What’s Going on with Semgrep and OpenGrep?

 In the blog post, Josh Grossman discusses recent changes to Semgrep, an open-source static analysis tool. Semgrep allows users to find patterns in code with custom rules and is licensed under LGPL. Until December 2024, its rule library was under Commons Clause, which had commercial usage limitations. In December 2024, the license for Semgrep rules was updated to restrict usage to internal purposes only, prohibiting distribution or offering them as a service. This led to concerns among users, prompting the creation of the Opengrep fork to provide an open alternative. Grossman reflects on both the challenges and benefits of these changes.

https://joshcgrossman.com/2025/01/28/whats-going-on-with-sem-open-grep/

Comments

Popular posts from this blog

Secure Vibe Coding Guide: Best Practices for Writing Secure Code

OWASP SAMM Skills Framework Enhances Software Security Roles

Opengrep: Open-Source SAST for Code Security and Innovation