OSS TanbouSign in with GitHub

Find bugs and policy violations across languages with code-like patterns

About these scores

OSS scale score is an unbounded metric that log-compresses and weights Stars, Watchers, Forks, and Contributors. Discovery score is the current OSS scale score minus the score at discovery. Update pace is commits in the last 30 days, growth momentum is the OSS scale score difference within the recent observation window, and OSS health is a 0–100 rating based on available recency, Community Health, and release data.

Stars
16,867
Primary language
C
License
LGPL-2.1
Repository last updated
Oct 2, 2026
On this page

Overview

Semgrep is a static analysis tool that searches source code with patterns resembling the code being matched. Across more than 30 languages, teams can use the same rules to find variants of known bugs, risky API use, and coding-policy violations during development and in CI.

Features and best fit

Based on official documentation; not hands-on tested · Content checked:

Key features

Search syntax with rules that preserve code shape

Patterns abstract variable names and syntax that plain text search handles poorly. Teams can use published rules or write YAML rules, then run them from the CLI, editors, pre-commit, or CI. The CLI keeps analyzed code local by default.

Sources: [1]

Best fit

Turn a one-time investigation into a repeatable guardrail

It fits teams that need to search a repository for the code shape behind an incident or vulnerability and retain that search in review. Verify matches on a small target, version the rule, and then move it into pre-commit or CI to catch similar changes earlier.

Sources: [1]

Before adoption

Do not treat Community Edition's scope as a security guarantee

Community Edition analyzes within a single function or file and may miss security findings that require cross-function or cross-file data flow. Installing v1.179.0 with pip requires Python 3.10 or newer. If AppSec Platform analysis or CI integration is used, assess accounts, authentication, and code-handling policy separately. GitHub reports LGPL-2.1.

Sources: [1][2][3][4]

Official sources

  1. [1]Semgrep v1.179.0 README(2026-10-04)
  2. [2]Semgrep v1.179.0 CLI package metadata(2026-10-04)
  3. [3]semgrep/semgrep GitHub repository metadata(2026-10-04)
  4. [4]Semgrep v1.179.0 LICENSE(2026-10-04)
Supplemental curator note

Start with a small set of known findings and known misses, then measure false positives and false negatives. Use Community Edition for local single-file checks and evaluate AppSec Platform when security analysis needs cross-function or cross-file context.

Try it in 3 steps

  1. 1

    Create an isolated Python environment

    Using Python 3.10 or newer in a macOS or Linux POSIX shell, create and activate a disposable virtual environment. Continue in the same terminal and working directory.

    python3 -m venv semgrep-demo-env && . semgrep-demo-env/bin/activate
  2. 2

    Install Semgrep 1.179.0

    Install the reviewed CLI release in the virtual environment. This local check needs no account or token.

    python -m pip install "semgrep==1.179.0"
  3. 3

    Scan a local example

    Create a two-line Python file with LF line endings, scan it with the inline rule from the official README, and verify one finding. It sends no target code and changes no external project.

    printf '%s\n' 'def same(value):' ' return value == value' > demo.py && semgrep --json -e '$X == $X' --lang=py demo.py > results.json && python -c 'import json; assert len(json.load(open("results.json"))["results"]) == 1'
Check the official README

Growth

Growth trends · Last 30 days

16,867 Stars

Trend data is still being collected.

Development activity

Last 90 days · weekly

Commits (last 30 days)
82
Open PRs
55

Development activity is still being collected.

Built with

Categories and tags

GitHub data

GitHub dataView detailed GitHub data

GitHub Topics

  • static-analysis
  • static-code-analysis
  • java
  • go
  • sast
  • semgrep
  • r2c
  • c
  • python
  • ruby
  • javascript
  • typescript
Stars
16,867
Forks
1,084
Watchers
119
Open issues
886
Contributors
207
Owner type
Organization
Primary language
C
License
LGPL-2.1
Repository last updated
Oct 2, 2026
Write a related article

Share a guide or use case for this OSS in Markdown. Articles are published after administrator approval.

Report incorrect information

Tell us if any listing information is incorrect or outdated.

After reading this page, do you know what to do next?