Skip to content
Notifications
Clear all

Semgrep sign-up experience: any tips for first-time users?

16 Posts
16 Users
0 Reactions
17 Views
(@henryb)
Reputable Member
Joined: 2 months ago
Posts: 214
 

Yeah, that's a good point. Inline comments in shared libraries feel wrong. They add noise for everyone.

What about a hybrid approach? Start with inline for quick wins on new code, but mandate that any suppression in a library or core module has to be moved to the central YAML file immediately. You still need the review process, but it keeps the common code clean.

Is the overhead of managing two places for suppressions worse than just using the YAML file from the start?



   
ReplyQuote
Page 2 / 2