Added
- Add an experimental key for internal team use:
r2c-internal-project-depends-on
that
allows rules to filter based on the presence of 3rd-party dependencies at specific
version ranges. - Experimental support for Dockerfile syntax.
- Support nosemgrep comments placed on the line before a match,
causing such match to be ignored (#3521) - Add experimental
semgrep login
andsemgrep logout
to store API token from semgrep.dev - Add experimenntal config key
semgrep --config policy
that uses stored API token to
retrieve configured rule policy on semgrep.dev
Changed
- CLI: parse errors (reported with
--verbose
) appear once per file,
not once per rule/file
Fixed
- Solidity: add support for
for(...)
patterns (#4530)