Skip to content
KitploitKITPLOIT
ツールブログ
提出
ツールブログ
提出

ハッキング、侵入テスト、サイバーセキュリティツールをあなたのセキュリティアーセナルに!

Kitploitはハッキング、サイバーセキュリティ、ペネトレーションテストのツールディレクトリです。最新のプロジェクトアップデートを見つけて、脆弱性の発見、システム分析、テストの自動化、セキュリティの強化を行いましょう。

··フィード·お問い合わせ·プライバシー·© 2026 Kitploit

ツールディレクトリ

カテゴリ

すべてのカテゴリを見る
Loading categories
semgrep-rules — 静的コード解析、セキュリティ脆弱性の検出、および複数の言語にわたる安全なコーディング慣行を適用するための Semgrep ルール集。 | Kitploit
ツール/GitHubGitHub/trailofbits/semgrep-rules
静的分析脆弱性分析コード分析DevSecOps設定ミス
GitHubtrailofbits/semgrep-rules

semgrep-rules

静的コード解析、セキュリティ脆弱性の検出、および複数の言語にわたる安全なコーディング慣行を適用するための Semgrep ルール集。

リポジトリを見る
520593ヶ月前Kitploit レビュー済み

人気

すべて見る →

コミュニティで最も使われているツールを見つけましょう。

すべてのツールを探索

ツールコレクションを閲覧

すべてのツールを見る →
共有

Trail of Bits 公開 Semgrep ルール

このリポジトリには、Trail of Bits が開発し公開している Semgrep ルールが含まれています。これらは当社の継続的な開発活動の一部であり、セキュリティ監査、脆弱性調査、社内プロジェクトで使用されています。新しい技術を特定するにつれて、時間の経過とともに進化していきます。

Semgrep のガイダンスについては、Testing Handbook を参照してください。

Semgrep の使用方法

ルールを実行する最も簡単な方法は、Semgrep レジストリ から実行することです。これを行うには、プロジェクトのルートフォルダーに移動して、次のコマンドを実行します。```shell $ semgrep --config "p/trailofbits"

root@kitploit:~
あるいは、このリポジトリをクローンして、プロジェクトのルートフォルダに移動し、以下のコマンドを使用して個々のルールを実行することもできます:```shell
$ semgrep --config /path/to/semgrep-rules/semgreprule.yml

クローンしたリポジトリからすべてのルールを実行するには:```shell $ semgrep --config /path/to/semgrep-rules/ .

root@kitploit:~
## 便利なフラグ

Semgrep は、`.gitignore` ファイルに含まれるものを除き、サポートされているすべてのコードファイルに対して実行されます。`.gitignore` に含まれるファイルやディレクトリを含むすべてのファイルとディレクトリに対してルールを実行する場合は、`--no-git-ignore` フラグを追加してください。```shell
$ semgrep --config /path/to/semgrep-rules/ . --no-git-ignore

また、Semgrep に任意のパターンに一致するファイルやディレクトリを無視させることもできます。たとえば、Semgrep にすべての Go テストファイルを無視させたい場合は、次のコマンドを実行します:```shell $ semgrep --config /path/to/semgrep-rules/ . --exclude='*_test.go'

root@kitploit:~
`-o` を使用して結果をファイルに出力します:```shell
$ semgrep --config /path/to/semgrep-rules/hanging-goroutine.yml -o leaks.txt'

Rules

go

IDPlaygroundImpactConfidenceDescription
eth-rpc-tracetransaction🛝🔗🟥🌕EVMトランザクションまたはブロックからトレース情報を抽出しようとする試みを検出します。取引所やブリッジアプリケーションでは、リバートされたコールフレーム中に転送された値が計上されないように、これらのエンドポイントをカプセル化する追加ロジックを実装する必要があります。
eth-txreceipt-status🛝🔗🟥🌕トランザクションレシートのステータスが読み取られたことを検出します
hanging-goroutine🛝🔗🟩🌗ゴルーチンのリーク
invalid-usage-of-modified-variable🛝🔗🟧🌘エラー発生時に意図しない代入が行われる可能性
iterate-over-empty-map🛝🔗🟩🌗空のマップに対する冗長な反復処理の可能性
missing-runlock-on-rwmutex🛝🔗🟧🌗

python

IDPlaygroundImpactConfidenceDescription
automatic-memory-pinning🛝🔗🟩🌘PyTorchメモリが自動的に固定されていない
lxml-in-pandas🛝🔗🟧🌘pandasでのlxmlの読み込みによるXXE攻撃の可能性
msgpack-numpy🛝🔗🟥🌗ピクル化に依存する関数による任意のコード実行の可能性
numpy-distutils🛝🔗🟩🌘非推奨のnumpy.distutilsの使用
numpy-f2py-compile🛝🔗🟥🌗NumPyのf2pyコンパイルによる任意のコード実行の可能性
numpy-in-pytorch-datasets🛝🔗🟩🌘

rs

IDPlaygroundImpactConfidenceDescription
panic-in-function-returning-result🛝🔗🟩🌘Resultを返す関数内でのunwrapまたはexpectの呼び出し

javascript

IDPlaygroundImpactConfidenceDescription
schema-directives🛝🔗🟥🌗古いApolloServerオプションの'schemaDirectives'の使用
use-of-graphql-upload🛝🔗🟧🌕graphql-uploadライブラリの使用
v3-potentially-bad-cors🛝🔗🟧🌕不適切な可能性のあるCORSポリシー
v3-express-bad-cors🛝🔗🟥🌗不適切なCORSポリシー
v3-express-no-cors🛝🔗🟩🌘CORSポリシーの欠如
v3-bad-cors🛝🔗🟥🌗不適切なCORSポリシー

ruby

IDPlaygroundImpactConfidenceDescription
action-dispatch-insecure-ssl🛝🔗🟥🌘
action-mailer-insecure-tls🛝🔗🟥🌘
active-record-encrypts-misorder🛝🔗🟥🌘
active-record-hardcoded-encryption-key🛝🔗🟥🌘
faraday-disable-verification🛝🔗🟥🌘
global-timeout🛝🔗🟩🌘
insecure-rails-cookie-session-store

hcl

IDPlaygroundImpactConfidenceDescription
docker-hardcoded-password🛝🔗🟥🌘
docker-privileged-mode🛝🔗🟩🌘
podman-tls-verify-disabled🛝🔗🟩🌘
root-user🛝🔗🟩🌘
tls-hostname-verification-disabled🛝🔗🟥🌘
aws-oidc-role-policy-duplicate-condition🛝🔗🟥🌘
aws-oidc-role-policy-missing-sub

jvm

IDPlaygroundImpactConfidenceDescription
gc-call🛝🔗🟩🌘
mongo-hostname-verification-disabled🛝🔗🟥🌘

yaml| ID | Playground | Impact | Confidence | Description |

| -- | :--------: | :----: | :--------: | ----------- | | apt-key-unencrypted-url | 🛝🔗 | 🟥 | 🌘 | | | apt-key-validate-certs-disabled | 🛝🔗 | 🟥 | 🌘 | | | apt-unencrypted-url | 🛝🔗 | 🟥 | 🌘 | | | dnf-unencrypted-url | 🛝🔗 | 🟥 | 🌘 | | | dnf-validate-certs-disabled | 🛝🔗 | 🟥 | 🌘 | | | get-url-unencrypted-url | 🛝🔗 | 🟥 | 🌘 | | | get-url-validate-certs-disabled | 🛝🔗 | 🟥 | 🌘 | | | rpm-key-unencrypted-url | 🛝🔗 | 🟥 | 🌘 | | | rpm-key-validate-certs-disabled | 🛝🔗 | 🟥 | 🌘 | | | unarchive-unencrypted-url | 🛝🔗 | 🟥 | 🌘 | | | unarchive-validate-certs-disabled | 🛝🔗 | 🟥 | 🌘 | | | wrm-cert-validation-ignore | 🛝🔗 | 🟥 | 🌘 | | | yum-unencrypted-url | 🛝🔗 | 🟥 | 🌘 | | | yum-validate-certs-disabled | 🛝🔗 | 🟥 | 🌘 | | | zypper-repository-unencrypted-url | 🛝🔗 | 🟥 | 🌘 | | | zypper-unencrypted-url | 🛝🔗 | 🟥 | 🌘 | | | port-all-interfaces | 🛝🔗 | 🟩 | 🌕 | | | aws-secret-key | 🛝🔗 | 🟧 | 🌘 | | | azure-principal-secret | 🛝🔗 | 🟧 | 🌘 | | | gcp-credentials-json | 🛝🔗 | 🟧 | 🌘 | | | jfrog-hardcoded-credential | 🛝🔗 | 🟧 | 🌘 | | | pypi-publish-password | 🛝🔗 | 🟧 | 🌘 | | | rubygems-publish-key | 🛝🔗 | 🟧 | 🌘 | | | vault-token | 🛝🔗 | 🟧 | 🌘 | |

generic

IDPlaygroundImpactConfidenceDescription
amqp-unencrypted-transport🛝🔗🟥🌘
container-privileged🛝🔗🟥🌗
container-user-root🛝🔗🟥🌗
curl-insecure🛝🔗🟥🌗
curl-unencrypted-url🛝🔗🟥🌗
gpg-insecure-flags🛝🔗🟥🌗
installer-allow-untrusted🛝🔗

swift

IDPlaygroundImpactConfidenceDescription
insecure-url-host-hassuffix-check🛝🔗🌫️🌘

コントリビューション

プルリクエストと issue を歓迎します!

