Skip to content
Navigation Menu
Sign in
Appearance settings
Platform
AI CODE CREATION
GitHub Copilot
Write better code with AI
GitHub Copilot app
Direct agents from issue to merge
MCP Registry
Integrate external tools
DEVELOPER WORKFLOWS
Actions
Automate any workflow
Codespaces
Instant dev environments
Issues
Plan and track work
Code Review
Manage code changes
Code Quality
Enforce quality at merge
APPLICATION SECURITY
GitHub Advanced Security
Find and fix vulnerabilities
Code security
Secure your code as you build
Secret protection
Stop leaks before they start
EXPLORE
Why GitHub
Documentation
Blog
Changelog
Marketplace
View all features
Solutions
BY COMPANY SIZE
Enterprises
Small and medium teams
Startups
Nonprofits
BY USE CASE
App Modernization
DevSecOps
DevOps
CI/CD
View all use cases
BY INDUSTRY
Healthcare
Financial services
Manufacturing
Government
View all industries
View all solutions
Resources
EXPLORE BY TOPIC
AI
Software Development
DevOps
Security
View all topics
EXPLORE BY TYPE
Customer stories
Events & webinars
Ebooks & reports
Business insights
GitHub Skills
SUPPORT & SERVICES
Documentation
Customer support
Community forum
Trust center
Partners
View all resources
Open Source
COMMUNITY
GitHub Sponsors
Fund open source developers
PROGRAMS
Security Lab
Maintainer Community
Accelerator
GitHub Stars
Archive Program
REPOSITORIES
Topics
Trending
Collections
Enterprise
ENTERPRISE SOLUTIONS
Enterprise platform
AI-powered developer platform
AVAILABLE ADD-ONS
GitHub Advanced Security
Enterprise-grade security features
Copilot for Business
Enterprise-grade AI features
Premium Support
Enterprise-grade 24/7 support
Pricing
Search
/
Sign in
Sign up
Appearance settings
You signed in with another tab or window.
Reload
to refresh your session.
You signed out in another tab or window.
Reload
to refresh your session.
You switched accounts on another tab or window.
Reload
to refresh your session.
Dismiss alert
{{ message }}
Uh oh!
There was an error while loading.
Please reload this page
.
semgrep
/
semgrep-rules
Public
Notifications
You must be signed in to change notification settings
Fork
573
Star
1.2k
Code
Issues
101
Pull requests
130
Actions
Projects
Security and quality
0
Insights
Additional navigation options
Code
Issues
Pull requests
Actions
Projects
Security and quality
Insights
Actions: semgrep/semgrep-rules
Actions
All workflows
Workflows
Copilot code review
Copilot code review
Dependabot Updates
Dependabot Updates
Deploy to dev.semgrep.dev and staging.semgrep.dev
Deploy to dev.semgrep.dev and staging.semgrep.dev
Deploy to semgrep.dev
Deploy to semgrep.dev
num-rules
num-rules
pre-commit
pre-commit
semgrep-rule-lints
semgrep-rule-lints
semgrep-rules-pro benchmark
semgrep-rules-pro benchmark
semgrep-rules-test
semgrep-rules-test
semgrep-rules-test-develop
semgrep-rules-test-develop
Show more workflows...
Management
Caches
pre-commit
pre-commit
Actions
Loading...
Loading
Sorry, something went wrong.
Uh oh!
There was an error while loading.
Please reload this page
.
will be ignored since log searching is not yet available
Show workflow options
Create status badge
Create status badge
Loading
Uh oh!
There was an error while loading.
Please reload this page
.
pre-commit.yml
will be ignored since log searching is not yet available
687 workflow runs
687 workflow runs
Event
Filter by Event
Sorry, something went wrong.
Filter
Loading
Sorry, something went wrong.
No matching events.
Status
Filter by Status
Sorry, something went wrong.
Filter
Loading
Sorry, something went wrong.
No matching statuses.
Branch
Filter by Branch
Sorry, something went wrong.
Filter
Loading
Sorry, something went wrong.
No matching branches.
Actor
Filter by Actor
Sorry, something went wrong.
Filter
Loading
Sorry, something went wrong.
No matching users.
