass --no-suppress-errors and semgrep will behave as it did previously, surfacing any exit codes that may result. (app-1951)--dataflow-traces) should no longer report "strange"
intermediate variables when there are record accesses involved. This happened e.g.
if foo was a tainted record and the code accessed some of its fields as in
foo.bar.baz. This was related to the use of auxiliary variables in the Dataflow IL.
These variables got tainted, but they had real tokens attached corresponding to the
dot . operator. Now we do not include these variables in the taint trace. (pa-1672)macos-10.15 is deprecated and will be unsupported by 30AUG2022. We've tested and can upgrade to macos-12 to avoid issues with brownouts or end of support. (devop-586)Fixed issue when scan fails due to pending changes in submodule. (cli-272)
Semgrep CI now accepts more formats of git url for metadata provided to semgrep.dev and lets the user provide a fallback for repo name (SEMGREP_REPO_NAME) and repo url (SEMGREP_REPO_URL) if they are undefined by CI. (cli-280)
Fixed a crash that occurred when reporting results when join mode and taint mode were used together (gh-5839)
JS: Allowed decorators to appear in Semgrep patterns for class methods and fields. (pa-1677)
Quick fix for a regression introduced in 0.107.0 (presumably by taint labels) that could cause some taint rules to crash Semgrep with:
Invalid_argument "output_value: abstract value (Custom)" (pa-1724)
Increase timeout for network calls to semgrep.dev from 30s to 60s (timeout-1)
obj. ... .bar()) (gh-5819)semgrep-core so that it can now be run with -rules on .yaml files which do not have a top-level rules: ... key. This means you can now copy paste from the playground editor directly into a .yaml file for use with semgrep-core. (implicit-rules-sc-core)--dataflow-traces flag, which directs the Semgrep CLI to explain how non-local values lead to a finding. Currently, this only applies to taint mode findings and it will trace the path from the taint source to the taint sink. (pa-1599)import patterns (gh-5219)-filter_irrelevant_rules was incorrectly skipping files when the PCRE engine threw
an error, while trying to match a regex that determines whether a rule is relevant
for a file. This has been fixed so that, in case of a PCRE error, we assume that the
rule could be relevant and we do run it on the file. (pa-1635)metavariable-comparison: The metavariable field is now optional, except
if strip: true. When strip: false (the default) the metavaraible field
has no use so it was pointless to require it. (metavariable-comparison-metavariable)
metavariable-comparison now also works on metavariables that cannot be evaluated
to simple literals. In such cases, we take the string representation of the code
bound by the metavariable. The way to access this string representation is via
str($MVAR). For example:
- metavariable-comparison:
metavariable: $X
comparison: str($X) == str($Y)
Here $X and $Y may bind to two different code variables, and we check whether
these two code variables have the same name (e.g. two different variables but both
named x). (pa-1659)
When running an SCA scan with semgrep ci --sca,
SCA findings will no longer be considered blocking if they are unreachable. (sca-128)
Fixed a regression in name resolution that occurred with metavariable patterns (gh-5690)
Rust: Fixed a bug with matching for scoped identifiers
Basically, scoped identifiers were only looking at the last identifier. So something like A::B::C would result in something like C. (gh-5717)
languages value (pa-1648)C#: Improved error message when function parameters are declared with var (gh-5068)
Scala/others: Added a fix allowing percolation of name information from class parameters
For example, classes which take in arguments like the following in Scala:
class ExampleClass(val x: TypeName) {
}
do not properly enter the context. So in our analysis, we would not know that the identifier
x has type TypeName, within the body of ExampleClass. (gh-5506)
Fixed the logged message describing the endpoint where rules are fetched from when SEMGREP_URL is set (gh-5753)
Fixed what data was used for indexing match results to used match based id data (index)
semgrep ci will now not block builds on triage ignored issues (cli-162)Metavariable-pattern now uses the same metavariable context as its parent. This will potentially cause breaking changes for rules that reuse metavariables in the pattern. For example, consider the following formula:
- patterns:
- pattern-either:
- pattern-inside: $OBJ.output($RESP)
- pattern: $RESP
- metavariable-pattern:
metavariable: $RESP
pattern: `...{ $OBJ }...`
Previously, the $OBJ in the metavariable-pattern would be a new metavariable. The formula would
behave the same if that $OBJ was $A instead. Now, $OBJ will try to unify with the value bound
by $OBJ in the pattern-inside. (gh-5060)
The semgrep test output used to produce expected lines and reported lines which is difficult to read and interpret. This change introduces missed lines and incorrect lines to make it easier for the users to pinpoint the differences in output. (gh-5600)
Separator lines are no longer drawn between findings that have no source code snippet. (sca-ui)
Using ellipses in XML/HTML elements is now more permissive of whitespace.
