Semgrep Updates: Licensing, Features, and Community Reactions

 Josh Grossman discusses recent developments with Semgrep, an open-source static analysis tool, and its new fork, Opengrep. He highlights issues with removed features affecting his custom rules but appreciates Semgrep's SARIF output support. Grossman explains Semgrep’s licensing: the core engine is LGPL, but the rule library includes a Commons Clause restricting commercial use. While noting misinformation about these changes, he praises Semgrep’s flexibility and simplicity, comparing it favorably to other tools. The post reflects his concerns and ongoing commitment to using Semgrep effectively.

https://joshcgrossman.com/2025/01/28/whats-going-on-with-sem-open-grep/

Comments

Popular posts from this blog

Secure Vibe Coding Guide: Best Practices for Writing Secure Code

OWASP SAMM Skills Framework Enhances Software Security Roles

Opengrep: Open-Source SAST for Code Security and Innovation