Semgrep
A fast, open-source, static analysis tool for finding bugs and enforcing code standards at editor, commit, and CI time. Its rules look like the code you already write; no abstract syntax trees or regex wrestling. Supports 17+ languages.
- from
- Static Analysis & Code Quality, DevSecOps
- added
- 2026-10-10
- likes
- 0
similar
-
ast-grep ast-grep.github.io
ast-grep is a powerful tool designed for managing code at scale using Abstract Syntax Trees (AST). Think of it as a hybrid of grep, eslint, and codemod, with the ability to search, lint, and rewrite code based on its structure rather than plain text. It supports multiple…
-
Semgrep Academy academy.semgrep.dev
Semgrep - Free, on-demand courses covering topics including API security, secure coding and application security.
-
tumillanino/semgrep.nvim github.com
Lightweight Semgrep static analysis integration to catch bugs and vulnerabilities.
-
Semgrep Supply Chain semgrep.dev
copyright: — Quickly find and remediate high-priority security issues. Semgrep Supply Chain prioritizes the 2% of vulnerabilities that are reachable from your code.
-
Scanmycode CE (Community Edition) github.com
Code Scanning/SAST/Static Analysis/Linting using many tools/Scanners with One Report. Currently supports: PHP, Java, Scala, Python, Ruby, Javascript, GO, Secret Scanning, Dependency Confusion, Trojan Source, Open Source and Proprietary Checks (total ca. 1000 checks)
-
Static Analysis & Code Quality › Multiple languages: “A fast, open-source, static analysis tool for finding bugs and enforcing code standards at editor, commit, and CI time. Its rules look like the code you already write; no abstract syntax trees or regex wrestling. Supports 17+ languages.”
DevSecOps › Tools > Static Analysis > Multi-Language Support: “r2c - Semgrep is a fast, open-source, static analysis tool that finds bugs and enforces code standards at editor, commit, and CI time.”