Packages
In addition to thesemgrep binary, the semgrep/semgrep:latest docker image contains the following packages:
bashjqcurl- Python 3.11 (
alpine:3.22base image)
docker run alpine:3.22 apk list.
Previous incidents
- Semgrep v.1.66.0 removed
bash,jq, andcurlto reduce the attack surface of the Semgrep docker image. They were subsequently re-added for future Semgrep releases.