Projects in Awesome Lists tagged with semgrep
A curated list of projects in awesome lists tagged with semgrep .
https://github.com/semgrep/semgrep
Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.
c go java javascript python r2c ruby sast semgrep static-analysis static-code-analysis typescript
Last synced: 04 Aug 2026
https://github.com/semgrep/semgrep-rules
Semgrep Community Edition rules, maintained by Semgrep and the community. Free to use under the Semgrep Rules License.
grep-like program-analysis security security-scanner semgrep semgrep-registry semgrep-rules static-analysis
Last synced: 11 Jul 2026
https://github.com/quasilyte/go-ruleguard
Define and run pattern-based custom linting rules.
analysis codeql dynamic-rules go go-analysis gogrep golang linter ruleguard semgrep static-analysis
Last synced: 13 May 2025
https://github.com/0xdea/semgrep-rules
A collection of my Semgrep rules to facilitate vulnerability research.
code-review semgrep semgrep-rules static-analysis vulnerability-research
Last synced: 04 Apr 2025
https://github.com/0sec-labs/foxguard
A security scanner as fast as a linter, written in Rust. Batteries included, TUI for triage, secrets, post-quantum audits, diff-aware scans and more 𓃥
cli code-security linter opengrep pre-commit rust sarif sast security semgrep static-analysis tree-sitter vulnerability-scanner
Last synced: 02 Jun 2026
https://github.com/PwnKit-Labs/foxguard
A security scanner as fast as a linter, written in Rust. Live in the terminal? It also comes with a TUI triage for secrets, post-quantum audits, diff-scans and more 🦊
cli code-security linter opengrep pre-commit rust sarif sast security semgrep static-analysis tree-sitter vulnerability-scanner
Last synced: 06 May 2026
https://github.com/chebuya/sastsweep
Automatically detect potential vulnerabilities and analyze repository metrics to prioritize open source security research targets
cli owasp sast security-audit security-research security-scanner semgrep static-code-analysis vulnerability-research vulnerability-scanners
Last synced: 12 Jul 2025
https://github.com/ajinabraham/libsast
Generic SAST Library
appsec codeanalysis genericsast libsast patternmatch regex sast security semanticgrep semgrep static-analyzer staticanalysis
Last synced: 05 Apr 2025
https://github.com/gand3lf/semgrepper
An extension to use Semgrep inside Burp Suite.
burpsuite-extension security-scanner semgrep
Last synced: 13 May 2025
https://github.com/semgrep/semgrep-action
This project is deprecated. Use https://github.com/returntocorp/semgrep instead
ci ci-cd github-actions sast semgrep static-analysis
Last synced: 30 Aug 2025
https://github.com/doyensec/poiex
🌐 Visualize and explore IaC ✒️ Create and share notes in VS Code 🤝 Sync notes and findings in real-time with friends
collaborative-editing iac security security-tools semgrep vscode vscode-extension
Last synced: 29 Apr 2025
https://github.com/momenbasel/vulnhawk
AI-powered SAST scanner that finds auth bypass, IDOR, and logic bugs Semgrep/CodeQL miss. Free GitHub Action. Supports Python, JS/TS, Go, PHP, Ruby.
ai appsec claude code-review code-security codeql devsecops github-actions llm owasp php python ruby sarif sast security security-tools semgrep static-analysis vulnerability-scanner
Last synced: 04 Jul 2026
https://github.com/semgrep/semgrep-vscode
Semgrep extension for Visual Studio Code
semgrep visual-studio-code vscode vscode-extension
Last synced: 06 Apr 2025
https://github.com/frappe/semgrep-rules
Semgrep rules specific to Frappe Framework
erpnext frappe-framework lint semgrep
Last synced: 09 Apr 2025
https://github.com/astteam/semgrep
《深入理解Semgrep》Finding vulnerabilities with Semgrep.
Last synced: 05 Jun 2026
https://github.com/semgrep/semgrep-docs
Documentation of Semgrep: a fast, open-source, static analysis tool.
Last synced: 04 Apr 2025
https://github.com/harisekhon/github-actions
GitHub Actions Reusable Workflows and Master Template
checkov ci-cd ci-cd-pipeline cicd github github-actions github-actions-ci hacktoberfest jenkins jenkinsfile library semgrep tfsec tfsec-checks validation validation-library validations
Last synced: 13 Jun 2025
https://github.com/HariSekhon/GitHub-Actions
GitHub Actions Reusable Workflows and Master Template
checkov ci-cd ci-cd-pipeline cicd github github-actions github-actions-ci hacktoberfest jenkins jenkinsfile library semgrep tfsec tfsec-checks validation validation-library validations
Last synced: 05 Apr 2025
https://github.com/avnu-labs/semgrep-cairo-rules
Semgrep rules for Cairo 1.0
Last synced: 13 May 2025
https://github.com/ligurio/semgrep-rules
semgrep rules for flakiness, missed error handling, Lua antipatterns and pitfalls.
code-quality error-handling flakiness flaky-tests golang lua non-determinism python semgrep semgrep-rules static-analysis
Last synced: 08 Sep 2025
https://github.com/Szowesgad/mcp-server-semgrep
MCP Server Semgrep is a [Model Context Protocol](https://modelcontextprotocol.io) compliant server that integrates the powerful Semgrep static analysis tool with AI assistants like Anthropic Claude. It enables advanced code analysis, security vulnerability detection, and code quality improvements directly through a conversational interface.
anthropic-claude modelcontextprotocol semgrep
Last synced: 17 Jun 2025
https://github.com/fhpythonutils/simplesecurity
Combine multiple popular python security tools and generate reports or output into different formats
bandit dlint dodgy linting python python-security safety sarif security-report security-tools semgrep simplesecurity static-analysis
Last synced: 11 Apr 2025
https://github.com/parsiya/personal-semgrep-server
Personal Semgrep Server for learning Rust.
Last synced: 11 Apr 2025
https://github.com/vinsoc-cyber/vulnhunterx
A Python framework for combining static analysis with LLM-based bug verification
codeql fuzzing llm semgrep static-analysis vulnerability vulnerability-verification
Last synced: 12 Jun 2026
https://github.com/j3ssie/sample-semgrep-ci
Github Action Example with Semgrep SAST
Last synced: 24 Jul 2025
https://github.com/vyuh-labs/dxkit
Deterministic Stop-gate and code-graph context for AI coding agents: blocks only net-new findings and gives the loop a structural map of the codebase, locally, with no model in the gate.
agentic-development ai-coding-agents brownfield ci-cd claude-code code-quality codeql codex coding-agents developer-tools guardrails loop-engineering nodejs pre-commit-hooks sarif security-scanning semgrep snyk static-analysis typescript
Last synced: 05 Jul 2026
https://github.com/parsiya/semgrep-hotspots
Repository for my Semgrep hot spot rules
semgrep semgrep-rules static-analysis
Last synced: 28 May 2026
https://github.com/ludo-technologies/codescan
Scan any GitHub repo for security issues — risky code, exposed keys, outdated packages
dependency-scanning devsecops gitleaks golang nextjs sast secrets-detection security security-tools semgrep static-analysis trivy
Last synced: 03 Jul 2026
https://github.com/johnsaigle/semgrep-diagnostics.nvim
A Neovim plugin that integrates semgrep with the built-in diagnostic system.
neovim neovim-plugin semgrep static-analysis
Last synced: 12 Apr 2025
https://github.com/ryosukedtomita/devsecops-demo-aws-ecs
GITHUB ACTIONS and devsecops tools document and demo.
aqua devsecops ghalint github-comment github-pages githubactions semgrep trivy
Last synced: 20 Feb 2026
https://github.com/g-wilson/action-semgrep
reviewdog action for semgrep - lightweight static analysis for many languages with rules that look like source code.
Last synced: 25 Jan 2026
https://github.com/semgrep/mcp
[beta] Use Semgrep in LLMs using MCP framework
Last synced: 10 Apr 2025
https://github.com/kalebu/gosec-vs-semgrep-benchmark
An oversimplified benchmark between gosec and semgrep tested on go web-frameworks
gosec gosec-vs-semgrep-benchmark semgrep semgrep-registry
Last synced: 01 Apr 2025
https://github.com/itallstartedwithaidea/last-mile
Last Mile 360 — The production-readiness platform for vibe-coded apps. Norton-grade trust. Cloudflare-native. Zero origin servers.
ai-agents cloudflare-workers code-quality devops devsecops production-readiness security semgrep typescript vibe-coding
Last synced: 17 Apr 2026
https://github.com/fazledyn/sastquatch
(Work in progress) Simple static analysis tool based on CodeQL, Semgrep
codeql docker docker-image sast semgrep
Last synced: 15 Feb 2026
https://github.com/xixifusi1213-gif/ai-project-maintainer
Release readiness gate for AI-coded projects.
ai-agents ai-coding codex devsecops github-actions gitleaks production-readiness security semgrep trivy
Last synced: 08 Jul 2026
https://github.com/iosifache/semgrep-snap
The Semgrep code scanner as a snap 📦
code-scanning semgrep snapcraft
Last synced: 17 Feb 2026
https://github.com/princepal9120/vibeaudit
dast express nextjs open-source sast security semgrep
Last synced: 06 Jul 2026
https://github.com/ashutosh0x/aardvark-security-scanner
An AI-powered security scanning system with automated triage, sandbox validation, and patch suggestions. Integrates Semgrep, Bandit, Trivy with LLM analysis for comprehensive vulnerability detection and remediation.
ai automated-patching bandit cybersecurity devsecops docker github-actions go javascript llm openai python sandbox security security-automation security-research security-tools semgrep trivy vulnerability-scanning
Last synced: 13 Apr 2026
https://github.com/alexandre-leng/ai-security-code-validator
MVP of an Open-source AI code security scanner for LLM-generated code. Detect prompt injection, secrets, vulnerable dependencies, and OWASP risks in CI/CD and DevSecOps workflows.
ai-security application-security code-security devsecops llm-security owasp prompt-injection sarif sbom secure-coding semgrep supply-chain-security vulnerability-scanner
Last synced: 11 Jun 2026
https://github.com/allsmog/kuzushi-security-plugin
Autonomous, language-aware security pipeline for Claude Code: builds repo context, then x-ray → PASTA threat model → CVE threat-intel → invariant testing & adversarial threat-hunting. Wires conditional LSP/MCP tooling (tree-sitter, semgrep, CodeQL, Joern); promotes findings to a shared index. Self-contained, no external engine.
claude-code claude-code-plugin codeql devsecops joern sast security semgrep static-analysis threat-intelligence threat-modeling tree-sitter
Last synced: 03 Jun 2026
https://github.com/elveder-ai/project-review-agent
AI agent for code review and analysis of an entire project.
ai code-review code2prompt langchain semgrep
Last synced: 10 May 2026
https://github.com/codebytemirza/LLMgrep
LLMGrep combines the precision of Semgrep's static analysis with the power of Large Language Models to deliver comprehensive security scanning, interactive vulnerability discussions, and intelligent rule generation capabilities.
ai-powered code-analysis code-security docker groq llm llm-applications python security-analysis security-automation security-scanning security-tools semgrep static-analysis static-code-analysis streamlit vulnerability-scanner
Last synced: 15 Jan 2026
https://github.com/s-santillan/semgrep4techwriting
Experimental repository for Semgrep rules specific to technical writing.
semgrep semgrep-rules technical-writing
Last synced: 19 Mar 2026
https://github.com/basel5001/devsecops-pipeline
Complete DevSecOps scanning platform: SAST, SCA, IaC, secrets + AI risk analysis (AWS Bedrock)
aws-bedrock checkov devsecops github-action gitleaks sast security-scanning semgrep trivy
Last synced: 24 Jul 2026
https://github.com/parsiya/semgrep-rs
Rust library crate to interact with Semgrep.
Last synced: 06 Jun 2026
https://github.com/lucasmelin/semgrep-deprecation-demo
How to use Semgrep to automate the work of detecting and fixing deprecations.
Last synced: 02 May 2026
https://github.com/nerdy-krishna/securecoder
Installable AI-agent skill bundle for OWASP-driven code scanning, fixing, and secure-build supervision. Multi-host (Claude Code, Cursor, Codex, etc). Distilled from the SCCAP platform. Distributed via skills.sh.
agent-skills asvs claude-code owasp sast secure-coding security semgrep skills-sh
Last synced: 17 May 2026
https://github.com/codebytemirza/llmgrep
LLMGrep combines the precision of Semgrep's static analysis with the power of Large Language Models to deliver comprehensive security scanning, interactive vulnerability discussions, and intelligent rule generation capabilities.
ai-powered code-analysis code-security docker groq llm llm-applications python security-analysis security-automation security-scanning security-tools semgrep static-analysis static-code-analysis streamlit vulnerability-scanner
Last synced: 20 Apr 2026
https://github.com/mehrdoost/devsecops-radar
🛡️ Unify Trivy, Semgrep, Poutine & Zizmor scans into one AI-enhanced, offline-ready dashboard. Track CI/CD security trends, get LLM-powered analysis, and enforce policies — the open-source DevSecOps command center.
ai ai-discovery ai-tools application-security ci-cd cybersecurity cybersecurity-tools dashboard devops-tools devsecops security-tools semgrep trivy vulnerability-managemen
Last synced: 07 Jun 2026
https://github.com/hoeg/semgrep-report
Github action for reporting semgrep findings to PRs
github-actions pull-requests security semgrep
Last synced: 17 Jan 2026
https://github.com/polespurnes/semgrep-json-to-sqlite-parser
A tool to easily parse a Semgrep CLI scan output file into a simple SQLite Database.
cybersecurity parser python semgrep sqlite tool
Last synced: 18 Feb 2026
https://github.com/beadon/ai-security-reviewer
Two-layer AI security review pipeline for npm/JS — automated tool scanning + Claude semantic analysis of what tools cannot catch
claude claude-code code-review devsecops iac-security javascript llm nodejs owasp sast security semgrep supply-chain-security terraform
Last synced: 01 Jun 2026
https://github.com/laugiov/code-safety
Security Engineering reference: taint analysis benchmark comparing Pysa, CodeQL & Semgrep on a controlled Django app (16 OWASP Top 10 cases). Includes CI/CD integration with SARIF, ground truth validation, and enterprise scaling patterns.
appsec benchmark cicd-security codeql devsecops django owasp pysa python sarif sast security semgrep static-analysis taint-analysis vulnerability-detection
Last synced: 25 Apr 2026