Case Study Deskcasestudydesk.com
TransportationSourced

Case Study: Lyft cuts software supply chain noise by 95% with Semgrep

Lyft Case StudySourced & dated by Case Study Desk
Key facts · TL;DR
Company
Lyft
Industry
Transportation
Challenge
Custom rule writing was too time-consuming and SCA tools surfaced too many false positives
Headline result
Lyft reduces supply chain noise 95% and writes custom rules to catch issues specific to its code

Key results

95%
Reduction in supply chain noise
Semgrep Supply Chain

The challenge

Lyft's product security team aimed to scale security by shifting left and catching issues early in the software development lifecycle. Finding issues specific to Lyft's own code was essential to reduce false positives, but the tools the team used before Semgrep made custom rule writing and validation too time-consuming, taking hours per rule.

The solution

Lyft adopted Semgrep for its ease of writing and testing custom rules across all of the languages Lyft uses, and deployed Semgrep Supply Chain to identify and prioritize the dependency updates that matter most. Supply Chain pinpoints the exact location and when vulnerable code was introduced, making fixes and false-positive triage faster.

Semgrep Supply Chain has helped reduce the noise by 95%

KL
Khanh Le-Do
Security Software Engineer, Lyft

The results, in context

Semgrep Supply Chain reduced the noise Lyft's developers see by 95%. The team used reachability rules to identify and remediate all instances of the Log4Shell vulnerability immediately when it was announced, and application security engineers can go days without modifying a custom rule thanks to Semgrep's rule syntax.

Products used

Semgrep Semgrep CodeSemgrep Semgrep Supply Chain