Home / Companies / GitLab / Blog / Post Details
Content Deep Dive

How to write and continuously test vulnerability detection rules for SAST

Blog post from GitLab

Post Details
Company
Date Published
Author
Ross Fuhrman and Anshuman Singh and Julian Thome
Word Count
2,335
Company Posts That Month
22
Language
English
Hacker News Points
-
Post removed?
No
Summary

In summer 2021, GitLab's Vulnerability Research and Static Analysis teams embarked on a Google Summer of Code (GSoC) project to develop a framework for transitioning from various language-specific Static Application Security Testing (SAST) tools to Semgrep, a language-agnostic SAST tool. This project aimed to reduce the maintenance burden and inflexibility associated with multiple SAST tools by creating Semgrep rule-sets equivalent to existing analyzers, ensuring they produce comparable results. A central rule repository was established to manage these rules and their corresponding test cases, with GitLab CI/CD automating the testing and validation process. The framework facilitated the replacement of the C/C++ analyzer Flawfinder with a Semgrep rule-set, using automated gap analysis to measure and ensure parity between the original tools and the new configurations. This approach enabled the iterative refinement of rules to achieve full coverage and parity, effectively simplifying SAST tool management and enhancing GitLab's vulnerability detection capabilities.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.