Sign in

Semgrep

@semgrep.com
248 followers 42 following 503 posts

Semgrep is a code scanning platform for finding first and third-party security vulnerabilities in your code base.

PostsRepliesMedia
Semgrep @semgrep.com · 06/06/2026
Will AI replace AppSec teams? 👀 In the latest episode of Security Rulez, our Security Advocate Dr. Katie Paxton-Fear (@InsiderPhD) sat down with Anshuman Bhartiya (Tech Lead at Lyft) to tackle this exact question. 👇
000
Semgrep @semgrep.com · 05/06/2026
"AI agents are writing code so fast, we can't keep up with the security debt." 🫠 We have the solution: A plugin that lives in your IDE, detecting and resolving the vulnerabilities, malicious packages, and hardcoded secrets before a PR is ever opened.
000
Semgrep @semgrep.com · 29/04/2026
full blog post
semgrep.dev
SAP Cloud Build Tool Packaged A Mini Shai-Hulud Malicious Dependency That Uses Bun
SAP npm Packages Compromised in Supply Chain Attack Using Obfuscated Bun Runtime Payload
000
Semgrep @semgrep.com · 29/04/2026
mbt@1.2.48 and @cap-js/sqlite@2.2.2 are malicious. preinstall hook → fetches Bun runtime → executes obfuscated payload → exfils GitHub/npm/AWS/Azure/GCP/k8s secrets → writes to attacker-controlled GitHub repos with description "A Mini Shai-Hulud Has Appeared" we pushed rules for customers
100
Semgrep @semgrep.com · 29/04/2026
PLEASE DON'T enable subcategory: - audit rules if you only want confirmed vulnerabilities, these are noisy by design! #EngineeringTakeover
000
Semgrep @semgrep.com · 29/04/2026
This hack week some of us are building new features, others are writing talks, and some people are doing gods work. That big rock? Verified commits.
000
Semgrep @semgrep.com · 28/04/2026
For years engineers wanted, and now they have it, everyone rejoices. Semgrep has a mobile rules editor #EngineeringTakeover
000
Semgrep @semgrep.com · 28/04/2026
Rule writing: Whenever possible, avoid leading ellipsis patterns (These patterns cause the engine to perform exhaustive searches and are quite slow, we have rules for this) BAD ... <- VERY BAD DO NOT DO THIS $X = someFunc(...) ... GOOD someOtherFunc($X) ...
010
Semgrep @semgrep.com · 28/04/2026
"Give the people what they want and they want Semgrepio" #EngineeringTakeover
000
Semgrep @semgrep.com · 27/04/2026
Here at Semgrep HQ our engineers are all in SF for our annual HackWeek so this is the Semgrep #EngineeringTakeover we've hacked the social accounts, we've locked out the marketing team and all posts going forward will be by engineers sorry, not sorry
010
Semgrep @semgrep.com · 05/04/2026
Why are so many organizations still hesitant to truly experiment with AI security? Our Security Advocate, Dr. Katie Paxton-Fear, has the answer👇
000
Semgrep @semgrep.com · 03/04/2026
Detect hard-coded JWT secrets in your Express.js codebase! Run: semgrep scan --config express-jwt-hardcoded-secret.yml ./src This rule catches risky credential patterns that could expose your authentication.
000
Semgrep @semgrep.com · 03/04/2026
Want to better understand the Semgrep Multimodal approach? Rick Harp, Senior Solutions Engineer, explains what it is and how it’s different from other static analysis tools. 👇
000
Semgrep @semgrep.com · 16/03/2026
Is your AppSec team scaling at the speed of AI, or are they still running on human-only hours? 🛡️ The timing is critical for two reasons.👇
010
Semgrep @semgrep.com · 09/03/2026
AI-native assistants don't automatically understand your unique security practices during code development. Custom Guardrails bridge that gap.👇 #AppSec #SecureCode
000
Semgrep @semgrep.com · 08/03/2026
Move from "Security Gates" to "Secure Guardrails" and keep your development velocity high without the risk. Try Semgrep today: 👇
semgrep.dev
Semgrep App Security Platform | AI-assisted SAST, SCA and Secrets Detection
An extensible developer-friendly application security platform that scans source code to surface true and actionable security issues with AI-assisted SAST, SCA, and Secrets Detection solutions.
000
Semgrep @semgrep.com · 08/03/2026
4️⃣Use Offensive AI  AI isn't just the problem, it’s also the solution. Use "Offensive AI" to: - Detect emerging issues before they become exploits. - Automatically suggest fixes for vulnerabilities in your backlog. - Learn from past mistakes to harden your codebase over time.
100
Semgrep @semgrep.com · 08/03/2026
3️⃣Enforce secure coding guardrails:  Think of guardrails as your security team’s "digital brain." By using custom rules and policies (like those in the Semgrep Pro Engine), you can set a definitive security posture that scales. If the AI suggests an insecure pattern, the guardrail stops it instantly.
100
Semgrep @semgrep.com · 08/03/2026
2️⃣ Embed security early and continuously: Security can't be an afterthought. - In the IDE: Catch issues the moment they are written. - In the PR: Enforce scans automatically to ensure no vulnerable AI code ever reaches production.
100
Semgrep @semgrep.com · 08/03/2026
1️⃣ Assume AI code is vulnerable until proven safe: Our studies show that 48% of code generated by major LLMs contains vulnerabilities. You must apply the same (or even higher) scrutiny to AI suggestions as you would to a junior engineer's PR.
100
Semgrep @semgrep.com · 08/03/2026
If your team is leaning into "vibe coding" or heavy LLM usage, you need a strategy to ensure that speed doesn't turn into a liability. Here are four essential principles for securing AI-generated code👇
110
Semgrep @semgrep.com · 07/03/2026
Want to scan your entire codebase without touching a single CI/CD file? 🛡️ In this quick walkthrough, we show you how to scale security across your repos in minutes using Semgrep Managed Scans. No manual config, just results.👇 #AppSec #SecureCode
000
Semgrep @semgrep.com · 28/02/2026
Imagine an AI that reasons like a security engineer with the context of your lead developer.  Semgrep’s retrieval systems give any LLM the repo-specific nuance it needs to be reliable.👇 #AppSec
000
Semgrep @semgrep.com · 26/02/2026
We provide secure coding feedback where it matters most: on the dev's screen. Faster feedback = less exploitable software, less frustration from devs and less time wasted.
000
Semgrep @semgrep.com · 25/02/2026
If a vulnerable function in your supply chain isn’t reachable, it shouldn’t derail your sprint. If it *is* reachable, you need it at the top of the queue. Semgrep helps teams figure this out quickly so that remediation is efficient.
000
Semgrep @semgrep.com · 14/01/2026
🟢 Semgrep version 1.147.0 is live! Check out all the details here👇 github.com/semgrep/semgrep/releases…
021
Semgrep @semgrep.com · 11/01/2026
We’re just 3 days away from our exclusive boot fitting event at the San Francisco Sports Basement. Attendance is limited and subject to confirmation. RSVP today to get on the list 👇 semgrep.dev/events/step-into-ski-se…
000
Semgrep @semgrep.com · 31/12/2025
$ semgrep init --year 2026 [INFO] Initializing Future... [OK] [INFO] Deploying: Secure_Code.v2026 [SUCCESS] [WARN] Challenges: Loading...  Welcome to 2026❇️
000
Semgrep @semgrep.com · 30/12/2025
Leave false positives in 2025. Imagine 2026: An AppSec world with zero noise and 100% developer trust. By leveraging the Semgrep platform, you can silence the friction of irrelevant alerts and focus on what actually matters ➡️ shipping secure code. 🌀Learn how we’re doing it: semgrep.dev
000
Semgrep @semgrep.com · 29/12/2025
59% of developers still don’t trust AI tools to handle security. With "vibe-coding" skyrocketing, even a small error rate creates a massive wave of new vulnerabilities. At Semgrep, we’re bridging that trust gap. #AppSec #AI #DevSecOps
000
Semgrep @semgrep.com · 28/12/2025
Read how it works👇
semgrep.dev
Semgrep × Cursor Hooks: Making Security Reliable for Agents
With Cursor hooks, AppSec teams can guarantee that all code generated by AI is scanned with Semgrep - without introducing any friction to developers. Even cooler, hooks let Semgrep give agents critical security context before they generate code, making their outputs safer to begin with.
000
Semgrep @semgrep.com · 28/12/2025
In the world of "vibe coding," agents are powerful but they aren’t secure. Semgrep x Cursor Hooks changes that. Using Cursor Hooks allows AI agents to run and test code safely in their own environment, identifying vulnerabilities and applying fixes before you ever see the code.
110
Semgrep @semgrep.com · 15/12/2025
Last chance to join us! ⏰ Tomorrow at 9:00 AM PT, @insider.phd (Semgrep) and Aubrey King (F5) will go head-to-head on the industry’s biggest hot takes, from whether AI is actually helping security teams to why developers might not care about security 🔗 semgrep.dev/events/unfil...
000
Semgrep @semgrep.com · 12/12/2025
That’s a wrap on Black Hat Europe 🇬🇧 Huge thank you to everyone who stopped by Booth #816 and to everyone who joined us at our events! We’re heading home feeling genuinely grateful for this community. Thanks for the great conversations, thoughtful questions, and good energy. Until next time! 👋
000
Semgrep @semgrep.com · 11/12/2025
On December 16th at 9:00 AM PT, join @insider.phd (Semgrep) and Aubrey King (F5) for a live, unscripted session where they tackle the hot takes practitioners are actually debating. No slides. No scripts. Just two experts digging into the issues shaping 2026. 👉 semgrep.dev/events/unfil...
000
Semgrep @semgrep.com · 11/12/2025
Still in town tonight? Join us for one more adventure: THE CUBE Experience – an AppSec Adventure 🧊 🕔 17:00–20:30 GMT | 📍 London (short tube from ExCeL) Teams of two, gameshow-style challenges + festive dinner & drinks. 👉 Register: semgrep.dev/events/the-c...
