SecuriTEA & Crumpets is a series where security professionals come together to talk about their background, research, and interesting topics. The ninth episode welcomes Clint Gibler. Clint has a Ph.D. in computer science from UCDavis, Clint has worked as a Software Security engineer, consultant and was the research and technical director at the NCC Group. Clint is currently the Head of security research at r2c which developers a very popular static analysis tool Semgrep. Clint is the co-founder of the tl;dr newsletter which aggregates and distills the best content for security tools, blogs which helps you do your job better and faster! In this episode Clint talks about how to use Semgrep!
00:00 intro
00:36 What is static analysis?
01:20 What is Semgrep?
03:10 Semgrep is opensource/github
03:30 Semgrep.dev
04:50 Security checks
06:50 GitLab now supports Semgrep
09:30 Running a simple rule
12:43 Semgrep rule writing 101
19:48 Combining patterns
24:30 Meta variables (track user inputs)
32:06 How is whitespace handled?
36:05 Go code example
39:19 History of Semgrep
42:57 Blog post on how to eradicate logging sensitive information using semgrep queries
47:19 Configs to integrating Github actions, and CI/CD
48:44 Community free tier of Semgrep
50:38 Run rules to cover many projects
55:55 Using Semgrep with the CLI
References:
https://semgrep.dev
https://tldrsec.com