The commercial version of semgrep contains additional rules beyond the FOSS ruleset. We do have access to this as part of our enterprise subscription (I believe, if not we could add it next FY and evaluate it for now).
The task is to examine the benefit of using the commercial ruleset and what would be a suitable policy/default configuration for scanning repos when integrating semgrep into the USD project.
We should look at the rulesets that are based on the target languages/platforms in use at wikimedia and suggest whether they would provide a significant benefit over the FOSS rules.
If we do recommend use of the commercial rulesets, we will need to open a ticket for Legal approval later on.