Skip to content

Commit

Permalink
Merge pull request #322 from DataDog/s.obregoso/bump_semgrep_version
Browse files Browse the repository at this point in the history
Bump semgrep verstion from 0.112.1 to 1.67.0
  • Loading branch information
christophetd authored Apr 8, 2024
2 parents ba5e53f + 0d3f723 commit fe3ab1a
Show file tree
Hide file tree
Showing 5 changed files with 339 additions and 469 deletions.
14 changes: 7 additions & 7 deletions guarddog/analyzer/sourcecode/code-execution.yml
Original file line number Diff line number Diff line change
Expand Up @@ -23,22 +23,22 @@ rules:
# subprocess module
- pattern: subprocess.getoutput($ARG1, ...)
- pattern: getoutput($ARG1, ...)
- pattern: subprocess.getoutput([..., "$ARG1", ...], ...)
- pattern: getoutput([..., "$ARG1", ...], ...)
- pattern: subprocess.getoutput([..., "... $ARG1 ...", ...], ...)
- pattern: getoutput([..., "... $ARG1 ...", ...], ...)

- pattern: subprocess.call($ARG1, ...)
- pattern: call($ARG1, ...)
- pattern: subprocess.call([..., "$ARG1", ...], ...)
- pattern: call([..., "$ARG1", ...], ...)
- pattern: subprocess.call([..., "... $ARG1 ...", ...], ...)
- pattern: call([..., "... $ARG1 ...", ...], ...)

- pattern: subprocess.check_output($ARG1, ...)
- pattern: check_output($ARG1, ...)
- pattern: subprocess.check_output([..., "$ARG1", ...], ...)
- pattern: check_output([..., "$ARG1", ...], ...)
- pattern: subprocess.check_output([..., "... $ARG1 ...", ...], ...)
- pattern: check_output([..., "... $ARG1 ...", ...], ...)

- pattern: subprocess.run($ARG1, ...)
- pattern: run($ARG1, ...)
- pattern: subprocess.run([..., "$ARG1", ...], ...)
- pattern: subprocess.run([..., "... $ARG1 ...", ...], ...)
- pattern: run([..., "$ARG1", ...], ...)

# eval, allow checking for version
Expand Down
Loading

0 comments on commit fe3ab1a

Please sign in to comment.