詳細は CONTRIBUTING.md を参照してください。

ライセンス

このリポジトリで定義されているルールは AGPLv3 のもとでライセンスされています。

サイドカーの例は他の作品から派生している 場合があり、必要な場合には元のライセンスを保持します。

ツールをダウンロード
関数から戻る前にRWMutexロックのRUnlockが欠落しています
missing-unlock-before-return🛝🔗🟧🌗関数から戻る前にmutexのアンロックが欠落しています
nil-check-after-call🛝🔗🟧🌗nil参照外しの可能性
racy-append-to-slice🛝🔗🟧🌗複数のゴルーチンからのappendへの同時呼び出し
racy-write-to-map🛝🔗🟧🌗複数のゴルーチンによる同じマップへの同時書き込み
servercodec-readrequestbody-unhandled-nil🛝🔗🟩🌘ServerCodecインターフェースの実装が不正確な可能性
string-to-int-signedness-cast🛝🔗🟧🌘整数のアンダーフロー
sync-mutex-value-copied🛝🔗🟩🌘値レシーバによるsync.Mutexのコピー
unmarshal-tag-is-dash🛝🔗🟧🌘
unmarshal-tag-is-omitempty🛝🔗🟩🌘
unsafe-dll-loading🛝🔗🟥🌘DLLハイジャック攻撃に対して脆弱な関数の使用
waitgroup-add-called-inside-goroutine🛝🔗🟧🌗匿名ゴルーチン内でのsync.WaitGroup.Addの呼び出し
waitgroup-wait-inside-loop🛝🔗🟧🌗ループ内でのsync.WaitGroup.Waitの呼び出し
Torchデータセット内でのNumPyRNGの呼び出し
numpy-in-pytorch-modules🛝🔗🌫️🌗PyTorchモジュール内でのNumPy関数の使用
numpy-load-library🛝🔗🟥🌗NumPyライブラリの読み込みによる任意のコード実行の可能性
onnx-session-options🛝🔗🟥🌗ONNXライブラリの読み込みによる任意のコード実行の可能性
pandas-eval🛝🔗🟥🌕ユーザー指定の式を評価するpandas関数による任意のコード実行の可能性
pickles-in-keras-deprecation🛝🔗🟥🌗Kerasのload_model関数による任意のコード実行の可能性
pickles-in-keras🛝🔗🟥🌗Kerasのload_model関数による任意のコード実行の可能性
pickles-in-numpy🛝🔗🟥🌗ピクル化に依存するNumPy関数による任意のコード実行の可能性
pickles-in-pandas🛝🔗🟥🌗ピクル化に依存するPandas関数による任意のコード実行の可能性
pickles-in-pytorch-distributed🛝🔗🟥🌗ピクル化に依存するPyTorch.Distributed関数による任意のコード実行の可能性
pickles-in-pytorch🛝🔗🟥🌗ピクル化に依存するPyTorch関数による任意のコード実行の可能性
pickles-in-tensorflow🛝🔗🟥🌗TensorFlowのload関数による任意のコード実行の可能性
pytorch-classes-load-library🛝🔗🟥🌗PyTorchライブラリの読み込みによる任意のコード実行の可能性
pytorch-package🛝🔗🟥🌕torch.packageによる任意のコード実行の可能性
pytorch-tensor🛝🔗🌫️🌘不適切なテンソル生成による解析上の問題と非効率性の可能性
scikit-joblib-load🛝🔗🟥🌗ピクル化に依存するSciKit.Joblib関数による任意のコード実行の可能性
tarfile-extractall-traversal🛝🔗🟧🌗tarfileに対するextractall呼び出しにおけるパストラバーサルの可能性
tensorflow-load-library🛝🔗🟥🌗TensorFlowライブラリの読み込みによる任意のコード実行の可能性
waiting-with-pytorch-distributed🛝🔗🟩🌗リクエストを待機しない場合のPyTorchの未定義動作の可能性
v3-no-cors🛝🔗🟩🌘CORSポリシーの欠如
v3-csrf-prevention🛝🔗🟧🌘CSRF対策の欠如
v4-csrf-prevention🛝🔗🟧🌘CSRF保護の無効化
🛝🔗
🟩
🌘
json-create-deserialization🛝🔗🟥🌕
rails-cache-store-marshal🛝🔗🟩🌗
rails-cookie-attributes🛝🔗🟩🌘
rails-params-json🛝🔗🟥🌕
rest-client-disable-verification🛝🔗🟥🌘
ruby-saml-skip-validation🛝🔗🟧🌘
yaml-unsafe-load🛝🔗🟥🌘
🛝🔗
🟥
🌘
vault-hardcoded-token🛝🔗🟥🌘
vault-skip-tls-verify🛝🔗🟥🌘
🟥
🌘
mongodb-insecure-transport🛝🔗🟥🌘
mysql-insecure-sslmode🛝🔗🟥🌗
node-disable-certificate-validation🛝🔗🟥🌘
openssl-insecure-flags🛝🔗🟥🌗
postgres-insecure-sslmode🛝🔗🟥🌘
redis-unencrypted-transport🛝🔗🟥🌘
ssh-disable-host-key-checking🛝🔗🟥🌗
tar-insecure-flags🛝🔗🟥🌗
wget-no-check-certificate🛝🔗🟥🌗
wget-unencrypted-url🛝🔗🟥🌗