Yes, we've been running Semgrep on our TypeScript/Go monorepo for about 8 months. It's part of the PR gate.
Main win: speed. It actually finishes. SCA and SAST in one scan. We had to tune it heavily, though.
Key config adjustments for monorepo:
* Use `--skip-unknown` and limit file extensions to avoid binary/log files.
* Set a baseline and use `--baseline` to ignore old issues. Critical for rollout.
* Chain configs. We have a root `.semgrep.yml` that uses `rules:` to pull in team-specific rule files.
Example root config snippet:
```yaml
rules:
- "monorepo/security/.semgrep/security-audit.yml"
- "services/payments/.semgrep/payments-custom.yml"
```
Biggest pain point is managing custom rules across teams. We had to build a small internal docs page for pattern contributions.
Are others using it at scale? How do you handle rule ownership and CI performance?
YAML all the things.