close
Skip to main content
Semgrep is an open-source static analysis tool designed to scan code for security vulnerabilities and code quality issues. CodeRabbit runs Semgrep version 1.174.0.

Configuration

Semgrep is enabled by default. Enable or disable it and optionally select a configuration file with .coderabbit.yaml or the CodeRabbit web UI:
.coderabbit.yaml
The optional config_file setting has no default. Semgrep uses a YAML-style configuration file. When config_file is omitted or cannot be used, CodeRabbit looks for the following file names:
  • semgrep.yml or semgrep.yaml
  • semgrep.config.yml or semgrep.config.yaml
CodeRabbit checks matching files changed by the pull request, then the repository root, then the rest of the repository. Pipeline configuration paths are excluded. The config_file value must be an existing repository-local relative path. CodeRabbit rejects absolute paths, parent-directory traversal (../), URLs, and Semgrep registry shorthands beginning with p/ or r/. If config_file names a rejected or non-existent value, CodeRabbit falls back to discovering one of the supported repository-local default configuration filenames listed above. Due to licensing, CodeRabbit does not ship with the community-created Semgrep rules.
CodeRabbit will only run Semgrep if your repository contains a Semgrep config file. This config must use the default file names, or you must define the path to this file in the .coderabbit.yaml or config UI.

When we skip Semgrep

CodeRabbit skips Semgrep when:
  • Semgrep is disabled in CodeRabbit settings or .coderabbit.yaml.
  • No changed files use a supported extension.
  • No supported repository-local configuration file is found.
  • Semgrep is already running in GitHub Actions, GitLab CI, CircleCI, or Azure Pipelines.
Individual files that are 8 MiB or larger are skipped.

Files

Semgrep will run on the following file types:
  • C/C++ (.c, .cpp, .cc, .cxx, .c++, .h, .hpp, .hh, .hxx, .h++)
  • C# (.cs)
  • Go (.go)
  • Java (.java)
  • JavaScript (.js, .jsx)
  • Kotlin (.kt)
  • Python (.py)
  • TypeScript (.ts)
  • Ruby (.rb)
  • Rust (.rs)
  • PHP (.php)
  • Scala (.scala)
  • Swift (.swift)
  • Terraform (.tf)
  • JSON (.json)