pypi semgrep 1.123.0
Release v1.123.0

latest releases: 1.135.0, 1.134.0, 1.133.0...
3 months ago

1.123.0 - 2025-05-28

Fixed

  • Fixed bug where supply chain reachability rules which match multiple dependencies could produce reachable findings on transitive dependencies even when the actually used direct dependency was not vulnerable. (SC-2088)
  • Fixed documentation to reflect that, for --metrics="auto", pseudoanonymous metrics are sent when the user is logged in. (gh-11028)

Don't miss a new semgrep release

NewReleases is sending notifications on new releases.