logo

Using Semgrep with Jupyter Notebook files

ID: 28ee777c-ce92-5b7e-87f3-2934a7df4ef4

STIX ID: report--28ee777c-ce92-5b7e-87f3-2934a7df4ef4

Feed Name: NCC Research

Threat Score
20/100

Date Published: 2025-12-02

Date Updated: 2026-08-02

ADMIRALTY:B6
...
...

This report explains using Semgrep's experimental extract mode (with a newly added 'transform' option) to convert Jupyter Notebook JSON "source" arrays into Python for static analysis, enabling detection of vulnerabilities embedded in .ipynb files—illustrated by finding unsafe use of pickle deserialization—and provides an example extraction rule and command-line usage while noting the feature is experimental.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.