Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

chore: enable semgrep #508

Merged
merged 1 commit into from
Apr 15, 2022
Merged

chore: enable semgrep #508

merged 1 commit into from
Apr 15, 2022

Conversation

96malhar
Copy link
Contributor

Issue #, if available:
DOTNET-5807

Description of changes:
This PR enables code scanning using Semgrep CI
Read more: https://semgrep.dev/docs/semgrep-ci/overview/

While scanning the entire repo with the current rule set, 63 JQuery vulnerabilities were discovered across 12 test web-apps.
Fixing them periodically, will increase toil and therefore testapps/ have been excluded from code scanning.

By submitting this pull request, I confirm that you can use, modify, copy, and redistribute this contribution, under the terms of your choice.

@96malhar 96malhar merged commit 84f5626 into dev Apr 15, 2022
@96malhar 96malhar deleted the kmalhar/enable-semgrep branch April 15, 2022 14:34
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

4 participants