Content Deep Dive
Announcing Semgrep's general availability support of PHP
Blog post from Semgrep
Post Details
Company
Date Published
Author
Pablo Estrada
Word Count
215
Language
English
Hacker News Points
-
Summary
PHP is now fully supported in Semgrep, reaching a parse rate of over 99.9%, thanks largely to contributions from Sjoerd Langkemper, who played a crucial role in integrating PHP support and enhancing C# capabilities. The Semgrep community has developed over 40 PHP rules in the Registry, including those targeting SQL injection in Laravel, and Federico Dotta has contributed additional rules focused on PHP security assessments, specifically SQL injection, Cross-Site Scripting, and authorization bypass. To utilize Semgrep for PHP code scanning, users can integrate it with GitHub or GitLab projects for automated checks on pull or merge requests and run the command line tool with Semgrep v0.99.0 or higher.