Vasilii Ermilov
@ermil0v
Followers
186
Following
316
Media
4
Statuses
168
Senior Security Researcher @semgrep
Joined June 2011
There has been some confusion and misinformation circulating about the recent changes to Semgrep Community Edition. I want to clarify what is, and isn’t, changing. The Semgrep engine license remains LGPL 2.1. Link in 🧵
1
7
15
Happy December, everyone! 🎄🎅 We’re kicking off the month with an exciting lineup of webinars! Check out whats coming up: 🗓️ December 3, 9AM PT: Adaptive Noise Canceling Meets Code Scanning. 👉 RSVP: https://t.co/Q2ZUnPibgO 🗓️ December 5, 9AM PT: How to Swim in The Ocean of
0
2
4
🎉 Big news: @semgrep made the 2025 #Cyber60 List by @FortuneMagazine & @lightspeedvp ! This honor highlights our mission to profoundly improve software security and reliability—and it’s all thanks to our incredible team pushing the boundaries every day. 🚀Huge shoutout to
0
2
7
🚀 Big news for Python devs! Semgrep Code’s latest update brings supercharged Python support with new framework-specific analysis. Now track implicit data flows in Django, FastAPI, Flask, and more! Check out how we're making Python code safer: https://t.co/kPXPAnwzb1
0
2
2
🚨 CONTEST ALERT! 🚨 Want to win 1 of 3 decks of 'Cards Against AppSec' by Tanya Janca? Simply RT this post and make sure you're following us to enter! ⏳ You have 48 hours—good luck! #AppSec #Giveaway #CardsAgainstAppSec
2
36
16
I’ll be speaking at BSides Singapore on September 20!
Catch Vasilii Ermilov @ermil0v as he dives into "Most Common Vulnerabilities in GitHub Actions: Takeaways from Mass Scanning GitHub Repositories for Bounties." 📅 Sept 20, 2024 📍 Lifelong Learning Institute, SG
0
1
2
Security researchers and developers, @semgrep now supports Move on @Aptos with an initial set of security rules. Learn how to get started, report bugs, and help secure the Aptos ecosystem ⤵️ https://t.co/SxkvSPMHvD
5
63
210
We’re excited to share our updated Jira integration! Developers now get AI-generated remediation steps in tickets, making fixing issues easy. Semgrep can now auto-create tickets from high-priority issues, reducing overhead for tracking and triage. More:
0
1
1
New blog post and tool release: plORMbing your Prisma ORM with Time-based Attacks https://t.co/DfUfQR1yJq and https://t.co/eHlEWIRJWc
1
13
48
🚀 Exciting news! Introducing Semgrep Academy: your FREE ticket to mastering AppSec and more! 💻 Enroll now in our on-demand courses and elevate your skills! https://t.co/RsqOTdiVzd
#SemgrepAcademy #FreeCourses #FreeAppSecCourses #Certification #AppSecCertification
0
6
11
What started as an April Fools joke turned into a great demo of Semgrep’s extensibility and scalability when it comes to adding support for new languages. Check out more about our GA support for CodeQL’s query language in @onefiftyman’s blog post: https://t.co/jARqn6Qg8N
semgrep.dev
We're excited to announce that Semgrep now offers GA support for CodeQL's query language.
0
3
8
📢 The Secret’s out! We’re thrilled to share that Semgrep Secrets is available for Public Beta today! Secrets leverages Semantic Analysis in addition to regex and entropy-based validation to detect secrets with high precision. Learn more → https://t.co/1yZ4jsw3cP
0
4
12
@BSidesMunich 👜 Bring your own code and I will help you write Semgrep rules, live at the workshop! ✍ Sign up for my workshop on October 14 if you are interested. https://t.co/4aaN6w79oH
0
3
3
Introduction to Semgrep Assistant - AI-assisted triaging and autofixes for insecure code #Semgrep #SAST #SemgrepProEngine #GPT
https://t.co/iBHOMVU70L
0
1
1
New advisory: Ruby on Rails: Possible XSS via User Supplied Values to redirect_to (CVE-2023-28362)
discuss.rubyonrails.org
Possible XSS via User Supplied Values to redirect_to The redirect_to method in Rails allows provided values to contain characters which are not legal in an HTTP header value. This results in the...
0
5
12
📢 You won't want to miss this webinar on AI & security! Join @clintgibler, founder of @tldrsec and @DanielMiessler, founder of Unsupervised Learning as they discuss the impact AI, ML and LLMs will have on security teams and tools. Save your seat here:
1
7
16