Analysis tools logo
55

Semgrep

A fast, open-source, static analysis tool for finding bugs and enforcing code standards at editor, commit, and CI time. Its rules look like the code you already write; no abstract syntax trees or regex wrestling. Supports 17+ languages.

Github:
    502750272412052019
Workflow integration:
  • Type: cli
    cli
  • Type: service
    service

Official Semgrep Homepage

https://github.com/returntocorp/semgrep

GNU Lesser General Public License v2.1

Maintained

Alternative Tools

  • 97Mega-Linter
  • 1CodeFactor
  • -1Synopsys
  • -2Sonatype
  • -12Checkmarx CxSAST