https://semgrep.dev/
Semgrep App Security Platform | AI-assisted SAST, SCA and Secrets Detection
An extensible developer-friendly application security platform that scans source code to surface true and actionable security issues with AI-assisted SAST,...
app securityplatform aisemgrep
https://github.com/semgrep/semgrep
GitHub - semgrep/semgrep: Lightweight static analysis for many languages. Find bug variants with...
Lightweight static analysis for many languages. Find bug variants with patterns that look like source code. - semgrep/semgrep
static analysis
https://Semgrep.dev/products/community-edition/
Semgrep Community Edition | Semgrep
Semgrep Community Edition is an open source lightweight static analysis engine for source code. Find bug variants across 30+ programming languages using...
semgrepcommunityedition
https://Semgrep.dev/resources/semgrep-vs-snyk/
Semgrep vs Snyk | Semgrep
An extensible developer-friendly application security platform that scans source code to surface true and actionable security issues with AI-assisted SAST,...
semgrepvssnyk
https://Semgrep.dev/resources/calculator/
Calculator | Semgrep
Interactive ROI calculator to discover how Semgrep can save your teams time and money.
calculatorsemgrep
https://cyber150.com/rooms/semgrep/
Semgrep Demo Room — CYBER 150
CYBER 150 — Vendor Demo Rooms
demo roomsemgrepcyber
https://semgrep.dev/docs/kb/rules/match-comments
Match comments with Semgrep | Semgrep
Semgrep's generic pattern matching mode can match comments in code files.
matchcommentssemgrep
https://semgrep.dev/docs/kb/semgrep-appsec-platform/projects-not-yet-started-sms
Why are my projects showing a status of "Not yet started" after I enable Managed Scans? | Semgrep
Why are my projects showing a status of "Not yet started" after I enable Managed Scans?
https://versalist.com/prompt-library/e1fe14d2-3dd4-40cd-b43c-436d1afec29d
Implement Semgrep Tool via MCP Server | AI Prompt Library | Versalist
Feb 2, 2026 - Set up a simple MCP server (e.g., using `mcp-server` Python package or a minimal Flask app) that exposes a function to run Semgrep on a given code snippet....
ai prompt librarymcp serverimplementsemgreptool
https://semgrep.dev/docs/release-notes/may-2024
May 2024 | Semgrep
May 30, 2024 - Release notes include the changes, fixes, and additions in specific versions of Semgrep.
maysemgrep
https://help.accuknox.com/integrations/semgrep-sast/
Semgrep Integration with Github Actions -
Step-by-step guide to integrating Semgrep with AccuKnox for SAST, SCA, and secret scanning in source code repositories.
integration with githubsemgrepactions
https://semgrep.dev/blog/2026/sap-npm-packages-compromised-in-supply-chain-attack-using-obfuscated-bun-runtime-payload/
SAP Cloud Build Tool Packaged A Mini Shai-Hulud Malicious Dependency That Uses Bun | Semgrep
SAP npm Packages Compromised in Supply Chain Attack Using Obfuscated Bun Runtime Payload
https://Semgrep.dev/resources/semgrep-vs-checkmarx/
Semgrep vs Checkmarx | Semgrep
An extensible developer-friendly application security platform that scans source code to surface true and actionable security issues with AI-assisted SAST,...
semgrepvscheckmarx
https://www.stackhawk.com/integrations/semgrep/
Semgrep + StackHawk: Unified SAST & DAST for faster fixes
Semgrep and StackHawk integrate to correlate code and runtime vulnerabilities, cutting through noise to prioritize real risks to AppSec teams.
semgrepstackhawkunifiedsastdast
https://semgrep.dev/blog/2024/sca-reachability-analysis-methods/
Comparing Reachability Analysis methods: Semgrep's distinct approach | Semgrep
What do people mean exactly when they use the term reachability? As it turns out, there are many distinct approaches to reachability analysis, but not many...
reachability analysiscomparingmethodssemgrepdistinct
https://semgrep.dev/docs/tags/contributing-to-semgrep
One doc tagged with "Contributing to Semgrep" | Semgrep
onedoctaggedcontributingsemgrep
https://semgrep.dev/events/tecovas-nyc-palo-alto-networks/
Step Into Style: A Private Executive Tecovas Experience | Semgrep
An extensible developer-friendly application security platform that scans source code to surface true and actionable security issues with AI-assisted SAST,...
step intostyle aprivateexecutivetecovas
https://www.pixiebrix.com/integration/semgrep
PixieBrix + Semgrep Integration | Browser-Native Workflow
PixieBrix connects to Semgrep and brings its capabilities into the tools where teams work every day. Surface relevant data and records anywhere in the browser...
