Semgrep Rulesets Reference
Complete Ruleset Catalog
Security-Focused Rulesets
| Ruleset |
Description |
Use Case |
p/security-audit |
Comprehensive vulnerability detection, higher false positives |
Manual audits, security reviews |
p/secrets |
Hardcoded credentials, API keys, tokens |
Always include |
p/owasp-top-ten |
OWASP Top 10 web application vulnerabilities |
Web app security |
p/cwe-top-25 |
CWE Top 25 most dangerous software weaknesses |
General security |
p/sql-injection |
SQL injection patterns and tainted data flows |
Database security |
p/insecure-transport |
Ensures code uses encrypted channels |
Network security |
p/gitleaks |
Hard-coded credentials detection (gitleaks port) |
Secrets scanning |
p/findsecbugs |
FindSecBugs rule pack for Java |
Java security |
p/phpcs-security-audit |
PHP security audit rules |
PHP security |
CI/CD Rulesets
| Ruleset |
Description |
Use Case |
p/default |
Default ruleset, balanced coverage |
First-time users |
p/ci |
High-confidence security + logic bugs, low FP |
CI pipelines |
p/r2c-ci |
Low false positives, CI-safe |
CI/CD blocking |
p/r2c |
Community favorite, curated by Semgrep (618k+ downloads) |
General scanning |
p/auto |
Auto-selects rules based on detected languages/frameworks |
Quick scans |
p/comment |
Comment-related rules |
Code review |
Third-Party Rulesets
| Ruleset |
Description |
Maintainer |
p/gitlab |
GitLab-maintained security rules |
GitLab |
Ruleset Selection Algorithm
Follow this algorithm to select rulesets based on detected languages and frameworks.
Step 1: Always Include Security Baseline
{
"baseline": ["p/security-audit", "p/secrets"]
}
p/security-audit - Comprehensive vulnerability detection (always include)
p/secrets - Hardcoded credentials, API keys, tokens (always include)
Step 2: Add Language-Specific Rulesets
For each detected language, add the primary ruleset. If a framework is detected, add its ruleset too.
GA Languages (production-ready):
| Detection |
Primary Ruleset |
Framework Rulesets |
Pro Rule Count |
.py |
p/python |
p/django, p/flask, p/fastapi |
710+ |
.js, .jsx |
p/javascript |
p/react, p/nodejs, p/express, p/nextjs, p/angular |
250+ (JS), 70+ (JSX) |
.ts, .tsx |
p/typescript |
p/react, p/nodejs, p/express, p/nextjs, p/angular |
230+ |
.go |
p/golang |
p/go (alias) |
80+ |
.java |
p/java |
p/spring, p/findsecbugs |
190+ |
.kt |
p/kotlin |
p/spring |
60+ |
.rb |
p/ruby |
p/rails |
40+ |
.php |
p/php |
p/symfony, p/laravel, p/phpcs-security-audit |
50+ |
.c, .cpp, .h |
p/c |
- |
150+ |
.rs |
p/rust |
- |
40+ |
.cs |
p/csharp |
- |
170+ |
.scala |
p/scala |
- |
Community |
.swift |
p/swift |
- |
60+ |
Beta Languages (Pro recommended):
| Detection |
Primary Ruleset |
Notes |
.ex, .exs |
p/elixir |
Requires Pro for best coverage |
.cls, .trigger |
p/apex |
Salesforce; requires Pro |
Experimental Languages:
| Detection |
Primary Ruleset |
Notes |
.sol |
No official ruleset |
Use Decurity third-party rules |
Dockerfile |
p/dockerfile |
Limited rules |
.yaml, .yml |
p/yaml |
K8s, GitHub Actions, docker-compose patterns |
.json |
r/json.aws |
AWS IAM policies; use r/json.* for specific rules |
| Bash scripts |
- |
Community support |
| Cairo, Circom |
- |
Experimental, smart contracts |
Framework detection hints:
| Framework |
Detection Signals |
Ruleset |
| Django |
settings.py, urls.py, django in requirements |
p/django |
| Flask |
flask in requirements, @app.route |
p/flask |
| FastAPI |
fastapi in requirements, @app.get/post |
p/fastapi |
| React |
package.json with react dependency, .jsx/.tsx files |
p/react |
| Next.js |
next.config.js, pages/ or app/ directory |
p/nextjs |
| Angular |
angular.json, @angular/ dependencies |
p/angular |
| Express |
express in package.json, app.use() patterns |
p/express |
| NestJS |
@nestjs/ dependencies, @Controller decorators |
p/nodejs |
| Spring |
pom.xml with spring, @SpringBootApplication |
p/spring |
| Rails |
Gemfile with rails, config/routes.rb |
p/rails |
| Laravel |
composer.json with laravel, artisan |
p/laravel |
| Symfony |
composer.json with symfony, config/packages/ |
p/symfony |
Step 3: Add Infrastructure Rulesets
| Detection |
Ruleset |
Description |
Dockerfile |
p/dockerfile |
Container security, best practices |
.tf, .hcl |
p/terraform |
IaC misconfigurations, CIS benchmarks, AWS/Azure/GCP |
| k8s manifests |
p/kubernetes |
K8s security, RBAC issues |
| CloudFormation |
p/cloudformation |
AWS infrastructure security |
| GitHub Actions |
p/github-actions |
CI/CD security, secrets exposure |
.yaml, .yml |
p/yaml |
Generic YAML patterns (K8s, docker-compose) |
| AWS IAM JSON |
r/json.aws |
IAM policy misconfigurations (use --config r/json.aws) |
Step 4: Add Third-Party Rulesets
These are NOT optional. Include automatically when language matches:
| Languages |
Source |
Why Required |
| Python, Go, Ruby, JS/TS, Terraform, HCL |
Trail of Bits |
Security audit patterns from real engagements (AGPLv3) |
| C, C++ |
0xdea |
Memory safety, low-level vulnerabilities |
| Solidity, Cairo, Rust |
Decurity |
Smart contract vulnerabilities, DeFi exploits |
| Go |
dgryski |
Additional Go-specific patterns |
| Android (Java/Kotlin) |
MindedSecurity |
OWASP MASTG-derived mobile security rules |
| Java, Go, JS/TS, C#, Python, PHP |
elttam |
Security consulting patterns |
| Dockerfile, PHP, Go, Java |
kondukto |
Container and web app security |
| PHP, Kotlin, Java |
dotta |
Pentest-derived web/mobile app rules |
| Terraform, HCL |
HashiCorp |
HashiCorp infrastructure patterns |
| Swift, Java, Cobol |
akabe1 |
iOS and legacy system patterns |
| Java |
Atlassian Labs |
Atlassian-maintained Java rules |
| Python, JS/TS, Java, Ruby, Go, PHP |
Apiiro |
Malicious code detection, supply chain |
Step 5: Verify Rulesets
Before finalizing, verify official rulesets load:
# Quick validation (exits 0 if valid)
semgrep --config p/python --validate --metrics=off 2>&1 | head -3
Or browse the Semgrep Registry.
Output Format
{
"baseline": ["p/security-audit", "p/secrets"],
"python": ["p/python", "p/django"],
"javascript": ["p/javascript", "p/react", "p/nodejs"],
"docker": ["p/dockerfile"],
"third_party": ["https://github.com/trailofbits/semgrep-rules"]
}
1---2name: semgrep-rulesets-reference3description: Follow this algorithm to select rulesets based on detected languages and frameworks.4---5# Semgrep Rulesets Reference67## Complete Ruleset Catalog89### Security-Focused Rulesets1011| Ruleset | Description | Use Case |12|---------|-------------|----------|13| `p/security-audit` | Comprehensive vulnerability detection, higher false positives | Manual audits, security reviews |14| `p/secrets` | Hardcoded credentials, API keys, tokens | Always include |15| `p/owasp-top-ten` | OWASP Top 10 web application vulnerabilities | Web app security |16| `p/cwe-top-25` | CWE Top 25 most dangerous software weaknesses | General security |17| `p/sql-injection` | SQL injection patterns and tainted data flows | Database security |18| `p/insecure-transport` | Ensures code uses encrypted channels | Network security |19| `p/gitleaks` | Hard-coded credentials detection (gitleaks port) | Secrets scanning |20| `p/findsecbugs` | FindSecBugs rule pack for Java | Java security |21| `p/phpcs-security-audit` | PHP security audit rules | PHP security |2223### CI/CD Rulesets2425| Ruleset | Description | Use Case |26|---------|-------------|----------|27| `p/default` | Default ruleset, balanced coverage | First-time users |28| `p/ci` | High-confidence security + logic bugs, low FP | CI pipelines |29| `p/r2c-ci` | Low false positives, CI-safe | CI/CD blocking |30| `p/r2c` | Community favorite, curated by Semgrep (618k+ downloads) | General scanning |31| `p/auto` | Auto-selects rules based on detected languages/frameworks | Quick scans |32| `p/comment` | Comment-related rules | Code review |3334### Third-Party Rulesets3536| Ruleset | Description | Maintainer |37|---------|-------------|------------|38| `p/gitlab` | GitLab-maintained security rules | GitLab |3940---4142## Ruleset Selection Algorithm4344Follow this algorithm to select rulesets based on detected languages and frameworks.4546### Step 1: Always Include Security Baseline4748```json49{50 "baseline": ["p/security-audit", "p/secrets"]51}52```5354- `p/security-audit` - Comprehensive vulnerability detection (always include)55- `p/secrets` - Hardcoded credentials, API keys, tokens (always include)5657### Step 2: Add Language-Specific Rulesets5859For each detected language, add the primary ruleset. If a framework is detected, add its ruleset too.6061**GA Languages (production-ready):**6263| Detection | Primary Ruleset | Framework Rulesets | Pro Rule Count |64|-----------|-----------------|-------------------|----------------|65| `.py` | `p/python` | `p/django`, `p/flask`, `p/fastapi` | 710+ |66| `.js`, `.jsx` | `p/javascript` | `p/react`, `p/nodejs`, `p/express`, `p/nextjs`, `p/angular` | 250+ (JS), 70+ (JSX) |67| `.ts`, `.tsx` | `p/typescript` | `p/react`, `p/nodejs`, `p/express`, `p/nextjs`, `p/angular` | 230+ |68| `.go` | `p/golang` | `p/go` (alias) | 80+ |69| `.java` | `p/java` | `p/spring`, `p/findsecbugs` | 190+ |70| `.kt` | `p/kotlin` | `p/spring` | 60+ |71| `.rb` | `p/ruby` | `p/rails` | 40+ |72| `.php` | `p/php` | `p/symfony`, `p/laravel`, `p/phpcs-security-audit` | 50+ |73| `.c`, `.cpp`, `.h` | `p/c` | - | 150+ |74| `.rs` | `p/rust` | - | 40+ |75| `.cs` | `p/csharp` | - | 170+ |76| `.scala` | `p/scala` | - | Community |77| `.swift` | `p/swift` | - | 60+ |7879**Beta Languages (Pro recommended):**8081| Detection | Primary Ruleset | Notes |82|-----------|-----------------|-------|83| `.ex`, `.exs` | `p/elixir` | Requires Pro for best coverage |84| `.cls`, `.trigger` | `p/apex` | Salesforce; requires Pro |8586**Experimental Languages:**8788| Detection | Primary Ruleset | Notes |89|-----------|-----------------|-------|90| `.sol` | No official ruleset | Use Decurity third-party rules |91| `Dockerfile` | `p/dockerfile` | Limited rules |92| `.yaml`, `.yml` | `p/yaml` | K8s, GitHub Actions, docker-compose patterns |93| `.json` | `r/json.aws` | AWS IAM policies; use `r/json.