Skip to content
Notifications
Clear all

Anyone actually using Semgrep in production for a monorepo?

1 Posts
1 Users
0 Reactions
14 Views
(@chrisg)
Honorable Member
Joined: 3 months ago
Posts: 431
Topic starter   [#10274]

Yes, we've been running Semgrep on our TypeScript/Go monorepo for about 8 months. It's part of the PR gate.

Main win: speed. It actually finishes. SCA and SAST in one scan. We had to tune it heavily, though.

Key config adjustments for monorepo:

* Use `--skip-unknown` and limit file extensions to avoid binary/log files.
* Set a baseline and use `--baseline` to ignore old issues. Critical for rollout.
* Chain configs. We have a root `.semgrep.yml` that uses `rules:` to pull in team-specific rule files.

Example root config snippet:
```yaml
rules:
- "monorepo/security/.semgrep/security-audit.yml"
- "services/payments/.semgrep/payments-custom.yml"
```

Biggest pain point is managing custom rules across teams. We had to build a small internal docs page for pattern contributions.

Are others using it at scale? How do you handle rule ownership and CI performance?


YAML all the things.


   
Quote