000
Semgrep @semgrep.com · 11/12/2025
Huge thank you to everyone who joined us for Security Sundowners on the Sunborn Yacht last night 🛥️🍸 And a big shoutout to our partners who helped make it happen: Tines, Cyera, Sublime Security, and Zenity 🙌 #BlackHatEU #BHEU #AppSec #Cybersecurity #Semgrep
100
Semgrep @semgrep.com · 11/12/2025
Ready to shape the future of AppSec? We are hiring across Engineering, Sales, and Marketing! Come build with us. 🌀See our open roles: semgrep.dev/about/careers
000
Semgrep @semgrep.com · 10/12/2025
Black Hat Europe is in full swing, and we’re live at booth #816 with great conversations happening all day 🙌 Come say hi to the Semgrep team to see how our AI-driven AppSec platform helps dev and security teams fix vulnerabilities earlier, reduce noise, and accelerate release velocity.
000
Semgrep @semgrep.com · 09/12/2025
The Semgrep team has touched down for Black Hat Europe! 🇬🇧 We’re set up and ready to see you tomorrow at Booth #816. Stop by to see how Semgrep’s AI-driven AppSec platform helps dev + security teams find and fix issues earlier, cut noise across SAST/SCA/Secrets, and ship faster.
000
Semgrep @semgrep.com · 08/12/2025
Semgrep is wrapping up Black Hat EU with something a little different this year. Join us at THE CUBE live in London right after the conference for a gameshow-style AppSec adventure! 🗓️ Thu, Dec 11, 2025 | ⏰ 17:00–20:30 GMT 👉 semgrep.dev/events/the-c... We hope to see you there! 👋
000
Semgrep @semgrep.com · 05/12/2025
It’s been a busy week for the Semgrep team! ⚡ 🎉 We’ve been out and about at AWS re:Invent, OWASP Benelux, the Colorado = Security Holiday Party, Merry & Mingling: Evolve's Holiday Mixer, and Hack the Halls! Curious where we’re heading next? Check out our events page: semgrep.dev/events/
000
Semgrep @semgrep.com · 04/12/2025
Yesterday was a blast! 🏁🔥 A huge thank you to everyone who joined us at the Accelerate to Innovate – Raceday at re:Invent event with Sysdig. Amazing conversations, big energy, and such a fun mid-week highlight, we loved sharing it with you! Stop by booth #486 today before the week wraps! 🙌
000
Semgrep @semgrep.com · 03/12/2025
What a night! 🌆✨ Huge thank you to everyone who joined us yesterday for Sip and Sync at the Sphere with Pellera Technologies and the AWS re:Invent Cocktail Reception with Felicis, Tableau, Supabase, Tines, and MotherDuck. Incredible conversations and such a fun way to kick off the week!
020
Semgrep @semgrep.com · 03/12/2025
Tomorrow (Dec 4 @ 9:00am PT), join a fireside chat with Mudita Khurana (Airbnb) and Chushi Li (Semgrep) on measurement + benchmarks for the next generation of AppSec agents, including the Closed-Loop Capability (CLC) score. 🔗 Register here: semgrep.dev/events/measu...
010
Semgrep @semgrep.com · 02/12/2025
Day 2 at AWS re:Invent is underway! If you're exploring the expo floor, come swing by Booth #486 to meet the team, check out live demos, and snag some exclusive Semgrep swag. #AWSreinvent #Semgrep #AppSec #DevSecOps #Cybersecurity
000
Semgrep @semgrep.com · 02/12/2025
With all eyes on Sha1-Hulud, it’s easy to forget this is just the latest in a series of attacks showing a new normal where malicious dependencies wreak havoc on organizations. That’s why Malicious Dependency Detection is now generally available for Semgrep Supply Chain. semgrep.dev/blog/2025/bl...
000
Semgrep @semgrep.com · 02/12/2025
Big news! 🎉 Semgrep has been named a 2025 Inc Best in Business honoree in the Best AI Implementation category. It's an honor to be recognized for how we're using AI to accelerate security and shape the future of cybersecurity. Learn more: www.prnewswire.com/news-release...
000
Semgrep @semgrep.com · 01/12/2025
The Semgrep team has officially landed in Las Vegas for AWS re:Invent! ✈️🎉 We’ll be at Booth #486 all week. Come meet the team, grab some great swag, and see how Semgrep helps engineering and security teams ship faster and stay secure. See you on the expo floor! 🙌
010
Semgrep @semgrep.com · 01/12/2025
🇧🇪OWASP Benelux Days – see you tomorrow! 🇧🇪 We’re excited to touch down in Mechelen, Belgium soon – for a day of AppSec talks, followed by our ‘Brews & Bytes’ evening event afterwards… Learn more: semgrep.dev/events/owasp... Hope to see you there! #AppSec #InfoSec #Cybersecurity
010