Semgrep is a fast, open-source, static analysis tool for finding bugs and enforcing code standards at editor, commit, and CI time. Get started →.
Semgrep analyzes code locally on your computer or in your build environment: code is never uploaded.
Its rules look like the code you already write; no abstract syntax trees, regex wrestling, or painful DSLs. Here's a quick rule for finding Python print() statements, run it online in Semgrep's Playground by clicking the image:
Semgrep rule example for finding Python print() statements

The Semgrep ecosystem includes:
Semgrep - the open-source command line tool at the heart of everything (this project)
Semgrep CI - a specialized Docker image for running Semgrep in CI environments
Semgrep Playground - an online interactive rule builder for writing and sharing rules
Semgrep Registry - 2,000+ community-driven rules covering security, correctness, and performance bugs
Semgrep App - deploy, manage, and monitor Semgrep at scale with free and paid tiers.
Join 100,000 other developers and security engineers already using Semgrep at companies like Chef, Dropbox, Figma, HashiCorp, Snowflake, and Trail of Bits. Also check out tools powered by Semgrep!
Semgrep is developed and commercially supported by r2c, a software security company.
Language support
General availability
C# · Go · Java · JavaScript · JSX · JSON · PHP · Python · Ruby · Scala · TypeScript · TSX