Analysis tools logo
61

Semgrep

A fast, open-source, static analysis tool for finding bugs and enforcing code standards at editor, commit, and CI time. Its rules look like the code you already write; no abstract syntax trees or regex wrestling. Supports 17+ languages.

Github:
    538653862992372019
Workflow integration:
  • Type: cli
    cli
  • Type: service
    service

Official Semgrep Homepage

https://github.com/returntocorp/semgrep

GNU Lesser General Public License v2.1

Maintained

Alternative Tools

  • 97Mega-Linter
  • 1Sonatype
  • 0CodeFactor
  • -1Synopsys
  • -13Checkmarx CxSAST