# Semgrep

## Home

- [Semgrep Docs](https://docs.semgrep.dev/index.md): Get started with Semgrep to help you catch, flag, and fix real vulnerabilities before they ship.

- [Scan with Semgrep (154 pages)](https://docs.semgrep.dev/_llms/scan-with-semgrep.md): Documentation for Scan with Semgrep.

## Write rules

### Write rules for Semgrep Code

- [Write rules](https://docs.semgrep.dev/writing-rules/overview.md): Semgrep uses rules, which encapsulate pattern matching logic and data flow analysis, to scan your code for security issues, style violations, bugs, and more. In addition to rules available to you in the Semgrep Registry, you can write custom rules to determine what Semgrep detects in your repositori…
- [Private rules](https://docs.semgrep.dev/writing-rules/private-rules.md)
- [Test rules](https://docs.semgrep.dev/writing-rules/testing-rules.md): Semgrep provides a testing mechanism for your rules. You can write code and provide annotations to let Semgrep know where you are or aren't expecting findings. Semgrep provides the following annotations:
- [Troubleshooting rules](https://docs.semgrep.dev/troubleshooting/rules.md)
- [Static analysis and rule-writing glossary](https://docs.semgrep.dev/writing-rules/glossary.md): The definitions provided here are specific to Semgrep.

#### Rule structure syntax

- [Rule structure syntax](https://docs.semgrep.dev/writing-rules/rule-syntax.md)
- [Rule structure syntax examples](https://docs.semgrep.dev/writing-rules/rule-ideas.md): Not sure what to write a rule for? Below are some common questions, ideas, and topics to spur your imagination. Happy hacking! 💡

#### Rule pattern syntax

- [Rule pattern syntax](https://docs.semgrep.dev/writing-rules/pattern-syntax.md)
- [Rule pattern syntax examples](https://docs.semgrep.dev/writing-rules/pattern-examples.md)

#### Advanced rule-writing techniques

- [Rule-defined fix](https://docs.semgrep.dev/writing-rules/rule-defined-fix.md): Rule-defined fix is a Semgrep feature that lets you add suggested fixes to rules.
- [Generic pattern matching](https://docs.semgrep.dev/writing-rules/generic-pattern-matching.md)
- [Metavariable analysis](https://docs.semgrep.dev/writing-rules/metavariable-analysis.md)

##### Dataflow analysis

- [Dataflow analysis engine overview](https://docs.semgrep.dev/writing-rules/data-flow/data-flow-overview.md): Semgrep provides an intraprocedural data-flow analysis engine that opens various Semgrep capabilities. Semgrep provides the following data-flow analyses:
- [Constant propagation](https://docs.semgrep.dev/writing-rules/data-flow/constant-propagation.md)
- [Dataflow status](https://docs.semgrep.dev/writing-rules/data-flow/status.md)

###### Taint analysis

- [Taint analysis overview](https://docs.semgrep.dev/writing-rules/data-flow/taint-mode/overview.md)
- [Advanced taint analysis techniques](https://docs.semgrep.dev/writing-rules/data-flow/taint-mode/advanced.md)

##### Experiments 🧪

- [Introduction to Semgrep experiments](https://docs.semgrep.dev/writing-rules/experiments/introduction.md)
- [Pattern syntax (experimental)](https://docs.semgrep.dev/writing-rules/experiments/pattern-syntax.md)
- [Aliengrep](https://docs.semgrep.dev/writing-rules/experiments/aliengrep.md)
- [Symbolic propagation](https://docs.semgrep.dev/writing-rules/experiments/symbolic-propagation.md): Symbolic propagation allows Semgrep to perform matching modulo variable assignments. Consider the following Python code:
- [Display propagated value of metavariables](https://docs.semgrep.dev/writing-rules/experiments/display-propagated-metavariable.md)
- [Include multiple focus metavariables using set union semantics](https://docs.semgrep.dev/writing-rules/experiments/multiple-focus-metavariables.md): Semgrep matches all pieces of code captured by focus metavariables when you specify them in a rule. Specify the metavariables you want to focus on in a YAML list format.
- [r2c-internal-project-depends-on](https://docs.semgrep.dev/writing-rules/experiments/r2c-internal-project-depends-on.md)
- [Match captured metavariables with specific types](https://docs.semgrep.dev/writing-rules/experiments/metavariable-type.md)
- [Deprecated experiments](https://docs.semgrep.dev/writing-rules/experiments/deprecated-experiments.md)

