semgrep_scan_diff
Scan only the lines changed between two git revisions for security and bug patterns, returning exact line numbers and source snippets for actionable code review.
Instructions
Run deterministic static analysis (Semgrep) restricted to the lines changed between two revisions, and return findings with exact line numbers plus the matched source snippet.
Prefer this over semgrep_scan when reviewing a pull request. OpenCodeReview reviews a diff and only permits comments on changed lines, so a finding on an untouched line cannot be reported — this tool does not return those at all, which keeps the result short and entirely actionable.
base and head are any git revisions (abc123, main, HEAD~1). Pass paths to narrow the scan to specific changed files.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| base | Yes | ||
| head | Yes | ||
| paths | No |
Output Schema
| Name | Required | Description | Default |
|---|---|---|---|
| result | Yes |