-
Notifications
You must be signed in to change notification settings - Fork 584
Pull requests: semgrep/semgrep-rules
Author
Label
Projects
Milestones
Reviews
Assignee
Sort
Pull requests list
feat: TypeScript mcp-command-injection and mcp-ssrf (#3873)
#4052
opened Sep 4, 2026 by
Tito0015
Loading…
2 tasks done
fix: stop treating realpath/abspath as complete path sanitizers
#4051
opened Sep 3, 2026 by
munzzyy
Loading…
2
Add rule: github-actions-checkout-persist-credentials (checkout leaves GitHub token in git config)
#4050
opened Sep 3, 2026 by
VanshBhardwaj1945
Loading…
fix: preserve path taint through replace calls
#4049
opened Sep 2, 2026 by
fusiontechstrategies
Loading…
feat: detect root users in Docker Compose services
#4048
opened Sep 2, 2026 by
fusiontechstrategies
Loading…
3 tasks done
fix: avoid Bash parsing for non-Bash action steps
#4047
opened Sep 2, 2026 by
fusiontechstrategies
Loading…
Add mcp-credential-destination-injection-python rule
#4043
opened Aug 20, 2026 by
SyedAnas01
Loading…
2 tasks done
Exclude
$/ self-repository refs from action pinning rules
#4042
opened Aug 19, 2026 by
nopcorn
Loading…
fix(generic-api-key): exclude pnpm-workspace.yaml
#4041
opened Aug 19, 2026 by
MgmClientGuy
Loading…
python/flask: catch inline render_template_string() calls in dangerous-template-string
#4040
opened Aug 18, 2026 by
shmulc8
Loading…
feat(python): add static detection rules for un-gated AI agent tool execution and excessive agency
#4039
opened Aug 17, 2026 by
AAH20
Loading…
Add tarfile-unsafe-extraction rule (CWE-22 tarslip)
#4033
opened Jul 31, 2026 by
rahulreddykarne
Loading…
fix(java): recognize SharedSessionContract in hibernate-sqli
#4027
opened Jul 28, 2026 by
Eljees
Loading…
fix(java): catch chained ProcessBuilder command injection
#4026
opened Jul 28, 2026 by
Eljees
Loading…
fix(django): let django-no-csrf-token span realistic form bodies
#4025
opened Jul 28, 2026 by
Eljees
Loading…
fix(java): treat ACCESS_EXTERNAL_DTD as an XXE sanitizer
#4024
opened Jul 28, 2026 by
Eljees
Loading…
fix(c): describe the real hazard in insecure-use-strtok-fn
#4022
opened Jul 27, 2026 by
Eljees
Loading…
fix(gha): run-shell-injection flags the truthiness-check shape on bare inputs
#4020
opened Jul 27, 2026 by
munzzyy
Loading…
fix(java/jdo-sqli): detect String.formatted() as a tainted query source
#4016
opened Jul 24, 2026 by
rayair250-droid
Loading…
Previous Next
ProTip!
Adding no:label will show everything without a label.