fix(docker-compose): support files without version
pre-commit
#10210:
Pull request
#4037
opened by
fyrsta7
Action required
fyrsta7:codex/docker-compose-versionless
fyrsta7:codex/docker-compose-versionless
Action required
View #4037
View workflow file
fix(java): catch permissive file permission APIs
pre-commit
#10209:
Pull request
#4034
opened by
0xTaoZ
Action required
0xTaoZ:agent/fix-java-file-permission-fns
0xTaoZ:agent/fix-java-file-permission-fns
Action required
View #4034
View workflow file
Add tarfile-unsafe-extraction rule (CWE-22 tarslip)
pre-commit
#10208:
Pull request
#4033
opened by
rahulreddykarne
Action required
rahulreddykarne:rahulreddykarne-patch-1
rahulreddykarne:rahulreddykarne-patch-1
Action required
View #4033
View workflow file
Merge Develop into Release
pre-commit
#10207:
Pull request
#4032
synchronize by
r2c-argo
Bot
27s
merge-develop-to-release
merge-develop-to-release
27s
View #4032
View workflow file
Merge pull request #4017 from semgrep/inline-pinned-precommit
pre-commit
#10206:
Commit
40b8c63
pushed by
leifdreizler
23s
develop
develop
23s
View workflow file
Merge Develop into Release
pre-commit
#10205:
Pull request
#4032
by
r2c-argo
Bot
Failure
develop
develop
Failure
View #4032
View workflow file
Merge pull request #3997 from semgrep/marc-andre/fix-oracle-manipulat…
pre-commit
#10204:
Commit
947bf05
pushed by
malaverdiere
Failure
develop
develop
Failure
View workflow file
fix(java): detect String.formatted() in jdo-sqli
pre-commit
#10203:
Pull request
#4023
by
Eljees
Failure
Eljees:agent/jdo-sqli-formatted
Eljees:agent/jdo-sqli-formatted
Failure
View #4023
View workflow file
fix(django): let django-no-csrf-token span realistic form bodies
pre-commit
#10202:
Pull request
#4025
by
Eljees
Failure
Eljees:agent/csrf-token-ellipsis-span
Eljees:agent/csrf-token-ellipsis-span
Failure
View #4025
View workflow file
fix(java): catch chained ProcessBuilder command injection
pre-commit
#10201:
Pull request
#4026
by
Eljees
Failure
Eljees:agent/process-builder-chained-and-later-args
Eljees:agent/process-builder-chained-and-later-args
Failure
View #4026
View workflow file
fix(c): describe the real hazard in insecure-use-strtok-fn
pre-commit
#10200:
Pull request
#4022
by
Eljees
Failure
Eljees:agent/strtok-message-thread-safety
Eljees:agent/strtok-message-thread-safety
Failure
View #4022
View workflow file
fix: correct regex pattern in insecure-hash-function rule
pre-commit
#10199:
Pull request
#4031
by
lxcxjxhx
Failure
lxcxjxhx:fix/insecure-hash-regex
lxcxjxhx:fix/insecure-hash-regex
Failure
View #4031
View workflow file
fix: Solidity move basic-oracle-manipulation test annotation to the matched line
pre-commit
#10198:
Pull request
#3997
by
malaverdiere
Failure
marc-andre/lang-207-update-solidity-grammar
marc-andre/lang-207-update-solidity-grammar
Failure
View #3997
View workflow file
fix: Solidity move basic-oracle-manipulation test annotation to the matched line
pre-commit
#10197:
Pull request
#3997
by
malaverdiere
Failure
marc-andre/fix-oracle-manipulation-solidity-line
marc-andre/fix-oracle-manipulation-solidity-line
Failure
View #3997
View workflow file
Fix Renovate minimum release age exception
pre-commit
#10196:
Pull request
#4029
by
Eljees
Failure
Eljees:agent/fix-renovate-minimum-release-age
Eljees:agent/fix-renovate-minimum-release-age
Failure
View #4029
View workflow file
fix(java): avoid eqeq false positives on null checks
pre-commit
#10195:
Pull request
#4028
by
0xTaoZ
Failure
0xTaoZ:agent/fix-java-eqeq-ternary
0xTaoZ:agent/fix-java-eqeq-ternary
Failure
View #4028
View workflow file
fix(java): treat ACCESS_EXTERNAL_DTD as an XXE sanitizer
pre-commit
#10194:
Pull request
#4024
by
Eljees
Failure
Eljees:agent/xxe-setattribute-sanitizer
Eljees:agent/xxe-setattribute-sanitizer
Failure
View #4024
View workflow file
fix(java): recognize SharedSessionContract in hibernate-sqli
pre-commit
#10193:
Pull request
#4027
by
Eljees
Failure
Eljees:agent/hibernate-sqli-shared-session
Eljees:agent/hibernate-sqli-shared-session
Failure
View #4027
View workflow file
fix(java): catch chained ProcessBuilder command injection
pre-commit
#10192:
Pull request
#4026
by
Eljees
Failure
Eljees:agent/process-builder-chained-and-later-args
Eljees:agent/process-builder-chained-and-later-args
Failure
View #4026
View workflow file
fix(django): let django-no-csrf-token span realistic form bodies
pre-commit
#10191:
Pull request
#4025
by
Eljees
Failure
Eljees:agent/csrf-token-ellipsis-span
Eljees:agent/csrf-token-ellipsis-span
Failure
View #4025
View workflow file
fix(java): treat ACCESS_EXTERNAL_DTD as an XXE sanitizer
pre-commit
#10190:
Pull request
#4024
by
Eljees
Failure
Eljees:agent/xxe-setattribute-sanitizer
Eljees:agent/xxe-setattribute-sanitizer
Failure
View #4024
View workflow file
fix(java): detect String.formatted() in jdo-sqli
pre-commit
#10189:
Pull request
#4023
by
Eljees
Failure
Eljees:agent/jdo-sqli-formatted
Eljees:agent/jdo-sqli-formatted
Failure
View #4023
View workflow file
fix(c): describe the real hazard in insecure-use-strtok-fn
pre-commit
#10188:
Pull request
#4022
by
Eljees
Failure
Eljees:agent/strtok-message-thread-safety
Eljees:agent/strtok-message-thread-safety
Failure
View #4022
View workflow file
Merge Develop into Release (conflict-resolved, supersedes #4012)
pre-commit
#10187:
Pull request
#4021
by
p4p3r
Failure
merge-develop-to-release-4012
merge-develop-to-release-4012
Failure
View #4021
View workflow file
Add 4 Laravel security rules: raw SQL, open redirect, mass assignment, weak hashing
pre-commit
#10186:
Pull request
#3808
by
momenbasel
Failure
momenbasel:laravel-security-rules
momenbasel:laravel-security-rules
Failure
View #3808
View workflow file
Previous
1
2
3
4
5
…
27
28
Next
You can’t perform that action at this time.