semgrep
https://github.com/returntocorp/semgrep
OCaml
Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.
Triage Issues!
When you volunteer to triage issues, you'll receive an email each day with a link to an open issue that needs help in this project. You'll also receive instructions on how to triage issues.
Triage Docs!
Receive a documented method or class from your favorite GitHub repos in your inbox every day. If you're really pro, receive undocumented methods or classes and supercharge your commit history.
OCaml not yet supported1 Subscribers
Add a CodeTriage badge to semgrep
Help out
- Issues
- [Python] Taint mode - False Positive in Try-Except-Finally
- semgrep bash_completion has no nosort option, MacOS, bash shell only.
- [Taint Mode - Python] Wrong source reported
- False Negative: `rust.rocket.sql.diesel-taint.diesel-taint` fails to track taint through dereference (`*`) and `RefCell` unwrapping
- semgrep.dev bug report from editor - stuck in loading state
- ChatGPT integration error "This MCP server doesn't implement our specification"
- [Rust] A false negative about hardcoed-auth vulnerability detection
- (Windows-python) semgrep ver. 1.140.0 scan fail - "charmap codec can't encode character"
- c/c++: add support for matching character literals, e.g., with sizeof('...')
- Python: semgrep doesn't see that symbols live in their own modules
- Docs
- OCaml not yet supported