Previously, in order to have a element with an ellipsis no leading/trailing
whitespace was permitted in the element contents, i.e., <tag>...</tag> was
the only permitted form. Now, leading or trailing whitespace is ignored when
the substantive content of the element is only an ellipsis. (xml-permissive-ellipsis)
os.stat instead of os.access to determine if a file is executable. (gh-5560)--debug isn't passed
since it isn't read unless --debug is used (pa-1618)semgrep ci e2e. (cli-253)towncrier to avoid merge conflicts in changelog on release (cli-77)foo();) used to also match when
they were a bit deeper in the expression (e.g., x = foo();).
This can now be disabled via rule options:
with implicit_deep_exprstmt: false (#5472)SEMGREP_GIT_COMMAND_TIMEOUT environment variable.
The unit used is seconds. The default value is 300.for (...; $X <- $Y if $COND; ...) { ... } to match nested for loops. (#5650)SEMGREP_GHA_MIN_FETCH_DEPTH environment variable which lets you set how many
commits semgrep ci fetches from the remote at the minimum when calculating the merge-base in GitHub Actions.
Having more commits available helps Semgrep determine what changes came from the current pull request,
fixing issues where Semgrep would report findings that weren't touched in a given pull request.
This value is set to 0 by default (#5664)--verbose no longer toggles the display of timing information, use
--verbose --time to display this information.semgrep ci: CI runs in GitHub Actions failed to checkout the commit assoociated with the head branch, and is fixed here.semgrep ci: CI runs were failing to checkout the PR head in GitHub Actions, which is
corrected here.pattern-propagators now works correclty when the
from or to metavariables match a function call. For example, given
sqlBuilder.append(page.getOrderBy()), we can now propagate taint from
page.getOrderBy() to sqlBuilder.pattern-propagators feature that allows to specify
arbitrary patterns for the propagation of taint by side-effect. In particular,
this allows to specify how taint propagates through side-effectful function calls.
For example, you can specify that when tainted data is added to an array then the
array itself becomes tainted. (#4509)--config auto no longer sends the name of the repository being scanned to the Semgrep Registry.
As of June 21st, this data is not recorded by the Semgrep Registry backend, even if an old Semgrep version sends it.
Also as of June 21st, none of the previously collected repository names are retained by the Semgrep team;
any historical data has been wiped.semgrep scan options:
--json-stats, --json-time, --debugging-json, --save-test-output-tar, --synthesize-patterns,
--generate-config/-g, --dangerously-allow-arbitrary-code-execution-from-rules,
and --apply (which was an easter egg for job applications, not the same as --autofix)with context expressions where the value is not
bound (#5513)Version 0.99.0 of Semgrep was intentionally skipped. Version 0.100.0 immediately follows version 0.98.0.
SEMGREP_ENABLE_VERSION_CHECK=0{...foo}) are now translated into the Dataflow ILsemgrep lsp --config auto!semgrep --config auto run on the semgrep Python package in 14s instead of 16s.--disable-version-check would still send a request
when a scan resulted in zero findings./src without notice.
This also could cause permission issues when running the image.$X() no longer matches new Foo(), for consistency with other languages (#5510)($X: C) matches new C(). (#5540)package $X, which is useful to bind the package
name and use it in the error message.semgrep ci should be clear it is exiting with error code 0
when there are findings but none of them being blockersyarn.lock files with no depenencies, and with dependencies that lack URLs, now parsegeneric_ellipsis_max_span for controlling
how many lines an ellipsis can match (#5211)generic_comment_style for ignoring
comments that follow the specified syntax (C style, C++ style, or
Shell style) (#3428):include instruction in
a .semgrepignore file.
