AI-assisted development is changing how security issues surface in production code. This session provides a technical deep dive into how Semgrep works inside real engineering workflows to identify, triage, prioritize, and remediate vulnerabilities.
In this hands-on workshop, we will walk through AI Detection in depth, with a focus on implementation details and practical application.
We will demonstrate:
AI Detection for complex vulnerability classes such as IDOR and logic flaws
Organization-aware detection using Memories and internal documentation
Context-based prioritization and AI-driven file risk scoring
AI-assisted remediation, including multi-file fixes and draft PR generation
Upgrade Guidance for safe dependency updates without breaking builds
This session is demo-driven and technical. The goal is to show how these systems work together in practice to reduce false positives, surface higher-signal findings, and accelerate secure remediation.