diff --git a/requirements/dev.in b/requirements/dev.in index d9f61d71f4..6ae065efaa 100644 --- a/requirements/dev.in +++ b/requirements/dev.in @@ -62,7 +62,7 @@ cairosvg python-debian # Pattern-based lint tool -semgrep<1.38.0 # https://github.com/returntocorp/semgrep/issues/8669 +semgrep # Contains Pysa, a security-focused static analyzer pyre-check diff --git a/tools/lint b/tools/lint index dcd3e53fa9..f992b894a8 100755 --- a/tools/lint +++ b/tools/lint @@ -180,17 +180,18 @@ def run() -> None: semgrep_command = [ "semgrep", - "--config=./tools/semgrep.yml", + "scan", + "--scan-unknown-extensions", "--error", "--disable-version-check", "--quiet", ] linter_config.external_linter( "semgrep-py", - [*semgrep_command, "--lang=python"], + [*semgrep_command, "--config=./tools/semgrep-py.yml"], ["py"], fix_arg="--autofix", - description="Syntactic grep (semgrep) code search tool (config: ./tools/semgrep.yml)", + description="Syntactic grep (semgrep) code search tool (config: ./tools/semgrep-py.yml)", ) linter_config.external_linter( diff --git a/tools/semgrep.yml b/tools/semgrep-py.yml similarity index 100% rename from tools/semgrep.yml rename to tools/semgrep-py.yml