These strings will NOT include user data or specific settings. As an example,
with semgrep scan --output=secret.txt we might send "option/output" but
will NOT send "option/output=secret.txt".fixes section--test flag will now seach for code files with .fixed suffix and use
these to test the behaviour of autofixes of the rules.r2c-internal-project-depends-on: support for poetry and gradle lockfilesSEMGREP_BASELINE_REF as alias for SEMGREP_BASELINE_COMMITr2c-internal-project-depends-on:
--scaThe ci CLI command will now include ignored matches in output formats
that dictate they should always be included
Previously, you could use $X in a message to interpolate the variable captured
by a metavariable named $X, but there was no way to access the underlying value.
However, sometimes that value is more important than the captured variable.
Now you can use the syntax value($X) to interpolate the underlying
propagated value if it exists (if not, it will just use the variable name).
Example:
Take a target file that looks like
x = 42
log(x)
Now take a rule to find that log command:
- id: example_log
message: Logged $SECRET: value($SECRET)
pattern: log(42)
languages: [python]
Before, this would have given you the message Logged x: value(x). Now, it
will give the message Logged x: 42.
A parameter pattern without a default value can now match a parameter with a default value (#5021)
return for taint analysis (#4975)metavariable-regex now supports an optional constant-propagation key.
When this is set to true, information learned from constant propagation
will be used when matching the metavariable against the regex. By default
it is set to falseENVshouldafound - False Negative reporting via the CLItaint(x) makes x tainted by side-effect.
Previously, we had to rely on a trick that declared that any occurrence of
x inside taint(x); ... was as taint source. If x was overwritten with
safe data, this was not recognized by the taint engine. Also, if taint(x)
occurred inside e.g. an if block, any occurrence of x outside that block
was not considered tainted. Now, if you specify that the code variable itself
is a taint source (using focus-metavariable), the taint engine will handle
this as expected, and it will not suffer from the aforementioned limitations.
We believe that this change should not break existing taint rules, but please
report any regressions that you may find.sanitize(x) sanitizes x by side-effect.
Previously, we had to rely on a trick that declared that any occurrence of
x inside sanitize(x); ... was sanitized. If x later overwritten with
tainted data, the taint engine would still regard x as safe. Now, if you
specify that the code variable itself is sanitized (using focus-metavariable),
the taint engine will handle this as expected and it will not suffer from such
limitation. We believe that this change should not break existing taint rules,
but please report any regressions that you may find.^ and $
now match at the beginning and end of each line, respectively,
rather than previously just at the beginning and end of the input
file. This corresponds to PCRE's multiline mode. To get the old
behavior back, use \A instead of '^' and \Z instead of $. See
the PCRE
manual
for details.semgrep scan --config auto on the semgrep repo itself
went from 50-54 seconds to 28-30 seconds.
:include .gitignore and .git/
from the default .semgrepignore patterns.
This should not cause any difference in which files are targeted
as other parts of Semgrep ignore these files already.override keyword (#4220, #4798)(null)(foo) (#4468)func foo() (..., error, ...) {}) (#4896)with context expressions
(e.g., with (open(x) as a, open(y) as b): pass) (#5092)semgrep ci used to incorrectly report the base branch as a CI job's branch
when running on a pull_request_target event in GitHub Actions.
By fixing this, Semgrep App can now track issue status history with on: pull_request_target jobs.PRIVACY.md had already documented a timestamp field.class Foo(...) {} (#5180)import {..., Foo, ...} from 'Bar') (#5012)fixed_lines is once again included in JSON output when running with --autofix --dryrunsemgrep scan is now fully specified using
ATD (https://atd.readthedocs.io/) and jsonschema (https://json-schema.org/).
See the semgrep-interfaces submodule under interfaces/
(e.g., interfaces/semgrep-interfaces/Semgrep_output_v0.atd for the ATD spec)semgrep scan now contains a "version": field with the
version of Semgrep used to generate the match results.focus-metavariable can be used to
precisely specify that a function parameter is a source of taint, and the taint
engine will handle this as expected.let {x} = E, Semgrep will now infer that x
is tainted if E is tainted.--core-opts flag to send options to semgrep-core. For internal use:
no guarantees made for semgrep-core options (#5111)semgrep ci prints out all findings instead of hiding nonblocking findings (#5116)rules: key underneath the join: key.{} appearing when it expects a scalar,
allowing extensions of YAML that use {} to be parsed (#4849)echo $...ARGS (#4887)({ params }: Request) => { } with ({$VAR} : $REQ) => {...}. (#5004)-> (P) {Q} where P and Q are sub-patterns. (#4950)semgrep install-deep-semgrep command for DeepSemgrep beta (#4993)lang.json file not found error while building the docker imageEXPOSE 12345 will now parse 12345 as an int instead of a string,
allowing metavariable-comparison with integers (#4875)def f[@an A, @an B](x : A, y : B) = ...)r2c-internal-project-depends-on:
package-lock.json parsing now defaults to dependencies instead of packages,
and will not completely fail on dependencies with no versionyarn.lock parsing has been rewritten to fix a bug where sometimes
large numbers of dependencies would be ignoredfocus-metavariable operator that lets you focus (or "zoom in") the match
on the code region delimited by a metavariable. This operator is useful for
narrowing down the code matched by a rule, to focus on what really matters. (#4453)semgrep ci uses "GITHUB_SERVER_URL" to generate urls if it is availableNO_COLOR=1 to force-disable colored outputpattern-sinks, plus the subset of metavariables bound by pattern-sources
that do not collide with the ones bound by pattern-sinks. We do not expect
this change to break many taint rules because source-sink metavariable
unification had a bug (see #4464) that prevented metavariables bound by a
pattern-inside to be unified, thus limiting the usefulness of the feature.
Nonetheless, it is still possible to force metavariable unification by setting
taint_unify_mvars: true in the rule's options.r2c-internal-project-depends-on: this is now a rule key, and not part of the pattern language.
The depends-on-either key can be used analgously to pattern-eitherr2c-internal-project-depends-on: each rule with this key will now distinguish between
reachable and unreachable findings. A reachable finding is one with both a dependency match
and a pattern match: a vulnerable dependency was found and the vulnerable part of the dependency
(according to the patterns in the rule) is used somewhere in code. An unreachable finding
is one with only a dependency match. Reachable findings are reported as coming from the
code that was pattern matched. Unreachable findings are reported as coming from the lockfile
that was dependency matched. Both kinds of findings specify their kind, along with all matched
dependencies, in the extra field of semgrep's JSON output, using the dependency_match_only
and dependency_matches fields, respectively.r2c-internal-project-depends-on: a finding will only be considered reachable if the file
containing the pattern match actually depends on the dependencies in the lockfile containing the
dependency match. A file depends on a lockfile if it is the nearest lockfile going up the
directory tree.semgrep as the entrypoint.
This means that semgrep is no longer prepended automatically to any command you run in the image.
This makes it possible to use the image in CI executors that run provisioning commands within the image.- is now parsed as a valid identifier in Scalanew $OBJECT(...) will now work properly as a taint sink (#4858)...{$X}... will no longer match strpattern-inside are now available to the
rule message. (#4464)SEMGREP_URL or SEMGREP_APP_URL
now updates the URL used both for Semgrep App communication,
and for fetching Semgrep Registry rules.# nosemgrep is supposed to be the same
as if the ignore comment wasn't there.
This has previously only worked for single-line findings, including in semgrep-agent.
Now the fingerprint is consistent as expected for multiline findings as well.--timeout-threshold default set to 3 instead of 0--gitlab-sast and --gitlab-secrets.<script>$...JS</script>)semgrep ci subcommand that auto-detects settings from your CI environment
and can upload findings to Semgrep App when logged in.tests from published python wheel'xxxxxxxxxxxxxx' are no longer reported has having high entropy (#4833)++ and -- as side-effectful
(#4667)<$TAG>...</$TAG>) (#4078)CMD ... to match both CMD ls and CMD ["ls"]
(#4770).Added support for named arguments in taint tracking. This is only relevant for DeepSemgrep users. (pa-1886)
rules: key. This change does not
affect Semgrep CLI which never accepted that relaxed format. (pa-1931)--sca to --supply-chain.
Correspondinly changed --config sca to --config supply-chain (sca-ssc)new operator, that had been broken since
version 0.98.0. You can again e.g. use the pattern new A().foo() to match
a.foo(), with a = new A(). (gh-6161)this or this.x to be a source of taint. (pa-1929)if condition or a throw (aka raise) expression/statement. (pa-1933)Adds support for a .semgrepconfig file. Users can add metadata (such as a list of tags) to the .semgrepconfig YAML file which will automatically be as
$X match { ... }) (gh-6131)Add functionality to exclude rules by id passing it by cli flag --exclude-rule (cli-2530)
focus-metavariable, which allows Semgrep to highlight the
values matched by multiple metavariables more easily in certain circumstances.
See the gist in the description of the original issue for an example. (gh-5686)metavariable-regex. (gh-5987)$...ARGS) in arguments (gh-6065)NamedTemporaryFile objects while their corresponding
temporary files are still in use by the core runner. Failure to explicitly hold
references to these objects on some Python implementations, such as PyPy,
results in them sometimes being garbage-collected during processing. This,
in turn, triggers removal of the temp files while they are still in use by
the core runner or the worker subprocesses, resulting in various crashes and
processing failures. (gh-6100)Adds backwards-compatibility with older versions of semgrep-app. Only relevant for customers with on-prem versions of the app. (gh-6098)
x.a and x.b separately, so that e.g. x.a can be
tainted at the same time as x.b is clean, hence sink(x.a) would produce
a finding but sink(x.b) would not. It is also possible for x to be tainted
while x.a is clean. We expect this to have an net positive effect by reducing
false positives. (pa-1278)import world.Hello, and create a
new Hello.internal_class(), you can match that with
new world.Hello.internal_class(). (gh-6001)semgrep --test now fails when encountering a parsing error in target code. (gh-6068)not in operator. (gh-6072)TypeError: unbound method set.intersection() needs an argument crash
that occurred when all of a scan's rules were multilang (regex or generic). (gh-6093)Fixed a regression introduced with the previous release, involving a bug with pattern-inside. (gh-6059)
pattern-inside. (gh-6059)JS/TS: Allow standalone switch cases as patterns (e.g. case 5: ...) (pa-1788)
case 5: ...) (pa-1788)/.../ can now match any regexp, including regexp templates such as /hello #{name}/. (gh-5147)public Foo() { } (gh-5558)match statements (pa-1739)Previously, the following error message appears when metrics are not uploaded within the set timeout timeframe:
Previously, the following error message appears when metrics are not uploaded within the set timeout timeframe:
Error in send: HTTPSConnectionPool(host='metrics.semgrep.dev', port=443): Read timed out. (read timeout=3)
As this causes users confusion when running the CLI, the log level of the message is reduced to appear for development and debugging purposes only. Note that metrics are still successfully uploaded, but the success status is not sent in time for the curent timeout set. (app-1398)
"some string".concat(x). Previously, when x was tainted, the concat
expression was not recognized as tainted and this caused false negatives. (pa-1787)Introduced experimental support for Swift (gh-2232)
When a YAML rule file had a string that contained an ISO timestamp, that would be parsed as a datetime object, which would then be rejected by Semgrep's rule schema validator. This is now fixed by keeping strings that contain an ISO timestamp as strings. (app-2157)
When parsing PHP with tree-sitter, parse $this similar to pfff, as an IdSpecial. This makes it possible to match $this when the pattern is parsed with pfff and the program with tree-sitter. (gh-5594)
Parse die() as exit() in tree-sitter PHP. This makes pfff and tree-sitter parse die() in the same way. (gh-5880)
All: Applied a fix so that qualified identifiers can unify with metavariables. Notably, this affected Python decorators, among others. (pa-1700)
Fixed a regression in DeepSemgrep after the experimental taint labels feature was introduced in 0.106.0. This prevented DeepSemgrep from reporting taint findings when e.g. the sink was wrapped by another function. (pa-1750)
Fixed metavariable unification in JSON when one of the patterns is a single field. (pa-1763)
Changed symbolic propagation such that "redundant" matches are no longer reported as findings. For instance:
def foo():
x = g(5)
f(x)
If we are looking for the pattern g(5), we should not match on line 3,
since we will match on line 2 anyways, and this is just repeating information that
we already know.
