0
I Use This!
Activity Not Available
Analyzed 11 months ago. based on code collected about 1 year ago.

Project Summary

Semgrep is a fast, open-source, static analysis tool that excels at expressing code standards — without complicated queries — and surfacing bugs early at editor, commit, and CI time. Precise rules look like the code you’re searching; no more traversing abstract syntax trees or wrestling with regexes.

The Semgrep Registry has 900+ rules written by the Semgrep community covering security, correctness, and performance bugs. No need to DIY unless you want to.

Semgrep runs offline, on uncompiled code.

The Semgrep project is led by returntocorp.

Tags

analysis go java javascript json pytho rules sast

GNU Lesser General Public License 2.1
Permitted
Forbidden
Required

These details are provided for information only. No information here is legal advice and should not be used as such.

Project Security

Vulnerabilities per Version ( last 10 releases )

There are no reported vulnerabilities

Project Vulnerability Report

Security Confidence Index

Poor security track-record
Favorable security track-record

Vulnerability Exposure Index

Many reported vulnerabilities
Few reported vulnerabilities

Did You Know...

  • ...
    nearly 1 in 3 companies have no process for identifying, tracking, or remediating known open source vulnerabilities
  • ...
    anyone with an Open Hub account can update a project's tags
  • ...
    55% of companies leverage OSS for production infrastructure
  • ...
    data presented on the Open Hub is available through our API
About Project Security

Languages

C
90%
OCaml
5%
25 Other
5%

30 Day Summary

Mar 9 2024 — Apr 8 2024

12 Month Summary

Apr 8 2023 — Apr 8 2024
  • 3221 Commits
    Up + 503 (18%) from previous 12 months
  • 115 Contributors
    Down 0 (0%) from previous 12 months