On this page
Overview
Opengrep is an open-source SAST engine that finds security issues through semantic code patterns and taint analysis. It was forked from Semgrep and keeps compatibility with existing Semgrep rules while developing its own analysis capabilities.
Features and best fit
Based on official documentation; not hands-on tested · Content checked:
Key features
Reuse existing Semgrep rules and rulesets
Semgrep-compatible rules can be used without rewriting the rule library, while JSON and SARIF outputs make findings portable into CI and security tooling.
Sources: [2]
Combine semantic pattern matching with taint analysis
Beyond text matching, Opengrep understands syntax and tracks tainted data through features such as field assignments, inter-method flow, and higher-order functions.
Sources: [2]
Scan more than 30 languages through one CLI
Supported targets include JavaScript, TypeScript, Python, Go, Java, PHP, C#, Rust, Terraform, and many others through the same opengrep scan workflow.
Sources: [2]
Best fit
Before adoption
Validate compatibility separately from Opengrep-specific behavior
The README identifies Opengrep as a fork of Semgrep v1.100.0. Rule compatibility is a goal, but the CLI and analysis features continue to evolve independently, so identical behavior should not be assumed.
Sources: [2]
Separate stable releases from candidates and alphas
As of September 2026, v1.30.0 is the stable release. v1.30.1-candidate and the 2.0.0 alpha line are prereleases, so production CI is easier to reproduce when pinned to a stable tag.
Sources: [3]
Review LGPL-2.1 obligations for redistribution and modification
The repository is licensed under LGPL-2.1. Check the applicable conditions when redistributing binaries or shipping modified versions as part of another product.
Sources: [4]
Official sources
- [1]opengrep/opengrep repository(2026-09-30)
- [2]Opengrep README(2026-09-30)
- [3]Opengrep v1.30.0 release(2026-09-30)
- [4]Opengrep LGPL-2.1 license(2026-09-30)
Supplemental curator note
Opengrep is useful when teams want to reuse Semgrep rule assets while running an open SAST engine locally or in CI. As of September 2026, v1.30.0 is the stable release; the 1.30.1 candidate and 2.0 alpha line should be evaluated separately as prereleases.
Try it in 3 steps
- 1
Install Opengrep v1.30.0
Use the official installer and pin the stable v1.30.0 release.
curl -fsSL https://raw.githubusercontent.com/opengrep/opengrep/main/install.sh | bash -s -- -v v1.30.0 - 2
Create a minimal rule and target
Create a small local rule that flags JavaScript eval calls and a sample file to scan.
mkdir -p rules code && printf 'rules:\n- id: risky-eval\n pattern: eval(...)\n message: Avoid eval\n languages: [javascript]\n severity: WARNING\n' > rules/demo.yml && printf 'eval(userInput);\n' > code/demo.js - 3
Run the static analysis
Scan the code directory with the local rule. CI workflows can later switch to JSON or SARIF output for integration.
opengrep scan -f rules code
Growth
Growth trends · Last 30 days
3,124 Stars
Trend data is still being collected.
Built with
Categories and tags
Categories
GitHub data
GitHub dataView detailed GitHub data
Related information
Write a related articleShare a guide or use case for this OSS in Markdown. Articles are published after administrator approval.
Explore next
- CodeceptJS4,242 Stars
1 shared tag(s) · 2 shared category(s)
unify Playwright and other E2E engines behind user-perspective
JavaScriptIsteps - Ladle2,989 Stars
1 shared tag(s) · 2 shared category(s)
Develop and share React component states as isolated stories
TypeScript - NUnit2,627 Stars
1 shared tag(s) · 2 shared category(s)
Write .NET fixtures, parameterized tests, and constraint-based assertions in an attribute-driven test framework
C# - fake-indexeddb695 Stars
1 shared tag(s) · 2 shared category(s)
recreate the IndexedDB API in memory for Node.js tests
JavaScript - Argos633 Stars
1 shared tag(s) · 2 shared category(s)
review UI changes by comparing visual diffs for each pull request
TypeScript - RSpec117 Stars
1 shared tag(s) · 2 shared category(s)
describe Ruby behavior with examples, expectations, and test doubles and run it through a CLI
Ruby
Report incorrect information
Tell us if any listing information is incorrect or outdated.