*` for specific rules |94| Bash scripts | - | Community support |95| Cairo, Circom | - | Experimental, smart contracts |9697**Framework detection hints:**9899| Framework | Detection Signals | Ruleset |100|-----------|------------------|---------|101| Django | `settings.py`, `urls.py`, `django` in requirements | `p/django` |102| Flask | `flask` in requirements, `@app.route` | `p/flask` |103| FastAPI | `fastapi` in requirements, `@app.get/post` | `p/fastapi` |104| React | `package.json` with react dependency, `.jsx`/`.tsx` files | `p/react` |105| Next.js | `next.config.js`, `pages/` or `app/` directory | `p/nextjs` |106| Angular | `angular.json`, `@angular/` dependencies | `p/angular` |107| Express | `express` in package.json, `app.use()` patterns | `p/express` |108| NestJS | `@nestjs/` dependencies, `@Controller` decorators | `p/nodejs` |109| Spring | `pom.xml` with spring, `@SpringBootApplication` | `p/spring` |110| Rails | `Gemfile` with rails, `config/routes.rb` | `p/rails` |111| Laravel | `composer.json` with laravel, `artisan` | `p/laravel` |112| Symfony | `composer.json` with symfony, `config/packages/` | `p/symfony` |113114### Step 3: Add Infrastructure Rulesets115116| Detection | Ruleset | Description |117|-----------|---------|-------------|118| `Dockerfile` | `p/dockerfile` | Container security, best practices |119| `.tf`, `.hcl` | `p/terraform` | IaC misconfigurations, CIS benchmarks, AWS/Azure/GCP |120| k8s manifests | `p/kubernetes` | K8s security, RBAC issues |121| CloudFormation | `p/cloudformation` | AWS infrastructure security |122| GitHub Actions | `p/github-actions` | CI/CD security, secrets exposure |123| `.yaml`, `.yml` | `p/yaml` | Generic YAML patterns (K8s, docker-compose) |124| AWS IAM JSON | `r/json.aws` | IAM policy misconfigurations (use `--config r/json.aws`) |125126### Step 4: Add Third-Party Rulesets127128These are **NOT optional**. Include automatically when language matches:129130| Languages | Source | Why Required |131|-----------|--------|--------------|132| Python, Go, Ruby, JS/TS, Terraform, HCL | [Trail of Bits](https://github.com/trailofbits/semgrep-rules) | Security audit patterns from real engagements (AGPLv3) |133| C, C++ | [0xdea](https://github.com/0xdea/semgrep-rules) | Memory safety, low-level vulnerabilities |134| Solidity, Cairo, Rust | [Decurity](https://github.com/Decurity/semgrep-smart-contracts) | Smart contract vulnerabilities, DeFi exploits |135| Go | [dgryski](https://github.com/dgryski/semgrep-go) | Additional Go-specific patterns |136| Android (Java/Kotlin) | [MindedSecurity](https://github.com/mindedsecurity/semgrep-rules-android-security) | OWASP MASTG-derived mobile security rules |137| Java, Go, JS/TS, C#, Python, PHP | [elttam](https://github.com/elttam/semgrep-rules) | Security consulting patterns |138| Dockerfile, PHP, Go, Java | [kondukto](https://github.com/kondukto-io/semgrep-rules) | Container and web app security |139| PHP, Kotlin, Java | [dotta](https://github.com/federicodotta/semgrep-rules) | Pentest-derived web/mobile app rules |140| Terraform, HCL | [HashiCorp](https://github.com/hashicorp-forge/semgrep-rules) | HashiCorp infrastructure patterns |141| Swift, Java, Cobol | [akabe1](https://github.com/akabe1/akabe1-semgrep-rules) | iOS and legacy system patterns |142| Java | [Atlassian Labs](https://github.com/atlassian-labs/atlassian-sast-ruleset) | Atlassian-maintained Java rules |143| Python, JS/TS, Java, Ruby, Go, PHP | [Apiiro](https://github.com/apiiro/malicious-code-ruleset) | Malicious code detection, supply chain |144145### Step 5: Verify Rulesets146147Before finalizing, verify official rulesets load:148149```bash150# Quick validation (exits 0 if valid)151semgrep --config p/python --validate --metrics=off 2>&1 | head -3152```153154Or browse the [Semgrep Registry](https://semgrep.dev/explore).155156### Output Format157158```json159{160 "baseline": ["p/security-audit", "p/secrets"],161 "python": ["p/python", "p/django"],162 "javascript": ["p/javascript", "p/react", "p/nodejs"],163 "docker": ["p/dockerfile"],164 "third_party": ["https://github.com/trailofbits/semgrep-rules"]165}166```