Skip to content

Add Semgrep to the MetaMask Security Code Scanner#20

Merged
EllusionN merged 2 commits intomainfrom
ellul/add-semgrep
Jan 24, 2025
Merged

Add Semgrep to the MetaMask Security Code Scanner#20
EllusionN merged 2 commits intomainfrom
ellul/add-semgrep

Conversation

@EllusionN
Copy link
Contributor

Summary

This pull request integrates https://github.com/MetaMask/semgrep-action into the MetaMask Security Code scanner, allowing us to be capable of more easily writing custom rules.

Testing

I've set up https://github.com/MetaMask/Appsec-Playground to use this branch of the code scanner. To test this action perform the following:

  1. Create a pull request in the appsec-playground repo with any conents.
  2. See the scan executes successfully.

Here is an example of a rule violation: https://github.com/MetaMask/Appsec-Playground

@EllusionN EllusionN requested a review from a team as a code owner January 17, 2025 20:19
witmicko
witmicko previously approved these changes Jan 20, 2025
Copy link
Contributor

@witmicko witmicko left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

👍

@EllusionN EllusionN merged commit bcf57b9 into main Jan 24, 2025
2 checks passed
@EllusionN EllusionN deleted the ellul/add-semgrep branch January 24, 2025 15:02
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants