Skip to content

fix: Preserve Semgrep context in diff-only scans - #112

Merged
julio-rocketchat merged 2 commits into
developfrom
fix/semgrep-complete-diff-input
Sep 26, 2026
Merged

julio-rocketchat merged 2 commits into
developfrom
fix/semgrep-complete-diff-input

Conversation

@julio-rocketchat

Copy link
Copy Markdown
Member

Summary

Semgrep now parses complete selected HEAD files in both scan modes. The existing worker post-filter still restricts diff-only reporting to changed lines. Trufflehog continues to receive projected hunks.

Why

Removing enclosing syntax before Semgrep runs can hide matches that depend on function context or dataflow.

Verification

  • Node 22: build, typecheck, lint, configuration validation, and all 620 tests passed.
  • Added a dispatcher regression with different repository and projected-workspace paths.
  • Ran an ephemeral real-Semgrep test: a synthetic rule matched a changed eval call inside its function, but not the projected snippet. Temporary fixtures were removed.
  • Security review covered scanner scope, changed-line filtering, and workspace routing. Gitleaks staged-patch scan passed.

Related but distinct from #80, which addresses annotation end lines.

@julio-rocketchat

Copy link
Copy Markdown
Member Author

CI follow-up: the shared install failure was reproduced in an isolated Node 22 container. With maintainer approval, this branch now uses npm ci instead of deleting the lockfile and resolving a fresh dependency graph. This is the only CI change; GitHub checks are rerunning.

@julio-rocketchat
julio-rocketchat merged commit eafd3d3 into develop Sep 26, 2026
3 checks passed
@github-actions github-actions Bot mentioned this pull request Sep 26, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant