Analysis tools logo
54

Semgrep

A fast, open-source, static analysis tool for finding bugs and enforcing code standards at editor, commit, and CI time. Its rules look like the code you already write; no abstract syntax trees or regex wrestling. Supports 17+ languages.

Github:
    426842682231722019
Workflow integration:
  • Type: cli
    cli
  • Type: service
    service

Official Semgrep Homepage

https://github.com/returntocorp/semgrep

GNU Lesser General Public License v2.1

Maintained

Alternative Tools

  • 94Mega-Linter
  • 1Sonatype
  • 1CodeFactor
  • -1Synopsys
  • -10Checkmarx CxSAST