NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
PyPI · #815 most downloaded on PyPI
Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.
Last release 3 days ago
02 Oct 2026
Ships on a steady schedule
a new release about every 2 weeks
Nearly every release is documented
notes for 54 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
6 years old
360 releases · first in 2020
One column per quarter.
Added new metavariable-pattern operator (available only via --optimizations), thanks to Kai Zhong for the feature request (#3257).
--debugging-json (#3265)Per rule parse times and per rule-file parse and match times added to opt-in metrics
--optimizations all--timeout-threshold option in --optimizations all modeMetrics collection of project_hash in cases where git is not available
--strict will now return results if there are nosem mismatches. Semgrep will report a nonzero exit code if --strict is set and there are nosem mismathces. #3099Let meta-variables match both a constant variable occurrence and that same constant value
Keep track of and report rule parse time in addition to file parse time
$ARG = [$V];
...
<... $O[$ARG] ...>; // this works now
y in x[y]--debug.--max-target-bytes 0 restores the old behavior.--timeReinstate --debugging-json to avoid stderr output of --debug
--debugging-json to avoid stderr output of --debugJS/TS: Infer global constants even if the const qualifier is missing
const qualifier is missing (#2978)--time flag instead of --json-time which shows a summary of the
timing information when invoked with normal output and adds a time field
to the json output when --json is also presentsemgrep_main.invoke_semgrep) now takes an
optional OutputSettings argument for controlling outputOutputSettings.json_time has moved to OutputSettings.output_time,
this and many other OutputSettings arguments have been made optional--debugging-json flag in favor of --json + --debug--json-time flag in favor of --json + --timeSupport for matching multiple arguments with a metavariable (#3009) This is done with a 'spread metavariable' operator that looks like $...ARGS. This
$...ARGS. This used to be available only for JS/TS and is now available
for the other languages (Python, Java, Go, C, Ruby, PHP, and OCaml).--optimizations [STR] command-line flag to turn on/off some
optimizations. Use 'none' to turn off everything and 'all' to turn on
everything.
Just using --optimizations is equivalent to --optimizations all, and
not using --optimizations is equivalent to --optimizations none.<a href="foo">...</a> (#2963)<a href=$X>some text</a> (#2964)Taint mode: Basic cross-function analysis
extra lines data is now consistent across scan types
(e.g. semgrep-core, spacegrep, pattern-regex)Rust: Semgrep patterns now support top-level statements
for(...) for Java$FLD: { ... } patternthis.that.check.yaml.
More concretely: configs end with .yaml, YAML language tests end with .test.yaml,
and everything else is handled by its respective language extension (e.g. .py).YAML language support to --test
<... foo ...>) now match within the bodies of anonymous
functions (a.k.a. lambda-expressions) and arbitrary language-specific
statements (e.g. the Golang go statement)New --experimental flag for passing rules directly to semgrep-core
--experimental flag for passing rules directly to semgrep-core (#2836)Support for YAML! You can now write YAML patterns in rules to match over YAML target files (including semgrep YAML rules, inception!)
$_COOKIE (#2820)semgrep-core onlyThese features are not yet available via the semgrep CLI,
but have been fixed to the internal semgrep-core binary.
Support for generating patterns that will match multiple given code targets
Added propagation of metavariables to clauses nested under patterns:. Fixes #2548.
patterns:. Fixes #2548.--json-time flag which reports runtimes for (rule, target file)--vim flag for Syntasticrs or rust as a languageStatically link pcre in semgrep-core for MacOS releases
Added basic typed metavariables for javascript and typescript
semgrep-core onlyThese features are not yet available via the semgrep CLI,
but have been added to the internal semgrep-core binary.
Documentation for contributing new languages.
:= short assignment in Go. (#2440)No new changes in this version. This is a re-release of 0.39.0 due to an error in the release process.
No new changes in this version. This is a re-release of 0.39.0 due to an error in the release process.
$X == $Y can now match specific types like so: (char *$X) == $Y. (#2431)semgrep-core onlyThese features are not yet available via the semgrep CLI, but have been added to the internal semgrep-core binary.
semgrep-core supports rules in JSON and Jsonnet format. (#2428)semgrep-core supports a new nested format for combining patterns into a boolean query. (#2430)-c is the new shorthand for --config in the CLI. -f is kept as an alias for backward-compatibility. (#2447)Nothing published for this version
Added a new language: Rust. Support for basic semgrep patterns (#2391) thanks to Ruin0x11!
pattern-not-regex added so findings can be filtered using regular expression
Typed metavariables can now match field access when we can propagate the type of a field
setup.py functionality (.whl and pip install unchanged):
SEMGREP_SKIP_BIN, SEMGREP_CORE_BIN, and SPACEGREP_BIN now availableSupport for ... in chains of method calls in JS, e.g. $O.foo() ... .bar()
... in chains of method calls in JS, e.g. $O.foo() ... .bar()--test (#1796)Experimental support for matching multiple arguments in JS/TS. This is done with a 'spread metavariable' operator, that looks like $...ARGS.
$...ARGS.... inside a Golang switch statement.try, the catch, or the finally part of a try { } catch (e) { } finally { } construct in JS/TS.if () part of an if () { } construct in Java{..., $KEY: $VAL, ...}.--json-stats flag. The stats output contains the number of files and lines of code scanned, broken down by language. It also contains profiling data broken down by rule ID. Please note that as this is an experimental flag, the output format is subject to change in later releases.regex as their language. The previously used language none will keep working as well.--max-lines-per-finding option.// nosemgrep comment instead of the original // nosem. The two keywords have identical behavior.semgrep-core flag named -max_match_per_file prevents these crashes by forcing a 'timeout' state when 10,000 matches are reached. Semgrep can then gracefully report what combination of rules and paths causes too much work.semgrep --debug works again, and now outputs even more debugging information from semgrep-core. The new debugging output is especially helpful to discover which rules have too many matches.$X & $Y will now correctly match bitwise AND operations in Ruby.Allow selecting rules based on severity with the --severity flag. Thanks @kishorbhat!
--severity flag. Thanks @kishorbhat!def bar def foo when the
pattern is def ... foo, instead matching just def foo... foo to match what comes before fooinclude $XJSON output now includes an attribute of findings named is_ignored. This is false under regular circumstances, but if you run with --disable-nosem, it
is_ignored.
This is false under regular circumstances,
but if you run with --disable-nosem,
it will return true for findings
that normally would've been excluded by a // nosem comment.Regression in 0.31.0 where only a single file was being used when --config was given a directory with multiple rules (#2019).
--config
was given a directory with multiple rules (#2019).Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →