Robuta

https://semgrep.dev/ Semgrep App Security Platform | AI-assisted SAST, SCA and Secrets Detection An extensible developer-friendly application security platform that scans source code to surface true and actionable security issues with AI-assisted SAST,... app securityplatform aisemgrep https://github.com/semgrep/semgrep GitHub - semgrep/semgrep: Lightweight static analysis for many languages. Find bug variants with... Lightweight static analysis for many languages. Find bug variants with patterns that look like source code. - semgrep/semgrep static analysis https://Semgrep.dev/products/community-edition/ Semgrep Community Edition | Semgrep Semgrep Community Edition is an open source lightweight static analysis engine for source code. Find bug variants across 30+ programming languages using... semgrepcommunityedition https://Semgrep.dev/resources/semgrep-vs-snyk/ Semgrep vs Snyk | Semgrep An extensible developer-friendly application security platform that scans source code to surface true and actionable security issues with AI-assisted SAST,... semgrepvssnyk https://Semgrep.dev/resources/calculator/ Calculator | Semgrep Interactive ROI calculator to discover how Semgrep can save your teams time and money. calculatorsemgrep https://cyber150.com/rooms/semgrep/ Semgrep Demo Room — CYBER 150 CYBER 150 — Vendor Demo Rooms demo roomsemgrepcyber https://semgrep.dev/docs/kb/rules/match-comments Match comments with Semgrep | Semgrep Semgrep's generic pattern matching mode can match comments in code files. matchcommentssemgrep https://semgrep.dev/docs/kb/semgrep-appsec-platform/projects-not-yet-started-sms Why are my projects showing a status of "Not yet started" after I enable Managed Scans? | Semgrep Why are my projects showing a status of "Not yet started" after I enable Managed Scans? https://versalist.com/prompt-library/e1fe14d2-3dd4-40cd-b43c-436d1afec29d Implement Semgrep Tool via MCP Server | AI Prompt Library | Versalist Feb 2, 2026 - Set up a simple MCP server (e.g., using `mcp-server` Python package or a minimal Flask app) that exposes a function to run Semgrep on a given code snippet.... ai prompt librarymcp serverimplementsemgreptool https://semgrep.dev/docs/release-notes/may-2024 May 2024 | Semgrep May 30, 2024 - Release notes include the changes, fixes, and additions in specific versions of Semgrep. maysemgrep https://help.accuknox.com/integrations/semgrep-sast/ Semgrep Integration with Github Actions - Step-by-step guide to integrating Semgrep with AccuKnox for SAST, SCA, and secret scanning in source code repositories. integration with githubsemgrepactions https://semgrep.dev/blog/2026/sap-npm-packages-compromised-in-supply-chain-attack-using-obfuscated-bun-runtime-payload/ SAP Cloud Build Tool Packaged A Mini Shai-Hulud Malicious Dependency That Uses Bun | Semgrep SAP npm Packages Compromised in Supply Chain Attack Using Obfuscated Bun Runtime Payload https://Semgrep.dev/resources/semgrep-vs-checkmarx/ Semgrep vs Checkmarx | Semgrep An extensible developer-friendly application security platform that scans source code to surface true and actionable security issues with AI-assisted SAST,... semgrepvscheckmarx https://www.stackhawk.com/integrations/semgrep/ Semgrep + StackHawk: Unified SAST & DAST for faster fixes Semgrep and StackHawk integrate to correlate code and runtime vulnerabilities, cutting through noise to prioritize real risks to AppSec teams. semgrepstackhawkunifiedsastdast https://semgrep.dev/blog/2024/sca-reachability-analysis-methods/ Comparing Reachability Analysis methods: Semgrep's distinct approach | Semgrep What do people mean exactly when they use the term reachability? As it turns out, there are many distinct approaches to reachability analysis, but not many... reachability analysiscomparingmethodssemgrepdistinct https://semgrep.dev/docs/tags/contributing-to-semgrep One doc tagged with "Contributing to Semgrep" | Semgrep onedoctaggedcontributingsemgrep https://semgrep.dev/events/tecovas-nyc-palo-alto-networks/ Step Into Style: A Private Executive Tecovas Experience | Semgrep An extensible developer-friendly application security platform that scans source code to surface true and actionable security issues with AI-assisted SAST,... step intostyle aprivateexecutivetecovas https://www.pixiebrix.com/integration/semgrep PixieBrix + Semgrep Integration | Browser-Native Workflow PixieBrix connects to Semgrep and brings its capabilities into the tools where teams work every day. Surface relevant data and records anywhere in the browser... semgrepintegrationbrowsernativeworkflow https://semgrep.dev/about/ About | Semgrep Semgrep is an industry leader that is profoundly improving software security and reliability, powering 75M+ source-code security scans. semgrep https://semgrep.dev/blog/2026/security-advisory-pgserve-xinference-kube-health/ Security Advisory: $foo compromised on $packagemanager | Semgrep Malicious packages on NPM and PyPI including pgserve, kube-health-tools, xinference, and more are becoming commonplace. RCA necessitates a security incident... security advisoryfoocompromisedpackagemanagersemgrep https://semgrep.dev/events/security-leaders-dinner-at-black-blue/ Security Leaders Dinner at Black + Blue | Semgrep An extensible developer-friendly application security platform that scans source code to surface true and actionable security issues with AI-assisted SAST,... security leadersblack bluedinnersemgrep https://Semgrep.dev/products/integrations/ Integrations | Semgrep An extensible developer-friendly application security platform that scans source code to surface true and actionable security issues with AI-assisted SAST,... integrationssemgrep https://Semgrep.dev/industry/saas-cloud/ Industry Landing Page - SaaS & Cloud | Semgrep An extensible developer-friendly application security platform that scans source code to surface true and actionable security issues with AI-assisted SAST,... landing pageindustrysaascloudsemgrep https://semgrep.dev/docs/writing-rules/private-rules Private rules | Semgrep Semgrep Code users can publish rules to the Semgrep Registry that are not visible to others outside their organization. This can be useful for organizations... privaterulessemgrep https://www.aikido.dev/blog/sonarqube-vs-semgrep Sonarqube vs Semgrep Comparison | Aikido Security Compare Sonarqube vs Semgrep across key features like ease of use, integration, scanning speed, and coverage. Find out which tool fits your security needs best. vs semgrepsonarqubecomparisonaikidosecurity https://Semgrep.dev/about/careers/ Careers | Semgrep Semgrep is on a mission to make it expensive for attackers to exploit software. Backed by top investors and found on Best Places to Work lists. careerssemgrep https://mas.owasp.org/MASTG/demos/android/MASVS-CODE/MASTG-DEMO-0101/MASTG-DEMO-0101/ MASTG-DEMO-0101: Local Storage for Input Validation with semgrep - OWASP Mobile Application Security https://semgrep.dev/blog/2026/calling-back-to-vm2-and-escaping-sandbox/ New Sandbox Escape Affecting Popular nodejs Sandbox library vm2 | Semgrep Popular Node.js sandboxing library vm2 has just announced a critical vulnerability in their library which allows attackers to bypass their promise sanitization... newsandboxescapeaffectingpopular https://semgrep.dev/docs/semgrep-supply-chain/malicious-dependencies Detect and remove malicious dependencies | Semgrep Learn how Semgrep detects malicious dependencies and enable malicious dependency detection in your Supply Chain scans. detectremovemaliciousdependenciessemgrep https://semgrep.dev/events/trends-in-code-security-what-top-security-teams-do-differently/ Trends in Code Security: What Top Security Teams Do Differently | Semgrep An extensible developer-friendly application security platform that scans source code to surface true and actionable security issues with AI-assisted SAST,... in codetop teamstrendssecuritysemgrep https://semgrep.dev/blog/2026/appsec-in-pole-position-a-week-of-customers-conversations-and-code-security-across-emea/ AppSec in Pole Position: A Week of Customers, Conversations, and Code Security across EMEA | Semgrep Last week, London gave us two back-to-back experiences that reminded us why the work we're doing at Semgrep matters, and who we're doing it for. Two events,... https://semgrep.dev/events/march-26-rsa-technical-workshop/ Vibe Coding and AI Security Primer: From MCP to Mad Skills.md | Semgrep An extensible developer-friendly application security platform that scans source code to surface true and actionable security issues with AI-assisted SAST,... https://semgrep.dev/docs/semgrep-appsec-platform/github-pr-comments GitHub PR comments | Semgrep Enable pull request (PR) comments in your GitHub repositories to display Semgrep findings to developers. githubprcommentssemgrep https://linuxcommandlibrary.com/man/semgrep semgrep man | Linux Command Library semgrep linux command man page: Lightweight static analysis for code security and quality linux commandsemgreplibrary https://semgrep.dev:443/ Semgrep App Security Platform | AI-assisted SAST, SCA and Secrets Detection An extensible developer-friendly application security platform that scans source code to surface true and actionable security issues with AI-assisted SAST,... app securityplatform aisemgrep