Exercise sec-semgrep — three Semgrep rules that tell a real bug from a look-alike

Write three Semgrep taint rules for the three sinks Injection classes just walked — Java deserialization, JDBC SQL injection and OS command injection — each graded against a true-positive fixture it must catch and a false-positive twin it must ignore. This mirrors the actual job task: a security engineer's rule is only useful once it stops flagging the codebase's safe patterns. It runs on your Mac, not in the browser — Pyodide has no semgrep binary.

~90 minruns locally · uv + pytest 6 checkssec-semgrep

What you're building

The tests are ordinary pytest and ship in the public folder with the starter — read them first; the names below are the check list. Solutions are not published.

Get the repo (once)

Needs git. uv installs the right Python itself, so nothing else is required.

# once, anywhere on your machine
git clone https://github.com/theDocWho/ai-ml-roadmap.git
cd ai-ml-roadmap

No git? Download the ZIP, unzip it, and cd into the unzipped folder instead.

Run it

From the repo root:

# one-time: uv (https://docs.astral.sh/uv/) manages the venv and pins Python ≥ 3.12
cd exercises/sec-semgrep && uv sync && uv run pytest -q

Done when uv run pytest -q prints 6 passed. Rerun after every edit — a Semgrep rule change is instant, no rebuild needed.

The checks

Each pair runs the same rule against its true-positive and false-positive fixture: exactly one finding on the first, exactly zero on the second.

Files

This is self-attestation — the site cannot see your terminal, so the box and the button are you telling The Path the suite went green on your machine.

If you get stuck