137 results for “topic:semgrep”
Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.
Semgrep Community Edition rules, maintained by Semgrep and the community. Free to use under the Semgrep Rules License.
Define and run pattern-based custom linting rules.
A collection of my Semgrep rules to facilitate vulnerability research.
Semgrep rules for smart contracts based on DeFi exploits
A MCP server for using Semgrep to scan code for security vulnerabilities.
VULNRΞPO - Free vulnerability report generator and repository, end-to-end encrypted! Templates of issues, CWE,CVE,MITRE ATT&CK,PCI DSS, import Nmap/Nessus/Burp/OpenVAS/Bugcrowd/Trivy, Jira export, TXT/JSON/MARKDOWN/HTML/DOCX, attachments, automatic changelog, stats, vulnerability management, bugbounty, local ai/llm, super fast pentest reporting!
A collection of Semgrep rules derived from the OWASP MASTG specifically for Android applications.
Prevent merging of malicious code in pull requests
tool designed for identifying vulnerabilities in open source codebases at scale. It can gather and filter on key repository metrics such as popularity and project size
No description provided.
Focused malicious code detection ruleset, with a high protection-to-noise ratio
Generic SAST Library
Manager of 14 third-party sources comprising approximately 4,000 Semgrep rules 🗂
An extension to use Semgrep inside Burp Suite.
GitHub Actions CI/CD - Master Template & Reusable Workflows Library - Docker Builds, AWS, Python, Terraform, Jenkins, Linting, Security Scanning, Make Builds etc.
This project is deprecated. Use https://github.com/returntocorp/semgrep instead
Semgrep extension for Visual Studio Code
Autogrep automates Semgrep rule generation and filtering by using LLMs to analyze vulnerability patches, enabling automatic creation of high-quality security rules without manual curation.
🌐 Visualize and explore IaC ✒️ Create and share notes in VS Code 🤝 Sync notes and findings in real-time with friends
《深入理解Semgrep》Finding vulnerabilities with Semgrep.
Semgrep rules specific to Frappe Framework
Documentation of Semgrep: a fast, open-source, static analysis tool.
Semgrep-based Policy Controller for Kubernetes
🧪 Correlate Semgrep scans with Python test coverage to prioritize SAST findings and get bug fix suggestions via a self-hosted LLM.
Curation of DevSecOps tools that all work together inside the minimum amount of containers. Just run make exec and read the How To!
Automatically scan new pypi packages for potentially malicious code
xargs for semgrep
MCP Server Semgrep is a [Model Context Protocol](https://modelcontextprotocol.io) compliant server that integrates the powerful Semgrep static analysis tool with AI assistants like Anthropic Claude. It enables advanced code analysis, security vulnerability detection, and code quality improvements directly through a conversational interface.
My custom semgrep rules