Case Study: Lyft cuts software supply chain noise by 95% with Semgrep
Key results
The challenge
Lyft's product security team aimed to scale security by shifting left and catching issues early in the software development lifecycle. Finding issues specific to Lyft's own code was essential to reduce false positives, but the tools the team used before Semgrep made custom rule writing and validation too time-consuming, taking hours per rule.
The solution
Lyft adopted Semgrep for its ease of writing and testing custom rules across all of the languages Lyft uses, and deployed Semgrep Supply Chain to identify and prioritize the dependency updates that matter most. Supply Chain pinpoints the exact location and when vulnerable code was introduced, making fixes and false-positive triage faster.
“Semgrep Supply Chain has helped reduce the noise by 95%”
KLKhanh Le-DoSecurity Software Engineer, Lyft
The results, in context
Semgrep Supply Chain reduced the noise Lyft's developers see by 95%. The team used reachability rules to identify and remediate all instances of the Log4Shell vulnerability immediately when it was announced, and application security engineers can go days without modifying a custom rule thanks to Semgrep's rule syntax.