Skip to main content
Semgrep is an open-source static analysis tool designed to scan code for security vulnerabilities and code quality issues. CodeRabbit runs Semgrep version 1.170.0.

Configuration

Semgrep uses a YAML-style configuration file. By default, CodeRabbit automatically uses the following files when found in the repository root:
  • semgrep.yml or semgrep.yaml
  • semgrep.config.yml or semgrep.config.yaml
To use a custom file, set reviews.tools.semgrep.config_file in your project’s .coderabbit.yaml file or use the “Reviews → Tools → Semgrep → Config File” field in CodeRabbit’s settings page. The value must be an existing repository-local relative path. CodeRabbit rejects absolute paths, parent-directory traversal (../), URLs, and Semgrep registry shorthands beginning with p/ or r/. If config_file names a rejected or non-existent value, CodeRabbit falls back to discovering one of the supported repository-local default configuration filenames listed above. Due to licensing, CodeRabbit does not ship with the community-created Semgrep rules.
CodeRabbit will only run Semgrep if your repository contains a Semgrep config file. This config must use the default file names, or you must define the path to this file in the .coderabbit.yaml or config UI.

Files

Semgrep will run on the following file types:
  • C/C++ (.c, .cpp, .cc, .cxx, .c++, .h, .hpp, .hh, .hxx, .h++)
  • C# (.cs)
  • Go (.go)
  • Java (.java)
  • JavaScript (.js, .jsx)
  • Kotlin (.kt)
  • Python (.py)
  • TypeScript (.ts)
  • Ruby (.rb)
  • Rust (.rs)
  • PHP (.php)
  • Scala (.scala)
  • Swift (.swift)
  • Terraform (.tf)
  • JSON (.json)