On this page
Overview
Semgrep is a static analysis tool that searches source code with patterns resembling the code being matched. Across more than 30 languages, teams can use the same rules to find variants of known bugs, risky API use, and coding-policy violations during development and in CI.
Features and best fit
Based on official documentation; not hands-on tested · Content checked:
Key features
Search syntax with rules that preserve code shape
Patterns abstract variable names and syntax that plain text search handles poorly. Teams can use published rules or write YAML rules, then run them from the CLI, editors, pre-commit, or CI. The CLI keeps analyzed code local by default.
Sources: [1]
Best fit
Turn a one-time investigation into a repeatable guardrail
It fits teams that need to search a repository for the code shape behind an incident or vulnerability and retain that search in review. Verify matches on a small target, version the rule, and then move it into pre-commit or CI to catch similar changes earlier.
Sources: [1]
Before adoption
Do not treat Community Edition's scope as a security guarantee
Community Edition analyzes within a single function or file and may miss security findings that require cross-function or cross-file data flow. Installing v1.179.0 with pip requires Python 3.10 or newer. If AppSec Platform analysis or CI integration is used, assess accounts, authentication, and code-handling policy separately. GitHub reports LGPL-2.1.
Official sources
- [1]Semgrep v1.179.0 README(2026-10-04)
- [2]Semgrep v1.179.0 CLI package metadata(2026-10-04)
- [3]semgrep/semgrep GitHub repository metadata(2026-10-04)
- [4]Semgrep v1.179.0 LICENSE(2026-10-04)
Supplemental curator note
Start with a small set of known findings and known misses, then measure false positives and false negatives. Use Community Edition for local single-file checks and evaluate AppSec Platform when security analysis needs cross-function or cross-file context.
Try it in 3 steps
- 1
Create an isolated Python environment
Using Python 3.10 or newer in a macOS or Linux POSIX shell, create and activate a disposable virtual environment. Continue in the same terminal and working directory.
python3 -m venv semgrep-demo-env && . semgrep-demo-env/bin/activate - 2
Install Semgrep 1.179.0
Install the reviewed CLI release in the virtual environment. This local check needs no account or token.
python -m pip install "semgrep==1.179.0" - 3
Scan a local example
Create a two-line Python file with LF line endings, scan it with the inline rule from the official README, and verify one finding. It sends no target code and changes no external project.
printf '%s\n' 'def same(value):' ' return value == value' > demo.py && semgrep --json -e '$X == $X' --lang=py demo.py > results.json && python -c 'import json; assert len(json.load(open("results.json"))["results"]) == 1'
Growth
Growth trends · Last 30 days
16,867 Stars
Trend data is still being collected.
Development activity
Last 90 days · weekly
- Commits (last 30 days)
- 82
- Open PRs
- 55
Development activity is still being collected.
Built with
Categories and tags
Categories
GitHub data
GitHub dataView detailed GitHub data
GitHub Topics
- static-analysis
- static-code-analysis
- java
- go
- sast
- semgrep
- r2c
- c
- python
- ruby
- javascript
- typescript
Related information
Write a related articleShare a guide or use case for this OSS in Markdown. Articles are published after administrator approval.
Explore next
- JumpServer31,708 Stars
2 shared tag(s) · 1 shared category(s)
centralize privileged access to SSH, RDP, Kubernetes, and databases in one PAM platform
Python - SonarQube Community Build11,044 Stars
2 shared tag(s) · 1 shared category(s)
Continuously verify bugs, vulnerabilities, maintainability, and coverage with static analysis and Quality Gates in an open-source code-verification server
Java - MasterHttpRelayVPN3,935 Stars
2 shared tag(s) · 1 shared category(s)
Understand it as an experimental HTTP/SOCKS relay stack where a local proxy forwards traffic through services such as Google Apps Script
Python - Heliox-OS66 Stars
2 shared tag(s) · 1 shared category(s)
Control an existing OS through natural language, voice, and gestures while routing real actions through permissions, approvals, and verification
Python - FreeIPA1,288 Stars
2 shared tag(s)
centralize Linux identity and access with LDAP, Kerberos, PKI, DNS, sudo, and access-control policy
Python - libsodium13,973 Stars
1 shared tag(s) · 2 shared category(s) · Same language
A portable cryptography library for encryption, signatures, and password hashing through approachable APIs
C
Report incorrect information
Tell us if any listing information is incorrect or outdated.