
Opengrep is an open-source code security engine forked from SemgrepCS (formerly SemgrepOSS).
Opengrep is an open-source code security engine forked from SemgrepCS (formerly SemgrepOSS). It is built for developers and security teams who want static application security testing (SAST) without vendor lock-in, giving them a community-driven alternative for finding security issues in code. What Opengrep does Performs static application security testing (SAST) on source code Provides an open-source alternative to proprietary SAST tools Builds on the codebase originally developed as SemgrepCS (formerly SemgrepOSS) Who uses Opengrep Opengrep is aimed at developers who want to catch security issues in their code before it ships, and at security-minded teams who prefer an open-source engine they can inspect, self-host, and contribute to rather than relying solely on closed-source scanning tools. As an open, forkable project, Opengrep fits into a maker's workflow as a code-level security check that can be run alongside development, giving teams visibility into potential vulnerabilities without depending on a single vendor's roadmap.
