Analysis tools logo
62

Semgrep

A fast, open-source, static analysis tool for finding bugs and enforcing code standards at editor, commit, and CI time. Its rules look like the code you already write; no abstract syntax trees or regex wrestling. Supports 17+ languages.

Github:
    560156012972532019
Workflow integration:
  • Type: cli
    cli
  • Type: service
    service

Official Semgrep Homepage

https://github.com/returntocorp/semgrep

GNU Lesser General Public License v2.1

Maintained

Alternative Tools

  • 98Mega-Linter
  • 2Codiga
  • 1Sonatype
  • 0CodeFactor
  • -13Checkmarx CxSAST