Coverage in the guardian-default ruleset
Theguardian-default ruleset is based on p/default. Semgrep includes a rule only when the agent can apply a fix or a sanitizer. Rules that lack a reliable fix can cause the agent to rewrite code incorrectly, so Semgrep omits them.
What Guardian scans for
Guardian scans generated files using Semgrep Code, Supply Chain, and Secrets, so findings can cover:- Code vulnerabilities detected by Semgrep Code
- Vulnerable dependencies detected by Semgrep Supply Chain
- Committed credentials detected by Semgrep Secrets