This patch changes it so that we do not match on line 3 anymore. (pa-1772)
Semgrep now passes -j to DeepSemgrep engine so --deep became noticeably faster. (pa-1776)
taint-mode: Due to a mistake in the instantiation of a visitor, named function definitions were being analyzed twice! This is now fixed and you may observe significant speed ups in some cases. (pa-1778)
Extract mode: fixed a possible exception in normal usage introduced due to changes in handling of search/taint rules. (pa-1786)
Changed the fail-open message body (pm-194)
macos-12 is unreliable and has begun failing without
a clear explanation as to why: this downgrades to macos-11,
since 10.15 is to be depracted ~10 from now. (devop-609)Parse several built-in PHP functions in the same way in pfff and tree-sitter. This makes it possible to match exit, eval, empty and isset, even if the
GHA runner-image macos-10.15 is deprecated and will be unsupported by 30AUG2022. We've tested and can upgrade to macos-12 to avoid issues with brownou…
semgrep ci now defaults to fail open and will always exit with exit code 0, which is equivalent to passing --suppress-errors.
To disable this behavior, you can pass --no-suppress-errors and semgrep will behave as it did previously, surfacing any exit codes that may result. (app-1951)--dataflow-traces) should no longer report "strange"
intermediate variables when there are record accesses involved. This happened e.g.
if foo was a tainted record and the code accessed some of its fields as in
foo.bar.baz. This was related to the use of auxiliary variables in the Dataflow IL.
These variables got tainted, but they had real tokens attached corresponding to the
dot . operator. Now we do not include these variables in the taint trace. (pa-1672)macos-10.15 is deprecated and will be unsupported by 30AUG2022. We've tested and can upgrade to macos-12 to avoid issues with brownouts or end of support. (devop-586)One SCA finding per vulnerable dependency. If one rule matches multiple dependencies in one lockfile, that will produce multiple findings. This still…
Fixed issue when scan fails due to pending changes in submodule. (cli-272)
Semgrep CI now accepts more formats of git url for metadata provided to semgrep.dev and lets the user provide a fallback for repo name (SEMGREP_REPO_NAME) and repo url (SEMGREP_REPO_URL) if they are undefined by CI. (cli-280)
Fixed a crash that occurred when reporting results when join mode and taint mode were used together (gh-5839)
JS: Allowed decorators to appear in Semgrep patterns for class methods and fields. (pa-1677)
Quick fix for a regression introduced in 0.107.0 (presumably by taint labels) that could cause some taint rules to crash Semgrep with:
Invalid_argument "output_value: abstract value (Custom)" (pa-1724)
Increase timeout for network calls to semgrep.dev from 30s to 60s (timeout-1)
Made breaking changes to the dataflow_trace JSON output to make it more easily consumable by the App. Added content for taint_source and intermediate_…
obj. ... .bar()) (gh-5819)semgrep-core so that it can now be run with -rules on .yaml files which do not have a top-level rules: ... key. This means you can now copy paste from the playground editor directly into a .yaml file for use with semgrep-core. (implicit-rules-sc-core)--dataflow-traces flag, which directs the Semgrep CLI to explain how non-local values lead to a finding. Currently, this only applies to taint mode findings and it will trace the path from the taint source to the taint sink. (pa-1599)import patterns (gh-5219)-filter_irrelevant_rules was incorrectly skipping files when the PCRE engine threw
an error, while trying to match a regex that determines whether a rule is relevant
for a file. This has been fixed so that, in case of a PCRE error, we assume that the
rule could be relevant and we do run it on the file. (pa-1635)metavariable-comparison: The metavariable field is now optional, except if strip: true. When strip: false (the default) the metavaraible field has no
metavariable-comparison: The metavariable field is now optional, except
if strip: true. When strip: false (the default) the metavaraible field