###### Join mode

- [Join mode overview](https://docs.semgrep.dev/writing-rules/experiments/join-mode/overview.md): Join mode runs several Semgrep rules at once and only returns results if certain conditions on the results are met. Join mode is an experimental mode that lets you cross file boundaries, allowing you to write rules for whole code bases instead of individual files. As the name implies, this was inspi…
- [Recursive joins](https://docs.semgrep.dev/writing-rules/experiments/join-mode/recursive-joins.md)

### Write rules for Semgrep Secrets

- [Semgrep Secrets rule structure and sample](https://docs.semgrep.dev/semgrep-secrets/rules.md): This article walks you through writing, publishing, and using Semgrep Secrets rules. It also demonstrates what a sample Semgrep Secrets rule looks like, with subsequent sections describing the key-value pairs in the context of a Semgrep Secrets rule.
- [Write custom validators](https://docs.semgrep.dev/semgrep-secrets/validators.md)

## Learning guides

### Application Security

- [Semgrep Learning Guides](https://docs.semgrep.dev/learn.md)

#### Security Foundations

- [Security Foundations](https://docs.semgrep.dev/learn/security-foundations/overview.md): This section includes conceptual guides on application security essentials. These fundamental concepts can help strengthen your organization's security posture and can be a helpful reference when educating teams on security principles.
- [Understanding static code scanning tools](https://docs.semgrep.dev/learn/security-foundations/sast/overview.md)
- [Understanding supply chain security](https://docs.semgrep.dev/learn/security-foundations/supply-chain-security.md)
- [Incorporating security testing into development workflows](https://docs.semgrep.dev/learn/security-foundations/security-testing-workflow.md)

#### Vulnerabilities

- [Understanding Security Vulnerabilities](https://docs.semgrep.dev/learn/vulnerabilities/overview.md)
- [Code Injection](https://docs.semgrep.dev/learn/vulnerabilities/code-injection.md): An attacker's ultimate goal is often to escalate a vulnerability into something as impactful as possible. The most dangerous outcome is arbitrary code execution, and few vulnerabilities provide as direct a path to it as code injection.
- [Cross-Site Scripting (XSS)](https://docs.semgrep.dev/learn/vulnerabilities/cross-site-scripting.md)
- [Insecure Deserialization](https://docs.semgrep.dev/learn/vulnerabilities/insecure-deserialization.md)
- [Insecure Direct Object Reference (IDOR)](https://docs.semgrep.dev/learn/vulnerabilities/idor.md): Imagine you’re browsing your order history in an online store. You notice the URL includes an order ID, and out of curiosity, you try changing the number to see what happens.
- [Open Redirect](https://docs.semgrep.dev/learn/vulnerabilities/open-redirect.md)
- [Server Side Request Forgery (SSRF)](https://docs.semgrep.dev/learn/vulnerabilities/server-side-request-forgery.md)
- [SQL Injection](https://docs.semgrep.dev/learn/vulnerabilities/sql-injection.md)
- [XML Security](https://docs.semgrep.dev/learn/vulnerabilities/xml-security.md)

##### Command Injection

- [Command Injection](https://docs.semgrep.dev/learn/vulnerabilities/command-injection.md)
- [Command Injection in Argo Workflows](https://docs.semgrep.dev/learn/vulnerabilities/command-injection/argo-injection.md)
- [Injection Attacks in GitHub Actions](https://docs.semgrep.dev/learn/vulnerabilities/command-injection/github-actions-injection.md)

### Secure Coding

- [Cheat Sheets](https://docs.semgrep.dev/cheat-sheets/overview.md)

#### Go

- [Go](https://docs.semgrep.dev/category/go.md): Security guides and cheatsheets for the Go programming language and related frameworks.
- [Prevent Command Injection for Go](https://docs.semgrep.dev/cheat-sheets/go-command-injection.md)
- [Prevent XSS for Go](https://docs.semgrep.dev/cheat-sheets/go-xss.md)

