https://github.com/semgrep/pre-commit
Pre-commit hooks to run Semgrep
https://github.com/semgrep/pre-commit
Last synced: about 1 year ago
JSON representation
Pre-commit hooks to run Semgrep
- Host: GitHub
- URL: https://github.com/semgrep/pre-commit
- Owner: semgrep
- License: lgpl-2.1
- Created: 2024-04-26T20:18:07.000Z (about 2 years ago)
- Default Branch: develop
- Last Pushed: 2025-04-09T07:06:23.000Z (over 1 year ago)
- Last Synced: 2025-04-09T08:23:06.007Z (over 1 year ago)
- Language: Shell
- Size: 114 KB
- Stars: 3
- Watchers: 13
- Forks: 4
- Open Issues: 4
-
Metadata Files:
- Readme: README.md
- License: LICENSE
Awesome Lists containing this project
README
# Semgrep pre-commit
This repository contains several hooks designed to be used with the
[pre-commit] framework. Pre-commit uses [git hooks][git-hooks] (including, but
not only, the [eponymous one][git-pre-commit]) to run checks.
See [`.pre-commit-hooks.yaml`](.pre-commit-hooks.yaml) for the hooks this
repository defines.
## `semgrep ci`
To configure [pre-commit] to run custom rules and rulesets from the [Semgrep
AppSec Platform][semgrep-platform], similar to `semgrep ci`, we provide the
`semgrep-ci` hook. This can be used by adding the following to your
`.pre-commit-config.yaml` after installing `pre-commit`:
```yaml
- repo: https://github.com/semgrep/pre-commit
rev: 'v1.120.1'
hooks:
- id: semgrep-ci
```
## `semgrep scan`
Likewise, you can configure a hook to run a `semgrep scan` with the `semgrep`
hook. As an example, the following configuration would scan the files to be
committed with a specified config, skipping files with unknown extensions:
```yaml
- repo: https://github.com/semgrep/pre-commit
rev: 'v1.120.1'
hooks:
- id: semgrep
# See https://semgrep.dev/explore to select a ruleset and copy its URL
args: ['--config', '', '--error', '--skip-unknown-extensions']
```
## Running Pro rules
If you would like to run the pre-commit hook locally while using Semgrep Pro
rules:
1. Log in to your Semgrep account. Running this command launches a browser
window, but you can also use the link that's returned in the CLI to proceed:
```
$ semgrep login
```
2. In the Semgrep CLI login, click **Activate** to proceed.
---
The code in this repository is licensed under the terms of the [LGPL
2.1](LICENSE). For more information about the licensing details of Semgrep
itself see [our licensing page][semgrep-licensing].
[pre-commit]: https://pre-commit.com
[git-hooks]: https://git-scm.com/book/en/v2/Customizing-Git-Git-Hooks
[git-pre-commit]: https://git-scm.com/docs/githooks#_pre_commit
[semgrep-platform]: https://semgrep.dev/products/semgrep-appsec-platform
[semgrep-licensing]: https://semgrep.dev/docs/licensing/