Use VS Code GitHub Copilot Hooks to Run Semgrep in an AEM Project
[OVERVIEW]
This guide explains how to add repository-level agent hooks that run Semgrep after GitHub Copilot Agent performs a tool action. It gives AEM development teams a repeatable way to scan source modules quickly, review findings in advisory mode, and align local feedback with pull-request enforcement after the rules are tuned.
[IMPACT]
This should help to enforce and catch the security vulnerabilities and any other anti patterns that we would want to avoid in the AEM implementation. Which should definitely help in the overall quality of the code being delivered.
[LESSONS]
The Semgrep rules included here are intended as a starter pack and should be reviewed, refined, and expanded to align with your project's requirements and security standards. This exercise also highlights the power of GitHub Copilot Hooks and how they can be used alongside GitHub Copilot Skills to automate project-specific validation, security checks, and development workflows.
[TRYABLE]
1. Copilot Agent creates or edits project files.
2. VS Code fires the PostToolUse github copilot hook.
3. The hook invokes a repository-owned runner script.
4. The runner scans selected AEM source modules with local Semgrep rules.
5. Findings are printed in the agent debug log and saved as JSON for review.
6. After tuning, ERROR findings can return a nonzero status and block the workflow.
[SETUP]
Prerequisites
- VS Code with GitHub Copilot Chat and Agent mode available.
- Agent Hooks permitted by your organization and workspace trust policy.
- Semgrep CLI available on the developer workstation or development container.
- Python 3 for the portable wrapper scripts in this guide.
- An AEM Maven project, commonly created from the AEM Project Archetype.
- jq is optional. The supplied scripts do not require it.
```bash
semgrep --version
python --version
mvn --version
```
Installation example
```bash
python -m pip install semgrep
```
Repository layout
```text
.github/
hooks/
aem-semgrep.json
scripts/
run-semgrep-aem.py
semgrep-rules/
aem-java.yml
aem-clientlib.yml
aem-secrets.yml
.semgrepignore
.semgrep.yml
core/
ui.apps/
ui.config/
ui.frontend/
```
Keep hook configuration, scripts, and custom rules in source control so developers and CI use the same policy. Do not put credentials or Semgrep tokens in the hook file.
4. Semgrep configuration
Rule directory: semgrep-rules/
Run all local YAML-defined rules from the directory:
```bash
semgrep scan --config semgrep-rules PATH/TO/SOURCE
```
Ignore generated and third-party content: .semgrepignore
```text
target/
**/target/
node_modules/
**/node_modules/
ui.apps/target/
ui.content/target/
all/target/
dispatcher/target/
**/generated/
**/dist/
**/coverage/
**/*.min.js
```
If your AEM repository uses different module names, update the scan paths in the runner script. Do not scan Maven build output, npm dependencies, compiled client libraries, or generated packages.
[SAMPLE_OUTPUT]
https://gist.github.com/narendragandhi/76ee861ac6957eba15a126f02f0cf503
