Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

outdated rules in semgrep registry #15

Open
adriensaladin opened this issue Nov 10, 2022 · 2 comments
Open

outdated rules in semgrep registry #15

adriensaladin opened this issue Nov 10, 2022 · 2 comments
Assignees

Comments

@adriensaladin
Copy link

Hi team,

Thank you for maintaining this repository of semgrep rules!

I've noticed that the semgrep registry https://semgrep.dev/p/trailofbits is a bit outdated compared to this github repo. For example, the go/questionable-assignment.yml ruleset, which tends to generate false positives, is still used on semgrep.

If the current version is considered stable, would it be possible to update the registry?
Thanks!

@hex0punk
Copy link
Contributor

Hi @adriensaladin, thank you for opening this. The Semgrep registry cannot be automatically updated to reflect specific changes, such as deleted rules. For that reason, we suggest using the rules directly from this repo. I will update this issue once I reach out to them and they update the registry.

@hex0punk hex0punk self-assigned this Nov 18, 2022
@GrosQuildu GrosQuildu self-assigned this Dec 14, 2022
@GrosQuildu
Copy link
Collaborator

Small update - we are going to slightly change the structure of the repo, which requires updates to the registry and so is related to this issue. We are still waiting for response from the r2c team.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants