← All repos

opengrep

🔎 Static code analysis engine to find security issues in code.

Browse cluster: Static Analysis & Code Quality
9,955commits
239contributors
30languages

Tech stack & purpose

Opengrep is a static code analysis engine designed to find security vulnerabilities in code. It is a fork of Semgrep v1.100.0 released under the LGPL 2.1 license and backed by a consortium of AppSec organizations including Aikido, Amplify, Endor Labs, Kodem, and Orca Security. The tool supports over 30 languages including Python, JavaScript, Go, Java, Rust, C#, and Visual Basic, offering features like taint analysis, pattern matching, and customizable security rules with output in JSON and SARIF formats. Opengrep is built with OCaml-based parsers and Python components, and provides self-contained binaries via Nuitka that require no Python installation.

Community & reference links

Languages

OCaml
75.9%
Python
12.6%
Java
3.6%
JavaScript
1.7%
Yacc
1.6%
Standard ML
1.0%
Shell
0.8%
Lex
0.7%
Go
0.4%
Ruby
0.3%
C++
0.2%
Makefile
0.2%
Nix
0.2%
Dockerfile
0.1%
PowerShell
0.1%
Jsonnet
0.1%
Dune
0.1%
C
0.1%
Scala
0.1%
Elixir
0.1%
Swift
0.0%
PHP
0.0%
Mustache
0.0%
HTML
0.0%
C#
0.0%
HCL
0.0%
Jinja
0.0%
Max
0.0%
Vue
0.0%
Rust
0.0%

Contributors (top 30 of 239)