#### Java

- [Java](https://docs.semgrep.dev/category/java.md): Security guides and cheatsheets for the Java programming language and related frameworks.
- [Prevent Code Injection for Java](https://docs.semgrep.dev/cheat-sheets/java-code-injection.md)
- [Prevent Command Injection for Java](https://docs.semgrep.dev/cheat-sheets/java-command-injection.md)
- [Prevent XSS for Java and Java Server Pages (JSP)](https://docs.semgrep.dev/cheat-sheets/java-jsp-xss.md)
- [Prevent XML External Entity Vulnerabilities for Java](https://docs.semgrep.dev/cheat-sheets/java-xxe.md)

#### JavaScript

- [JavaScript](https://docs.semgrep.dev/category/javascript.md): Security guides and cheatsheets for the JavaScript programming language, Node and related frameworks.
- [Prevent Code Injection in JavaScript](https://docs.semgrep.dev/cheat-sheets/javascript-code-injection.md)
- [Prevent Command Injection for JavaScript](https://docs.semgrep.dev/cheat-sheets/javascript-command-injection.md)
- [Prevent XSS in ExpressJS](https://docs.semgrep.dev/cheat-sheets/express-xss.md)

#### Python

- [Python](https://docs.semgrep.dev/category/python.md): Security guides and cheatsheets for the Python programming language and related frameworks.
- [Prevent Code Injection for Python](https://docs.semgrep.dev/cheat-sheets/python-code-injection.md)
- [Prevent Command Injection for Python](https://docs.semgrep.dev/cheat-sheets/python-command-injection.md)
- [Prevent XSS in Django](https://docs.semgrep.dev/cheat-sheets/django-xss.md)
- [Prevent XSS for Flask](https://docs.semgrep.dev/cheat-sheets/flask-xss.md)
- [Insecure Deserialization in Python](https://docs.semgrep.dev/learn/vulnerabilities/insecure-deserialization/python.md)

#### Ruby

- [Ruby](https://docs.semgrep.dev/category/ruby.md): Security guides and cheatsheets for the Ruby programming language and related frameworks.
- [Prevent Code Injection for Ruby](https://docs.semgrep.dev/cheat-sheets/ruby-code-injection.md)
- [Prevent Command Injection for Ruby](https://docs.semgrep.dev/cheat-sheets/ruby-command-injection.md)
- [Prevent XSS for Ruby on Rails](https://docs.semgrep.dev/cheat-sheets/rails-xss.md)

- [API (259 pages)](https://docs.semgrep.dev/_llms/api.md): Documentation for API.
- [Help (123 pages)](https://docs.semgrep.dev/_llms/help.md): Documentation for Help.

## Explore

### What's Semgrep

#### What's Semgrep

- [Introduction to Semgrep](https://docs.semgrep.dev/introduction.md): Semgrep is a software security tool that provides static application security testing (SAST), software composition analysis (SCA), and secrets detection. Semgrep identifies vulnerabilities in your source code without executing your code. It integrates with IDEs and CI/CD, and can also run from the S…
- [Frequently asked questions](https://docs.semgrep.dev/faq/overview.md)
- [Run a successful proof-of-value (POV) trial with Semgrep](https://docs.semgrep.dev/run-a-successful-pov-1.md)
- [Semgrep AppSec Platform versus Semgrep Community Edition](https://docs.semgrep.dev/semgrep-pro-vs-oss.md)
- [Semgrep Community Edition (CE) philosophy](https://docs.semgrep.dev/contributing/semgrep-philosophy.md)
- [Semgrep integration guide for partners](https://docs.semgrep.dev/integrating.md): We're excited that you're integrating Semgrep into your tooling! Our goal with Semgrep is to bring world-class security tools to developers based on our conviction that software will run the most exciting parts of the future. It's not something that we can do alone; we want to build a community arou…
- [Semgrep metrics](https://docs.semgrep.dev/metrics.md): Semgrep CLI may collect aggregate metrics to help improve the product. This document describes:

##### Comparisons with other tools

- [Compare Semgrep to CodeQL](https://docs.semgrep.dev/faq/comparisons/codeql.md): Both Semgrep and CodeQL use static analysis to find bugs, but there are a few differences:
- [Compare Semgrep to Endor Labs](https://docs.semgrep.dev/faq/comparisons/endor-labs.md)
- [Compare Semgrep to Opengrep](https://docs.semgrep.dev/faq/comparisons/opengrep.md)
- [Compare Semgrep to Snyk](https://docs.semgrep.dev/faq/comparisons/snyk.md)
- [Compare Semgrep to SonarQube](https://docs.semgrep.dev/faq/comparisons/sonarqube.md): Both Semgrep and SonarQube use static analysis to find bugs, but there are a few differences:

### For developers

- [Semgrep for developers](https://docs.semgrep.dev/for-developers/overview.md): This guide is for developers who are using Semgrep in a team or organizational setting.
- [Sign in to Semgrep](https://docs.semgrep.dev/for-developers/signin.md)

#### Resolve findings

- [Resolve findings in your pull request or merge request](https://docs.semgrep.dev/for-developers/resolve-findings-through-comments.md)
- [Resolve findings through Semgrep AppSec Platform](https://docs.semgrep.dev/for-developers/resolve-findings-through-app.md): This guide explains how you can view and triage findings in bulk through the Semgrep AppSec Platform web app.

#### Run scans

- [Run local CLI scans](https://docs.semgrep.dev/for-developers/cli.md): You can run local Semgrep CLI scans with the Semgrep command-line tool.
- [Run IDE scans](https://docs.semgrep.dev/for-developers/ide.md): Semgrep supports the following IDE extensions:

#### References

- [How Semgrep works](https://docs.semgrep.dev/for-developers/detection.md): Semgrep enables you to:

### References

- [Language maturity levels](https://docs.semgrep.dev/references/language-maturity-levels.md)
- [Feature definitions](https://docs.semgrep.dev/references/feature-definitions.md)

#### CI references

- [CI references](https://docs.semgrep.dev/category/ci-references.md)
- [Continuous integration (CI) environment variables](https://docs.semgrep.dev/semgrep-ci/ci-environment-variables.md)
- [Sample continuous integration (CI) configurations](https://docs.semgrep.dev/semgrep-ci/sample-ci-configs.md): This document provides sample configuration snippets to run Semgrep CI on various continuous integration (CI) providers.
- [Findings in CI](https://docs.semgrep.dev/semgrep-ci/findings-ci.md): When running any Semgrep product in CI, Semgrep is able to track the lifetime of an individual finding. When configured to perform a diff-aware scan, Semgrep only shows new findings relative to some specified baseline commit.
- [Packages in the Semgrep docker image](https://docs.semgrep.dev/semgrep-ci/packages-in-semgrep-docker.md)

#### Language-specific features

- [Language-specific features](https://docs.semgrep.dev/category/language-specific-features.md)
- [Semantic detection in Java](https://docs.semgrep.dev/semgrep-code/java.md): This document explains how Semgrep detects true positives and reduces false positives in Java.

#### Glossaries

- [Glossaries](https://docs.semgrep.dev/category/glossaries.md)
- [Semgrep Code product terms](https://docs.semgrep.dev/semgrep-code/glossary.md): The terms and definitions provided here are specific to Semgrep Code.
- [Semgrep Supply Chain glossary](https://docs.semgrep.dev/semgrep-supply-chain/glossary.md): The terms and definitions provided here are specific to Semgrep Supply Chain.

### Support & resources

- [Support](https://docs.semgrep.dev/support.md): This document provides various methods for all users of Semgrep to get help.

## What's New

### What's New

- [What's New](https://docs.semgrep.dev/whats-new/index.md): Highlights of new Semgrep product features shipped each week.

### Release notes

#### Most recent posts

##### 2026

- [Week of August 31, 2026](https://docs.semgrep.dev/release-notes/2026-08-31.md): Updates made to Semgrep during the week of August 31-September 6, 2026.
- [Week of August 24, 2026](https://docs.semgrep.dev/release-notes/2026-08-24.md): Updates made to Semgrep during the week of August 24-30, 2026.
- [Week of August 17, 2026](https://docs.semgrep.dev/release-notes/2026-08-17.md): Updates made to Semgrep during the week of August 17-23, 2026.
- [Week of August 10, 2026](https://docs.semgrep.dev/release-notes/2026-08-10.md): Updates made to Semgrep during the week of August 10-16, 2026.
- [Week of August 3, 2026](https://docs.semgrep.dev/release-notes/2026-08-03.md): Updates made to Semgrep during the week of August 3-9, 2026.
- [Week of July 27, 2026](https://docs.semgrep.dev/release-notes/2026-07-27.md): Updates made to Semgrep during the week of July 27-August 2, 2026.
- [Week of July 20, 2026](https://docs.semgrep.dev/release-notes/2026-07-20.md): Updates made to Semgrep during the week of July 20-26, 2026.
- [Week of July 13, 2026](https://docs.semgrep.dev/release-notes/2026-07-13.md): Updates made to Semgrep during the week of July 13-19, 2026.
- [Week of July 6, 2026](https://docs.semgrep.dev/release-notes/2026-07-06.md): Updates made to Semgrep during the week of July 6-12, 2026.
- [June 2026](https://docs.semgrep.dev/release-notes/june-2026.md): July 8, 2026 · 7 min read
- [May 2026](https://docs.semgrep.dev/release-notes/may-2026.md): June 3, 2026 · 5 min read
- [April 2026](https://docs.semgrep.dev/release-notes/april-2026.md): May 12, 2026 · 8 min read
- [March 2026](https://docs.semgrep.dev/release-notes/march-2026.md): April 10, 2026 · 8 min read
- [February 2026](https://docs.semgrep.dev/release-notes/february-2026.md): March 6, 2026 · 4 min read
- [January 2026](https://docs.semgrep.dev/release-notes/january-2026.md): February 4, 2026 · 4 min read
- [December 2025](https://docs.semgrep.dev/release-notes/december-2025.md): January 13, 2026 · 7 min read

##### 2025

- [November 2025](https://docs.semgrep.dev/release-notes/november-2025.md): December 9, 2025 · 6 min read
- [October 2025](https://docs.semgrep.dev/release-notes/october-2025.md): November 11, 2025 · 3 min read
- [September 2025](https://docs.semgrep.dev/release-notes/september-2025.md): October 23, 2025 · 3 min read
- [August 2025](https://docs.semgrep.dev/release-notes/august-2025.md): September 3, 2025 · 3 min read
- [July 2025](https://docs.semgrep.dev/release-notes/july-2025.md): August 8, 2025 · 5 min read
- [June 2025](https://docs.semgrep.dev/release-notes/june-2025.md): July 18, 2025 · 6 min read
- [May 2025](https://docs.semgrep.dev/release-notes/may-2025.md): May 30, 2025 · 5 min read
- [April 2025](https://docs.semgrep.dev/release-notes/april-2025.md): April 30, 2025 · 4 min read

## OpenAPI Specs

- [public_v1.openapi](/public_v1.openapi.yaml)
- [public_v2.openapi](/public_v2.openapi.yaml)

## Optional

- [Registry](https://semgrep.dev/explore/)
- [Playground](https://semgrep.dev/playground/new)
- [Academy](https://academy.semgrep.dev)
- [Registry](https://semgrep.dev/explore)
- [Playground](https://semgrep.dev/playground/new)
- [Semgrep Academy](https://academy.semgrep.dev/)
- [GitHub](https://github.com/semgrep/semgrep-docs)

> The links below point to documentation indexes. Follow each `/_llms/` index recursively until you reach documentation pages.

## Indexes

- [Scan with Semgrep (154 pages)](https://docs.semgrep.dev/_llms/scan-with-semgrep.md): Documentation for Scan with Semgrep.
- [API (259 pages)](https://docs.semgrep.dev/_llms/api.md): Documentation for API.
- [API / v2 (Experimental) (229 pages)](https://docs.semgrep.dev/_llms/api/v2-experimental.md): Documentation for API / v2 (Experimental).
- [Help (123 pages)](https://docs.semgrep.dev/_llms/help.md): Documentation for Help.
