
Collection of Semgrep rules for static code analysis, detecting security vulnerabilities, and enforcing secure coding practices across multiple languages.
This repository contains Semgrep rules developed by Trail of Bits and made available to the public. They are part of our ongoing development efforts and are used in our security audits, vulnerability reseach, and internal projects. They will evolve over time as we identify new techniques.
Visit Testing Handbook for Semgrep guidance.
The easiest way to run the rules is to run them from the Semgrep registry. To do so, navigate to the root folder of your project and run the following:
$ semgrep --config "p/trailofbits"
Alternatively, you can clone this repository, navigate to the root folder of your project, and run individual rules using the command below :
$ semgrep --config /path/to/semgrep-rules/semgreprule.yml
To run all rules from the cloned repository:
$ semgrep --config /path/to/semgrep-rules/ .
Semgrep will run against all supported code files except for those in your .gitignore file. If you want to run the rules against all files and directories, including those in your .gitignore, add the --no-git-ignore flag.
$ semgrep --config /path/to/semgrep-rules/ . --no-git-ignore
You can also tell Semgrep to ignore files and directories that match any pattern. For instance, if you want to tell Semgrep to ignore all Go test files you can run the following:
$ semgrep --config /path/to/semgrep-rules/ . --exclude='*_test.go'
Use -o to output results to a file:
$ semgrep --config /path/to/semgrep-rules/hanging-goroutine.yml -o leaks.txt'
| ID | Playground | Impact | Confidence | Description |
|---|---|---|---|---|
| eth-rpc-tracetransaction | ππ | π₯ | π | Detects attempts to extract trace information from an EVM transaction or block. In exchange or bridge applications, extra logic must be implemented encapsulating these endpoints to prevent the values transferred during reverted call frames from being counted. |
| eth-txreceipt-status | ππ | π₯ | π | Detects when a transaction receipt's status is read |
| hanging-goroutine | ππ | π© | π | Goroutine leaks |
| invalid-usage-of-modified-variable | ππ | π§ | π | Possible unintentional assignment when an error occurs |
| iterate-over-empty-map | ππ | π© | π | Probably redundant iteration over an empty map |
| missing-runlock-on-rwmutex | ππ | π§ | π | Missing RUnlock on an RWMutex lock before returning from a function |
| missing-unlock-before-return | ππ | π§ | π | Missing mutex unlock before returning from a function |
| nil-check-after-call | ππ | π§ | π | Possible nil dereferences |
| racy-append-to-slice | ππ | π§ | π | Concurrent calls to append from multiple goroutines |
| racy-write-to-map | ππ | π§ | π | Concurrent writes to the same map in multiple goroutines |
| servercodec-readrequestbody-unhandled-nil | ππ | π© | π | Possible incorrect ServerCodec interface implementation |
| string-to-int-signedness-cast | ππ | π§ | π | Integer underflows |
| sync-mutex-value-copied | ππ | π© | π | Copying of sync.Mutex via value receivers |
| unmarshal-tag-is-dash | ππ | π§ | π | |
| unmarshal-tag-is-omitempty | ππ | π© | π | |
| unsafe-dll-loading | ππ | π₯ | π | Use of function vulnerable to DLL hijacking attacks |
| waitgroup-add-called-inside-goroutine | ππ | π§ | π | Calls to sync.WaitGroup.Add inside of anonymous goroutines |
| waitgroup-wait-inside-loop | ππ | π§ | π | Calls to sync.WaitGroup.Wait inside a loop |