Iron Law: NO SAST CONFIGURATION WITHOUT READING THE CUSTOM RULES FILE FIRST
Read references/semgrep-custom-rules.md before writing or modifying any SAST configuration.
When to Use
- Setting up scanning for a new service → tool selection + config templates
- Writing or modifying Semgrep rules → custom rules reference
- Integrating SAST into CI/CD → GitHub Actions example in tool config
- Triaging SAST findings → risk scoring and false positive suppression
Process
- Detect languages — Check for
pom.xml(Java),package.json(TS),pyproject.toml(Python),pubspec.yaml(Dart) - Load custom rules — Read
references/semgrep-custom-rules.mdfor project-specific rules already in place - Select tools — Java → SpotBugs + Semgrep; TS/Angular/NestJS → ESLint security + Semgrep; Python → Bandit + Semgrep; Dart → dart analyze
- Configure — See
references/sast-tool-config.mdfor config file templates and CI/CD step - Run and triage — Execute
/security-sast [path], classify findings, suppress false positives per the suppression patterns in tool config
References
| File | Content |
|---|---|
references/semgrep-custom-rules.md |
10 custom Semgrep rules for Java/TS/Python, usage, suppression syntax |
references/sast-tool-config.md |
Tool comparison matrix, config templates (Bandit/.bandit, ESLint, dart analyze, Semgrep CI), risk scoring thresholds |
Error Handling
If a scanner is not installed, report the install command from the tool config reference rather than skipping the scan silently.