Skip to content

Proposal to add semgrep to CI/CD #174

@federicofantini

Description

@federicofantini

Hi guys, during the secure software development course held by M. Andreolini the professor showed us a very powerful software: semgrep.
This software allows you to do static analysis of software sources and identify vulnerable patterns starting from rules written in YAML format.
Semgrep is open source and in the free version around 1000 rules are offered, if desired there is also the premium version of the rules.
Also it is possible to integrate semgrep into the github CI using or not their cloud platform, in the second case there are these limitations.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions