Semgrep
Fast, open-source static analysis for finding bugs and security issues.
Semgrep grinds its analysis engine wider — more languages, more taint precision, less noise.
◆Recent moves
- 18h ago
OpenTofu .tofu files now scanned as Terraform
Adds automatic detection of OpenTofu .tofu files, scanning them with the existing Terraform grammar and rulesets — broadens IaC coverage to the Terraform fork without new rules.
View source ↗ - 8d ago
Pro C/C++ skips dead preprocessor branches
Pro C/C++ scans now skip statically-dead preprocessor branches (#if 0), cutting false positives on intentionally-disabled code — a precision gain in the engine's C/C++ path.
View source ↗ - 14d ago
Dart parser upstream bump (infra)
An infra release bumping the Dart parser to a newer upstream version; no user-visible behavior change.
View source ↗ - 28d ago
Experimental transitive dependency-path output for SCA
Adds an experimental --x-dependency-paths flag exposing full transitive paths for supply-chain findings, plus clearer labeling of malicious-dependency rules — early reachability tooling for SCA.
View source ↗ - 1mo ago
Broader constant folding; platform nosemgrep control
Expands constant-propagation folding to more operators (subtraction, division, bit ops, comparisons) and adds a config field to disable nosemgrep suppression — incremental analysis-engine depth.
View source ↗ - 1mo ago
Experimental cross-file taint tracking for Gosu (Pro)
Adds experimental cross-file taint tracking for Gosu on the Pro tier, extending interfile analysis to another language — part of the steady reach expansion.
View source ↗