An open API service indexing awesome lists of open source software.

Projects in Awesome Lists tagged with semgrep

A curated list of projects in awesome lists tagged with semgrep .

https://github.com/semgrep/semgrep

Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.

c go java javascript python r2c ruby sast semgrep static-analysis static-code-analysis typescript

Last synced: 04 Aug 2026

https://github.com/semgrep/semgrep-rules

Semgrep Community Edition rules, maintained by Semgrep and the community. Free to use under the Semgrep Rules License.

grep-like program-analysis security security-scanner semgrep semgrep-registry semgrep-rules static-analysis

Last synced: 11 Jul 2026

https://github.com/quasilyte/go-ruleguard

Define and run pattern-based custom linting rules.

analysis codeql dynamic-rules go go-analysis gogrep golang linter ruleguard semgrep static-analysis

Last synced: 13 May 2025

https://github.com/Decurity/semgrep-smart-contracts

Semgrep rules for smart contracts based on DeFi exploits

defi ethereum security semgrep solidity

Last synced: 10 May 2025

https://github.com/decurity/semgrep-smart-contracts

Semgrep rules for smart contracts based on DeFi exploits

defi ethereum security semgrep solidity

Last synced: 07 Apr 2025

https://github.com/0xdea/semgrep-rules

A collection of my Semgrep rules to facilitate vulnerability research.

code-review semgrep semgrep-rules static-analysis vulnerability-research

Last synced: 04 Apr 2025

https://github.com/0sec-labs/foxguard

A security scanner as fast as a linter, written in Rust. Batteries included, TUI for triage, secrets, post-quantum audits, diff-aware scans and more 𓃥

cli code-security linter opengrep pre-commit rust sarif sast security semgrep static-analysis tree-sitter vulnerability-scanner

Last synced: 02 Jun 2026

https://github.com/PwnKit-Labs/foxguard

A security scanner as fast as a linter, written in Rust. Live in the terminal? It also comes with a TUI triage for secrets, post-quantum audits, diff-scans and more 🦊

cli code-security linter opengrep pre-commit rust sarif sast security semgrep static-analysis tree-sitter vulnerability-scanner

Last synced: 06 May 2026

https://github.com/chebuya/sastsweep

Automatically detect potential vulnerabilities and analyze repository metrics to prioritize open source security research targets

cli owasp sast security-audit security-research security-scanner semgrep static-code-analysis vulnerability-research vulnerability-scanners

Last synced: 12 Jul 2025

https://github.com/gand3lf/semgrepper

An extension to use Semgrep inside Burp Suite.

burpsuite-extension security-scanner semgrep

Last synced: 13 May 2025

https://github.com/semgrep/semgrep-action

This project is deprecated. Use https://github.com/returntocorp/semgrep instead

ci ci-cd github-actions sast semgrep static-analysis

Last synced: 30 Aug 2025

https://github.com/doyensec/poiex

🌐 Visualize and explore IaC ✒️ Create and share notes in VS Code 🤝 Sync notes and findings in real-time with friends

collaborative-editing iac security security-tools semgrep vscode vscode-extension

Last synced: 29 Apr 2025

https://github.com/momenbasel/vulnhawk

AI-powered SAST scanner that finds auth bypass, IDOR, and logic bugs Semgrep/CodeQL miss. Free GitHub Action. Supports Python, JS/TS, Go, PHP, Ruby.

ai appsec claude code-review code-security codeql devsecops github-actions llm owasp php python ruby sarif sast security security-tools semgrep static-analysis vulnerability-scanner

Last synced: 04 Jul 2026

https://github.com/semgrep/semgrep-vscode

Semgrep extension for Visual Studio Code

semgrep visual-studio-code vscode vscode-extension

Last synced: 06 Apr 2025

https://github.com/frappe/semgrep-rules

Semgrep rules specific to Frappe Framework

erpnext frappe-framework lint semgrep

Last synced: 09 Apr 2025

https://github.com/astteam/semgrep

《深入理解Semgrep》Finding vulnerabilities with Semgrep.

0e0w codeql semgrep

Last synced: 05 Jun 2026

https://github.com/semgrep/semgrep-docs

Documentation of Semgrep: a fast, open-source, static analysis tool.

semgrep

Last synced: 04 Apr 2025

https://github.com/icholy/semgrepx

xargs for semgrep

ai golang llm semgrep

Last synced: 17 Aug 2025

https://github.com/avnu-labs/semgrep-cairo-rules

Semgrep rules for Cairo 1.0

cairo cairo-lang semgrep

Last synced: 13 May 2025

https://github.com/ligurio/semgrep-rules

semgrep rules for flakiness, missed error handling, Lua antipatterns and pitfalls.

code-quality error-handling flakiness flaky-tests golang lua non-determinism python semgrep semgrep-rules static-analysis

Last synced: 08 Sep 2025

https://github.com/Szowesgad/mcp-server-semgrep

MCP Server Semgrep is a [Model Context Protocol](https://modelcontextprotocol.io) compliant server that integrates the powerful Semgrep static analysis tool with AI assistants like Anthropic Claude. It enables advanced code analysis, security vulnerability detection, and code quality improvements directly through a conversational interface.

anthropic-claude modelcontextprotocol semgrep

Last synced: 17 Jun 2025

https://github.com/fhpythonutils/simplesecurity

Combine multiple popular python security tools and generate reports or output into different formats

bandit dlint dodgy linting python python-security safety sarif security-report security-tools semgrep simplesecurity static-analysis

Last synced: 11 Apr 2025

https://github.com/parsiya/personal-semgrep-server

Personal Semgrep Server for learning Rust.

rust semgrep

Last synced: 11 Apr 2025

https://github.com/avnu-labs/tree-sitter-cairo

Cairo 1.0 - Tree-Sitter

cairo semgrep

Last synced: 13 May 2025

https://github.com/vinsoc-cyber/vulnhunterx

A Python framework for combining static analysis with LLM-based bug verification

codeql fuzzing llm semgrep static-analysis vulnerability vulnerability-verification

Last synced: 12 Jun 2026

https://github.com/j3ssie/sample-semgrep-ci

Github Action Example with Semgrep SAST

sast semgrep semgrep-action

Last synced: 24 Jul 2025

https://github.com/vyuh-labs/dxkit

Deterministic Stop-gate and code-graph context for AI coding agents: blocks only net-new findings and gives the loop a structural map of the codebase, locally, with no model in the gate.

agentic-development ai-coding-agents brownfield ci-cd claude-code code-quality codeql codex coding-agents developer-tools guardrails loop-engineering nodejs pre-commit-hooks sarif security-scanning semgrep snyk static-analysis typescript

Last synced: 05 Jul 2026

https://github.com/parsiya/semgrep-hotspots

Repository for my Semgrep hot spot rules

semgrep semgrep-rules static-analysis

Last synced: 28 May 2026

https://github.com/ludo-technologies/codescan

Scan any GitHub repo for security issues — risky code, exposed keys, outdated packages

dependency-scanning devsecops gitleaks golang nextjs sast secrets-detection security security-tools semgrep static-analysis trivy

Last synced: 03 Jul 2026

https://github.com/johnsaigle/semgrep-diagnostics.nvim

A Neovim plugin that integrates semgrep with the built-in diagnostic system.

neovim neovim-plugin semgrep static-analysis

Last synced: 12 Apr 2025

https://github.com/ryosukedtomita/devsecops-demo-aws-ecs

GITHUB ACTIONS and devsecops tools document and demo.

aqua devsecops ghalint github-comment github-pages githubactions semgrep trivy

Last synced: 20 Feb 2026

https://github.com/g-wilson/action-semgrep

reviewdog action for semgrep - lightweight static analysis for many languages with rules that look like source code.

reviewdog semgrep

Last synced: 25 Jan 2026

https://github.com/nunenuh/defense-kit

Defensive security toolkit — scan, harden, and monitor your OS, code, repos, and infrastructure. Claude Code skill.

claude-code defense docker gitleaks hardening lynis sast sca security semgrep trivy

Last synced: 04 Apr 2026

https://github.com/semgrep/mcp

[beta] Use Semgrep in LLMs using MCP framework

mcp semgrep

Last synced: 10 Apr 2025

https://github.com/kalebu/gosec-vs-semgrep-benchmark

An oversimplified benchmark between gosec and semgrep tested on go web-frameworks

gosec gosec-vs-semgrep-benchmark semgrep semgrep-registry

Last synced: 01 Apr 2025

https://github.com/itallstartedwithaidea/last-mile

Last Mile 360 — The production-readiness platform for vibe-coded apps. Norton-grade trust. Cloudflare-native. Zero origin servers.

ai-agents cloudflare-workers code-quality devops devsecops production-readiness security semgrep typescript vibe-coding

Last synced: 17 Apr 2026

https://github.com/fazledyn/sastquatch

(Work in progress) Simple static analysis tool based on CodeQL, Semgrep

codeql docker docker-image sast semgrep

Last synced: 15 Feb 2026

https://github.com/iosifache/semgrep-snap

The Semgrep code scanner as a snap 📦

code-scanning semgrep snapcraft

Last synced: 17 Feb 2026

https://github.com/ashutosh0x/aardvark-security-scanner

An AI-powered security scanning system with automated triage, sandbox validation, and patch suggestions. Integrates Semgrep, Bandit, Trivy with LLM analysis for comprehensive vulnerability detection and remediation.

ai automated-patching bandit cybersecurity devsecops docker github-actions go javascript llm openai python sandbox security security-automation security-research security-tools semgrep trivy vulnerability-scanning

Last synced: 13 Apr 2026

https://github.com/alexandre-leng/ai-security-code-validator

MVP of an Open-source AI code security scanner for LLM-generated code. Detect prompt injection, secrets, vulnerable dependencies, and OWASP risks in CI/CD and DevSecOps workflows.

ai-security application-security code-security devsecops llm-security owasp prompt-injection sarif sbom secure-coding semgrep supply-chain-security vulnerability-scanner

