Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Proposal to add semgrep to CI/CD #174

Open
federicofantini opened this issue May 17, 2023 · 0 comments
Open

Proposal to add semgrep to CI/CD #174

federicofantini opened this issue May 17, 2023 · 0 comments

Comments

@federicofantini
Copy link

Hi guys, during the secure software development course held by M. Andreolini the professor showed us a very powerful software: semgrep.
This software allows you to do static analysis of software sources and identify vulnerable patterns starting from rules written in YAML format.
Semgrep is open source and in the free version around 1000 rules are offered, if desired there is also the premium version of the rules.
Also it is possible to integrate semgrep into the github CI using or not their cloud platform, in the second case there are these limitations.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant