0
I Use This!
Very High Activity
Analyzed 10 days ago. based on code collected 12 days ago.

Project Summary

Semgrep is a fast, open-source, static analysis tool that excels at expressing code standards — without complicated queries — and surfacing bugs early at editor, commit, and CI time. Precise rules look like the code you’re searching; no more traversing abstract syntax trees or wrestling with regexes.

The Semgrep Registry has 900+ rules written by the Semgrep community covering security, correctness, and performance bugs. No need to DIY unless you want to.

Semgrep runs offline, on uncompiled code.

The Semgrep project is led by returntocorp.

Tags

analysis go java javascript json pytho rules sast

GNU Lesser General Public License 2.1
Permitted
Forbidden
Required

These details are provided for information only. No information here is legal advice and should not be used as such.

Project Security

Vulnerabilities per Version ( last 10 releases )

There are no reported vulnerabilities

Project Vulnerability Report

Security Confidence Index

Poor security track-record
Favorable security track-record

Vulnerability Exposure Index

Many reported vulnerabilities
Few reported vulnerabilities

Did You Know...

  • ...
    there are over 3,000 projects on the Open Hub with security vulnerabilities reported against them
  • ...
    you can embed statistics from Open Hub on your site
  • ...
    in 2016, 47% of companies did not have formal process in place to track OS code
  • ...
    search using multiple tags to find exactly what you need
About Project Security

Languages

C
90%
OCaml
5%
24 Other
5%

30 Day Summary

Mar 9 2024 — Apr 8 2024

12 Month Summary

Apr 8 2023 — Apr 8 2024
  • 2796 Commits
    Up + 78 (2%) from previous 12 months
  • 105 Contributors
    Down -10 (8%) from previous 12 months