OSS Tanbou

scan 30+ languages for security issues with Semgrep-compatible rules

About these scores

OSS scale score is an unbounded metric that log-compresses and weights Stars, Watchers, Forks, and Contributors. Discovery score is the current OSS scale score minus the score at discovery. Update pace is commits in the last 30 days, growth momentum is the OSS scale score difference within the recent observation window, and OSS health is a 0–100 rating based on available recency, Community Health, and release data.

Stars
3,124
Primary language
OCaml
License
LGPL-2.1
Repository last updated
Sep 30, 2026
On this page

Overview

Opengrep is an open-source SAST engine that finds security issues through semantic code patterns and taint analysis. It was forked from Semgrep and keeps compatibility with existing Semgrep rules while developing its own analysis capabilities.

Features and best fit

Based on official documentation; not hands-on tested · Content checked:

Key features

Reuse existing Semgrep rules and rulesets

Semgrep-compatible rules can be used without rewriting the rule library, while JSON and SARIF outputs make findings portable into CI and security tooling.

Sources: [2]

Combine semantic pattern matching with taint analysis

Beyond text matching, Opengrep understands syntax and tracks tainted data through features such as field assignments, inter-method flow, and higher-order functions.

Sources: [2]

Scan more than 30 languages through one CLI

Supported targets include JavaScript, TypeScript, Python, Go, Java, PHP, C#, Rust, Terraform, and many others through the same opengrep scan workflow.

Sources: [2]

Best fit

Fits AppSec and DevSecOps teams adding SAST to local and CI workflows

It is relevant when developers should test rules locally and carry the same scanner into CI, differential analysis, and SARIF-based review systems.

Sources: [2][3]

Before adoption

Validate compatibility separately from Opengrep-specific behavior

The README identifies Opengrep as a fork of Semgrep v1.100.0. Rule compatibility is a goal, but the CLI and analysis features continue to evolve independently, so identical behavior should not be assumed.

Sources: [2]

Separate stable releases from candidates and alphas

As of September 2026, v1.30.0 is the stable release. v1.30.1-candidate and the 2.0.0 alpha line are prereleases, so production CI is easier to reproduce when pinned to a stable tag.

Sources: [3]

Review LGPL-2.1 obligations for redistribution and modification

The repository is licensed under LGPL-2.1. Check the applicable conditions when redistributing binaries or shipping modified versions as part of another product.

Sources: [4]

Official sources

  1. [1]opengrep/opengrep repository(2026-09-30)
  2. [2]Opengrep README(2026-09-30)
  3. [3]Opengrep v1.30.0 release(2026-09-30)
  4. [4]Opengrep LGPL-2.1 license(2026-09-30)
Supplemental curator note

Opengrep is useful when teams want to reuse Semgrep rule assets while running an open SAST engine locally or in CI. As of September 2026, v1.30.0 is the stable release; the 1.30.1 candidate and 2.0 alpha line should be evaluated separately as prereleases.

Try it in 3 steps

  1. 1

    Install Opengrep v1.30.0

    Use the official installer and pin the stable v1.30.0 release.

    curl -fsSL https://raw.githubusercontent.com/opengrep/opengrep/main/install.sh | bash -s -- -v v1.30.0
  2. 2

    Create a minimal rule and target

    Create a small local rule that flags JavaScript eval calls and a sample file to scan.

    mkdir -p rules code && printf 'rules:\n- id: risky-eval\n pattern: eval(...)\n message: Avoid eval\n languages: [javascript]\n severity: WARNING\n' > rules/demo.yml && printf 'eval(userInput);\n' > code/demo.js
  3. 3

    Run the static analysis

    Scan the code directory with the local rule. CI workflows can later switch to JSON or SARIF output for integration.

    opengrep scan -f rules code
Check the official README

Growth

Growth trends · Last 30 days

3,124 Stars

Trend data is still being collected.

Built with

Categories and tags

GitHub data

GitHub dataView detailed GitHub data
Stars
3,124
Forks
268
Watchers
26
Open issues
97
Owner type
Organization
Primary language
OCaml
License
LGPL-2.1
Repository last updated
Sep 30, 2026
Write a related article

Share a guide or use case for this OSS in Markdown. Articles are published after administrator approval.

Report incorrect information

Tell us if any listing information is incorrect or outdated.

After reading this page, do you know what to do next?