Skip to content

Entry

Semgrep

Appears in 4 awesome lists

A fast, open-source, static analysis tool for finding bugs and enforcing code standards at editor, commit, and CI time. Its rules look like the code you already write; no abstract syntax trees or regex wrestling. Supports 17+ languages.

Open semgrep.dev

Found in these lists

Awesome AI Coding Tools

Section: Code Review and Refactoring · Static analysis for finding bugs and security issues.

FreshScore 85

Awesome Devsecops

Section: Static Analysis · r2c - Semgrep is a fast, open-source, static analysis tool that finds bugs and enforces code standards at editor, commit, and CI time.

StaleScore 52

Contents

Section: Static Code Analysis · Open-source, offline, easy-to-customize static analysis for many languages. Some others on this list (NodeJSScan) use semgrep as their engine.

FreshScore 78

Static Analysis

Section: Multiple languages · A fast, open-source, static analysis tool for finding bugs and enforcing code standards at editor, commit, and CI time. Its rules look like the code you already write; no abstract syntax trees or regex wrestling. Supports 17+ languages.

FreshScore 91

Snyk

copyright: — Snyk Code finds security vulnerabilities based on AI. Its speed of analysis allow us to analyse your code in real time and deliver results when you hit the save button in your IDE. Supported languages are Java, JavaScript, Python, PHP, C#, Go and TypeScript. Integrations with GitHub,…

In 14 listsDetails

Codacy

Automated Code Review. Continuous Static Analysis designed to complement your unit tests. Similar to CodeClimate.

In 8 listsDetails

CodeRabbit

copyright: — AI-powered code review tool that helps developers write better code faster. CodeRabbit provides automated code reviews, identifies security vulnerabilities, and suggests code improvements. It integrates with GitHub and GitLab.

In 7 listsDetails

Qodo

AI-powered coding platform for VS Code with testing, code review, and agentic tools.

In 7 listsDetails

Bandit

Python Code Quality Authority - Find common security vulnerabilities in Python code.

In 6 listsDetails

ESLint

JS Foundation - Linting tool for JavaScript with multiple security linting rules available.

In 6 listsDetails

Bearer

Open-Source static code analysis tool to discover, filter and prioritize security risks and vulnerabilities leading to sensitive data exposures (PII, PHI, PD). Highly configurable and easily extensible, built for security and engineering teams.

In 6 listsDetails

SonarQube

SonarQube empowers development teams with a code quality and security solution that deeply integrates into your enterprise environment; enabling you to deploy clean code consistently and reliably. SonarQube provides a free and open source Community Build.

In 6 listsDetails