Previous
Next
Semgrep
AI-assisted static analysis for app security
San Francisco, CA, USA
Founded 2017
Semgrep is a lightweight static analysis tool designed to help developers find bugs, enforce coding standards, and improve security in their codebases. Unlike traditional static analysis tools, Semgrep is fast, easy to configure, and works across multiple programming languages.
Websites:
Last Updated: May 10, 2025
Current Valuation
No valuation data available
Funding Summary
$193M
Total reported funding
Media Mention
June 23, 2026
DEV Community (dev.to): I'm Building a Code Security Analyzer. A Security Tool Found a Critical In It.
Media Mention
June 21, 2026
DEV Community (dev.to): What I found when I security-scanned 10 AI-built apps (and how to check yours manually) - DEV Community
OSS News & Views
June 20, 2026
TipRanks: Semgrep Leans Into AI-Driven AppSec, Reachability Analysis, and Conference Visibility - TipRanks.com
OSS News & Views
June 20, 2026
Programming Insider: Best Semgrep Alternatives in 2026: Top 5 SAST, SCA, and AppSec Platforms Compared - Programming Insider
OSS News & Views
June 17, 2026
GovInfoSecurity: Mastra AI Framework Poisoned in npm Supply-Chain Attack
Showing 1-5 of 35 headlines
Page 1 of 7
Key People
Core OSS Projects
Semgrep is a fast, open-source, static analysis tool that searches code, finds bugs, and enforces secure guardrails and coding standards. Semgrep supports 30+ languages and can run in an IDE, as a pre-commit check, and as part of CI/CD workflows.
License: LGPL-2.1
Business Information
Category
Developer ToolsIndustries
Data & Analytics
Technologies
CybersecuritySoftware Supply Chain SecurityAI/ML
Sectors
EnterpriseSMBs
Licenses
LGPL-2.1
Similar Companies
Cossmology Badge
COSS Weekly Newsletter
Stay up to date with the latest news, funding rounds, and announcements from the COSS universe.
Check out COSS Weekly on the web
