source-code-analysis.md (6068B)
1 --- 2 title: "Source Code Analysis" 3 section: "Methodology" 4 sectionSlug: "methodology" 5 sourcePath: "docs/methodology/source-code-analysis.md" 6 sourceUrl: "https://github.com/swisskyrepo/InternalAllTheThings/blob/203bb0c0b290/docs/methodology/source-code-analysis.md" 7 sha: "203bb0c0b290" 8 isIndex: false 9 --- 10 11 # Source Code Analysis 12 13 > Source code analysis is the process of examining and reviewing the code of a software program to identify errors, vulnerabilities, and potential improvements. This can be performed manually by developers or through automated tools that scan the code for issues like security risks, coding standard violations, and performance inefficiencies. 14 15 ## AI Analysis 16 17 * [trailofbits/skills](https://github.com/trailofbits/skills) - Trail of Bits Claude Code skills for security research, vulnerability detection, and audit workflows. 18 19 ```ps1 20 npm install -g @github/copilot 21 copilot 22 /login 23 /model 24 /plugin marketplace add trailofbits/skills 25 /plugin marketplace browse trailofbits 26 /plugin install ask-questions-if-underspecified@trailofbits 27 /plugin install static-analysis@trailofbits 28 /plugin install entry-point-analyzer@trailofbits 29 /plugin install semgrep-rule-creator@trailofbits 30 /plugin install semgrep-rule-variant-creator@trailofbits 31 /plugin install sharp-edges@trailofbits 32 /plugin install insecure-defaults@trailofbits 33 ``` 34 35 ## Semgrep 36 37 > Lightweight static analysis for many languages. Find bug variants with patterns that look like source code. 38 39 **Install**: 40 41 * Binaries: [opengrep/opengrep](https://github.com/opengrep/opengrep) / [semgrep/semgrep](https://github.com/semgrep/semgrep) 42 * Ubuntu/WSL/Linux/macOS: `python3 -m pip install semgrep` 43 * macOS: `brew install semgrep` 44 * Docker 45 46 ```ps1 47 docker run -it -v "${PWD}:/src" semgrep/semgrep semgrep login 48 docker run -e SEMGREP_APP_TOKEN=<TOKEN> --rm -v "${PWD}:/src" semgrep/semgrep semgrep ci 49 ``` 50 51 **Semgrep rules**: 52 53 * [semgrep/semgrep-rules](https://github.com/semgrep/semgrep-rules) - Official Semgrep rules registry 54 * [trailofbits/semgrep-rules](https://github.com/trailofbits/semgrep-rules) - Semgrep queries developed by Trail of Bits 55 * [Decurity/semgrep-smart-contracts)](https://github.com/Decurity/semgrep-smart-contracts) - Semgrep rules for smart contracts based on DeFi exploits 56 * [0xdea/semgrep-rules](https://github.com/0xdea/semgrep-rules) - A collection of Semgrep rules to facilitate vulnerability research. 57 * [elttam/semgrep-rules](https://github.com/elttam/semgrep-rules) - Elttam's public semgrep rules repository. 58 59 **Other Tools**: 60 61 * [Orange-Cyberdefense/grepmarx](https://github.com/Orange-Cyberdefense/grepmarx) - A source code static analysis platform for AppSec enthusiasts, based on semgrep engine. 62 63 ## SonarQube 64 65 > Continuous Inspection 66 67 **Install** 68 69 * Docker 70 71 ```ps1 72 docker run -d --name sonarqube -p 9000:9000 sonarqube:community 73 ``` 74 75 **Configuration** 76 77 * Go to localhost:9000 78 * Login with `admin:admin` 79 * Create a local project 80 * Generate a token for the project 81 * Use `sonar-scanner-cli` with the generated token 82 83 ```ps1 84 docker run --rm -e SONAR_HOST_URL="http://10.10.10.10:9000" -v "/tmp/www:/usr/src" sonarsource/sonar-scanner-cli -Dsonar.projectKey=sonar-project-name -Dsonar.sources=. -Dsonar.host.url=http://10.10.10.10:9000 -Dsonar.token=sqp_redacted 85 ``` 86 87 * Check the Security Hotspots tab: `http://10.10.10.10:9000/security_hotspots?id=sonar-project-name` 88 89 :warning: remove dead symbolic links before scanning a folder. 90 91 ## Psalm 92 93 > A static analysis tool for finding errors in PHP applications 94 95 **Install** 96 97 ```ps1 98 composer require --dev vimeo/psalm 99 ``` 100 101 **Configuration** 102 103 * Create a project and initiate a scan of the codebase 104 105 ```ps1 106 ./vendor/bin/psalm --init 107 ./vendor/bin/psalm --taint-analysis 108 ./vendor/bin/psalm --report=results.sarif 109 ``` 110 111 * Use a Sarif viewer to see the results: [microsoft.github.io/sarif-web-component](https://microsoft.github.io/sarif-web-component/) 112 113 ## CodeQL 114 115 > CodeQL: the libraries and queries that power security researchers around the world, as well as code scanning in GitHub Advanced Security 116 117 **Install**: 118 119 * [github/codeql](https://github.com/github/codeql) 120 121 **Configuration** 122 123 ```ps1 124 codeql resolve packs 125 codeql resolve languages 126 codeql database create <database> --language=<language-identifier> 127 codeql database create --language=python <output-folder>/python-database 128 codeql database create --language=cpp <output-folder>/cpp-database 129 codeql database analyze <database> --format=<format> --output=<output> <query-specifiers>... 130 codeql database analyze /codeql-dbs/example-repo javascript-code-scanning.qls --sarif-category=javascript-typescript --format=sarif-latest --output=/temp/example-repo-js.sarif 131 codeql database analyze <database> microsoft/coding-standards@1.0.0 github/security-queries --format=sarifv2.1.0 --output=query-results.sarif --download 132 ``` 133 134 ## Snyk 135 136 > Snyk CLI scans and monitors your projects for security vulnerabilities. 137 138 **Install** 139 140 * [Snyk Security - Visual Studio](https://marketplace.visualstudio.com/items?itemName=snyk-security.snyk-vulnerability-scanner-vs) 141 * [Snyk Code / Snyk Open Source](https://app.snyk.io) 142 143 ```ps1 144 curl https://static.snyk.io/cli/latest/snyk-linux -o snyk 145 chmod +x ./snyk 146 mv ./snyk /usr/local/bin/ 147 148 docker run -it \ 149 -e "SNYK_TOKEN=<TOKEN>" \ 150 -v "<PROJECT_DIRECTORY>:/project" \ 151 -v "/home/user/.gradle:/home/node/.gradle" \ 152 snyk/snyk:gradle:6.4 test --org=my-org-name 153 ``` 154 155 **Configuration** 156 157 ```ps1 158 snyk auth 159 snyk ignore --file-path=<directory_or_file> 160 snyk code test 161 162 # npm install snyk-to-html -g 163 snyk code test --json | snyk-to-html -o results-opensource.html 164 ``` 165 166 ## References 167 168 * [Code auditing 101 - Rodolphe Ghio - August 2, 2025](https://blog.rodolpheg.xyz/posts/code-auditing--101/) 169 * [Detect PHP security vulnerabilities with Psalm - Matt Brown - June 23, 2020](https://psalm.dev/articles/detect-security-vulnerabilities-with-psalm) 170 * [Security Analysis in Psalm - Official Documentation](https://psalm.dev/docs/security_analysis/)