has no use so it was pointless to require it. (metavariable-comparison-metavariable)
metavariable-comparison now also works on metavariables that cannot be evaluated
to simple literals. In such cases, we take the string representation of the code
bound by the metavariable. The way to access this string representation is via
str($MVAR). For example:
- metavariable-comparison:
metavariable: $X
comparison: str($X) == str($Y)
Here $X and $Y may bind to two different code variables, and we check whether
these two code variables have the same name (e.g. two different variables but both
named x). (pa-1659)
When running an SCA scan with semgrep ci --sca,
SCA findings will no longer be considered blocking if they are unreachable. (sca-128)
Fixed a regression in name resolution that occurred with metavariable patterns (gh-5690)
Rust: Fixed a bug with matching for scoped identifiers
Basically, scoped identifiers were only looking at the last identifier. So something like A::B::C would result in something like C. (gh-5717)
*Experimental* LSP support for: metavariable inlay hints, hot reloading, App integation, scan commands, and much much more (cli-235)
languages value (pa-1648)C#: Improved error message when function parameters are declared with var (gh-5068)
Scala/others: Added a fix allowing percolation of name information from class parameters
For example, classes which take in arguments like the following in Scala:
class ExampleClass(val x: TypeName) {
}
do not properly enter the context. So in our analysis, we would not know that the identifier
x has type TypeName, within the body of ExampleClass. (gh-5506)
Fixed the logged message describing the endpoint where rules are fetched from when SEMGREP_URL is set (gh-5753)
Fixed what data was used for indexing match results to used match based id data (index)
Metavariable-pattern now uses the same metavariable context as its parent. This will potentially cause breaking changes for rules that reuse metavaria…
semgrep ci will now not block builds on triage ignored issues (cli-162)Metavariable-pattern now uses the same metavariable context as its parent. This will potentially cause breaking changes for rules that reuse metavariables in the pattern. For example, consider the following formula:
- patterns:
- pattern-either:
- pattern-inside: $OBJ.output($RESP)
- pattern: $RESP
- metavariable-pattern:
metavariable: $RESP
pattern: `...{ $OBJ }...`
Previously, the $OBJ in the metavariable-pattern would be a new metavariable. The formula would
behave the same if that $OBJ was $A instead. Now, $OBJ will try to unify with the value bound
by $OBJ in the pattern-inside. (gh-5060)
The semgrep test output used to produce expected lines and reported lines which is difficult to read and interpret. This change introduces missed lines and incorrect lines to make it easier for the users to pinpoint the differences in output. (gh-5600)
Separator lines are no longer drawn between findings that have no source code snippet. (sca-ui)
Using ellipses in XML/HTML elements is now more permissive of whitespace.
Previously, in order to have a element with an ellipsis no leading/trailing
whitespace was permitted in the element contents, i.e., <tag>...</tag> was
the only permitted form. Now, leading or trailing whitespace is ignored when
the substantive content of the element is only an ellipsis. (xml-permissive-ellipsis)
os.stat instead of os.access to determine if a file is executable. (gh-5560)--debug isn't passed
since it isn't read unless --debug is used (pa-1618)semgrep ci e2e. (cli-253)towncrier to avoid merge conflicts in changelog on release (cli-77)Expression statement patterns (e.g. foo();) used to also match when they were a bit deeper in the expression (e.g., x = foo();). This can now be disab
foo();) used to also match when
they were a bit deeper in the expression (e.g., x = foo();).
This can now be disabled via rule options:
with implicit_deep_exprstmt: false (#5472)SEMGREP_GIT_COMMAND_TIMEOUT environment variable.
The unit used is seconds. The default value is 300.Your coding agent can read these notes before it upgrades. Set up the MCP server →