semgrepintegrationbrowsernativeworkflow
https://semgrep.dev/about/
About | Semgrep
Semgrep is an industry leader that is profoundly improving software security and reliability, powering 75M+ source-code security scans.
semgrep
https://semgrep.dev/blog/2026/security-advisory-pgserve-xinference-kube-health/
Security Advisory: $foo compromised on $packagemanager | Semgrep
Malicious packages on NPM and PyPI including pgserve, kube-health-tools, xinference, and more are becoming commonplace. RCA necessitates a security incident...
security advisoryfoocompromisedpackagemanagersemgrep
https://semgrep.dev/events/security-leaders-dinner-at-black-blue/
Security Leaders Dinner at Black + Blue | Semgrep
An extensible developer-friendly application security platform that scans source code to surface true and actionable security issues with AI-assisted SAST,...
security leadersblack bluedinnersemgrep
https://Semgrep.dev/products/integrations/
Integrations | Semgrep
An extensible developer-friendly application security platform that scans source code to surface true and actionable security issues with AI-assisted SAST,...
integrationssemgrep
https://Semgrep.dev/industry/saas-cloud/
Industry Landing Page - SaaS & Cloud | Semgrep
An extensible developer-friendly application security platform that scans source code to surface true and actionable security issues with AI-assisted SAST,...
landing pageindustrysaascloudsemgrep
https://semgrep.dev/docs/writing-rules/private-rules
Private rules | Semgrep
Semgrep Code users can publish rules to the Semgrep Registry that are not visible to others outside their organization. This can be useful for organizations...
privaterulessemgrep
https://www.aikido.dev/blog/sonarqube-vs-semgrep
Sonarqube vs Semgrep Comparison | Aikido Security
Compare Sonarqube vs Semgrep across key features like ease of use, integration, scanning speed, and coverage. Find out which tool fits your security needs best.
vs semgrepsonarqubecomparisonaikidosecurity
https://Semgrep.dev/about/careers/
Careers | Semgrep
Semgrep is on a mission to make it expensive for attackers to exploit software. Backed by top investors and found on Best Places to Work lists.
careerssemgrep
https://mas.owasp.org/MASTG/demos/android/MASVS-CODE/MASTG-DEMO-0101/MASTG-DEMO-0101/
MASTG-DEMO-0101: Local Storage for Input Validation with semgrep - OWASP Mobile Application Security
https://semgrep.dev/blog/2026/calling-back-to-vm2-and-escaping-sandbox/
New Sandbox Escape Affecting Popular nodejs Sandbox library vm2 | Semgrep
Popular Node.js sandboxing library vm2 has just announced a critical vulnerability in their library which allows attackers to bypass their promise sanitization...
newsandboxescapeaffectingpopular
https://semgrep.dev/docs/semgrep-supply-chain/malicious-dependencies
Detect and remove malicious dependencies | Semgrep
Learn how Semgrep detects malicious dependencies and enable malicious dependency detection in your Supply Chain scans.
detectremovemaliciousdependenciessemgrep
https://semgrep.dev/events/trends-in-code-security-what-top-security-teams-do-differently/
Trends in Code Security: What Top Security Teams Do Differently | Semgrep
An extensible developer-friendly application security platform that scans source code to surface true and actionable security issues with AI-assisted SAST,...
in codetop teamstrendssecuritysemgrep
https://semgrep.dev/blog/2026/appsec-in-pole-position-a-week-of-customers-conversations-and-code-security-across-emea/
AppSec in Pole Position: A Week of Customers, Conversations, and Code Security across EMEA | Semgrep
Last week, London gave us two back-to-back experiences that reminded us why the work we're doing at Semgrep matters, and who we're doing it for. Two events,...
https://semgrep.dev/events/march-26-rsa-technical-workshop/
Vibe Coding and AI Security Primer: From MCP to Mad Skills.md | Semgrep
An extensible developer-friendly application security platform that scans source code to surface true and actionable security issues with AI-assisted SAST,...
https://semgrep.dev/docs/semgrep-appsec-platform/github-pr-comments
GitHub PR comments | Semgrep
Enable pull request (PR) comments in your GitHub repositories to display Semgrep findings to developers.
githubprcommentssemgrep
https://linuxcommandlibrary.com/man/semgrep
semgrep man | Linux Command Library
semgrep linux command man page: Lightweight static analysis for code security and quality
linux commandsemgreplibrary
https://semgrep.dev:443/
Semgrep App Security Platform | AI-assisted SAST, SCA and Secrets Detection
An extensible developer-friendly application security platform that scans source code to surface true and actionable security issues with AI-assisted SAST,...
app securityplatform aisemgrep