Last synced: 11 Jun 2026

https://github.com/allsmog/kuzushi-security-plugin

Autonomous, language-aware security pipeline for Claude Code: builds repo context, then x-ray → PASTA threat model → CVE threat-intel → invariant testing & adversarial threat-hunting. Wires conditional LSP/MCP tooling (tree-sitter, semgrep, CodeQL, Joern); promotes findings to a shared index. Self-contained, no external engine.

claude-code claude-code-plugin codeql devsecops joern sast security semgrep static-analysis threat-intelligence threat-modeling tree-sitter

Last synced: 03 Jun 2026

https://github.com/elveder-ai/project-review-agent

AI agent for code review and analysis of an entire project.

ai code-review code2prompt langchain semgrep

Last synced: 10 May 2026

https://github.com/codebytemirza/LLMgrep

LLMGrep combines the precision of Semgrep's static analysis with the power of Large Language Models to deliver comprehensive security scanning, interactive vulnerability discussions, and intelligent rule generation capabilities.

ai-powered code-analysis code-security docker groq llm llm-applications python security-analysis security-automation security-scanning security-tools semgrep static-analysis static-code-analysis streamlit vulnerability-scanner

Last synced: 15 Jan 2026

https://github.com/s-santillan/semgrep4techwriting

Experimental repository for Semgrep rules specific to technical writing.

semgrep semgrep-rules technical-writing

Last synced: 19 Mar 2026

https://github.com/basel5001/devsecops-pipeline

Complete DevSecOps scanning platform: SAST, SCA, IaC, secrets + AI risk analysis (AWS Bedrock)

aws-bedrock checkov devsecops github-action gitleaks sast security-scanning semgrep trivy

Last synced: 24 Jul 2026

https://github.com/parsiya/semgrep-rs

Rust library crate to interact with Semgrep.

rust semgrep

Last synced: 06 Jun 2026

https://github.com/raeseoklee/scanrail

Developer-first security scan orchestrator for repeatable OSS-backed checks

cli dast devsecops gitleaks golang npm owasp sast security security-scanner semgrep trivy

Last synced: 25 Jul 2026

https://github.com/yashwanth2408/neurocode

🛡️ AI-powered security scanner for automated PR reviews using CodeLlama, Semgrep & Bandit

ai api bandit code-analysis codellama devsecops docker fastapi llm ollama python security security-scanner semgrep webhook

Last synced: 29 Apr 2026

https://github.com/lucasmelin/semgrep-deprecation-demo

How to use Semgrep to automate the work of detecting and fixing deprecations.

bash go semgrep

Last synced: 02 May 2026

https://github.com/nerdy-krishna/securecoder

Installable AI-agent skill bundle for OWASP-driven code scanning, fixing, and secure-build supervision. Multi-host (Claude Code, Cursor, Codex, etc). Distilled from the SCCAP platform. Distributed via skills.sh.

agent-skills asvs claude-code owasp sast secure-coding security semgrep skills-sh

Last synced: 17 May 2026

https://github.com/codebytemirza/llmgrep

LLMGrep combines the precision of Semgrep's static analysis with the power of Large Language Models to deliver comprehensive security scanning, interactive vulnerability discussions, and intelligent rule generation capabilities.

ai-powered code-analysis code-security docker groq llm llm-applications python security-analysis security-automation security-scanning security-tools semgrep static-analysis static-code-analysis streamlit vulnerability-scanner

Last synced: 20 Apr 2026

https://github.com/mehrdoost/devsecops-radar

🛡️ Unify Trivy, Semgrep, Poutine & Zizmor scans into one AI-enhanced, offline-ready dashboard. Track CI/CD security trends, get LLM-powered analysis, and enforce policies — the open-source DevSecOps command center.

ai ai-discovery ai-tools application-security ci-cd cybersecurity cybersecurity-tools dashboard devops-tools devsecops security-tools semgrep trivy vulnerability-managemen

Last synced: 07 Jun 2026

https://github.com/hoeg/semgrep-report

Github action for reporting semgrep findings to PRs

github-actions pull-requests security semgrep

Last synced: 17 Jan 2026

https://github.com/polespurnes/semgrep-json-to-sqlite-parser

A tool to easily parse a Semgrep CLI scan output file into a simple SQLite Database.

cybersecurity parser python semgrep sqlite tool

Last synced: 18 Feb 2026

https://github.com/beadon/ai-security-reviewer

Two-layer AI security review pipeline for npm/JS — automated tool scanning + Claude semantic analysis of what tools cannot catch

claude claude-code code-review devsecops iac-security javascript llm nodejs owasp sast security semgrep supply-chain-security terraform

Last synced: 01 Jun 2026

https://github.com/laugiov/code-safety

Security Engineering reference: taint analysis benchmark comparing Pysa, CodeQL & Semgrep on a controlled Django app (16 OWASP Top 10 cases). Includes CI/CD integration with SARIF, ground truth validation, and enterprise scaling patterns.

appsec benchmark cicd-security codeql devsecops django owasp pysa python sarif sast security semgrep static-analysis taint-analysis vulnerability-detection

Last synced: 25 Apr 2026