Skip to content

Conversation

khorne3
Copy link
Collaborator

@khorne3 khorne3 commented Mar 19, 2025

Preview

Please ensure

  • A subject matter expert (SME) reviews the content
  • A technical writer reviews the content or PR

Copy link

netlify bot commented Mar 19, 2025

Don't forget to add /docs at the end of the deploy preview site URL!

Name Link
🔨 Latest commit dbd6a9f
🔍 Latest deploy log https://app.netlify.com/sites/semgrep-docs-prod/deploys/6814da7a4e591c00087554af
😎 Deploy Preview https://deploy-preview-2037--semgrep-docs-prod.netlify.app
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.

To edit notification comments on pull requests, go to your Netlify site configuration.

@s-santillan
Copy link
Contributor

### CLI

Semgrep displays transitive reachability information in the CLI results as follows:

Copy link
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Is the subsequent content still accurate?

Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I don't think this part is totally settled at this point

@khorne3 khorne3 marked this pull request as ready for review April 25, 2025 19:11
@khorne3 khorne3 requested review from s-santillan and bkettle April 25, 2025 19:12

## Supported languages

Semgrep currently performs transitive reachability analysis for JavaScript projects.
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Do we need to mention the package managers we support here?

Copy link
Contributor

@s-santillan s-santillan left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM! But I have some questions (cc @bkettle who might know more)

  • Are there any special steps to enable this feature, will there be anything in the settings page?
  • How does the user know that Semgrep performed this analysis on their JavaScript repositories? Moving forward, this this type of analysis always "on"?
  • Are there any caveats to this feature, like speed?

Copy link
Contributor

@bkettle bkettle left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

left a few comments! I don't think we want to publish these yet, though; cc @k80kent for coordination on that

### CLI

Semgrep displays transitive reachability information in the CLI results as follows:

Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I don't think this part is totally settled at this point

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

4 participants