3 ms·
Semgrep started off as a “syntactic grep” but has increasingly become more semantic. So if you want to find all calls to foo that have 1 as the first argument,
by ievans 5y ago
Semgrep started off as a “syntactic grep” but has increasingly become more semantic. So if you want to find all calls to foo that have 1 as the first argument, you just search for foo(1) and even things like x = 1; foo(x); will match.
Here’s an elaborate example: https://semgrep.dev/s/ievans:c-dataflow https://semgrep.dev/s/ievans:c-dataflow
- dang 5y agoOk, I've put the word 'semantic' up there so we can not get hung up on title stuff. (Submitted title said "Like Grep but for Code".)
- jhgb 5y agoThat's called "a code walker", isn't it?
- tyingq 5y agoIt does seem potentially good for enforcing standards where the participants are willing. But you can work around it fairly easily. Like the example "python no-prints" rule: https://semgrep.dev/s/sabihb:no-prints https://semgrep.dev/s/sabihb:no-prints Lots of workarounds it wouldn't find, like: import builtins builtins.print("whee")
- sdesol 5y agoI'm guessing the value with the rules system is, you can add new rules easily. So during a code review, if you see somebody using your example, you could create a new rule to catch that. I don't think you can go in with the mindset that it will catch everything, but rather, it's about being able to iterate quickly with your rules.
- tyingq 5y agoSure. I raised it because it keeps using the word "static analysis", which at least wouldn't be fooled by builtins.print(). It's more than grep, for sure, but something less than static analysis tools I've used. And I don't mean that as a knock. It's working across a lot of languages, so I see the tradeoff.