Skip to content

Conversation

@gabrielanhaia
Copy link
Member

What?

Add comprehensive documentation for the Semgrep security scanning workflow.

Why?

Provide developers with a single reference for:

  • Understanding common security findings
  • How to fix vulnerabilities
  • Running Semgrep locally
  • Ignoring false positives

What's Included

File Purpose
docs/security/semgrep.md Full guide with examples
README.md Link to the new docs

Contents

  • Common findings and fixes (SQL injection, command injection, hardcoded secrets, etc.)
  • Language-specific examples (Kotlin/Java, PHP)
  • Local setup instructions
  • How to ignore false positives
  • CI behavior explanation

Add comprehensive documentation for Semgrep security scanning:
- Common findings and fixes for Kotlin/Java and PHP
- Local setup instructions
- How to ignore false positives
- CI behavior explanation
@gabrielanhaia gabrielanhaia marked this pull request as ready for review January 8, 2026 15:53
@gabrielanhaia gabrielanhaia self-assigned this Jan 8, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants