Software Alternatives & Reviews

Semgrep

Semgrep is a fast, open-source, static analysis tool for finding bugs and enforcing code standards at editor, commit, and CI time.

Top 12 Open-Source Alternatives to Semgrep

SonarQube Snyk Cppcheck Bearer CodeClimate GitGuardian Brakeman SonarCloud OWASP Dependency-Track

Summary

The top open-source alternatives to Semgrep are SonarQube, Snyk, and Cppcheck. One of the criteria for ordering this list is the number of mentions that products have on reliable external sources. You can suggest additional sources through the form here.
  1. SonarQube, a core component of the Sonar solution, is an open source, self-managed tool that systematically helps developers and organizations deliver Clean Code.
    Pricing:
    • Open Source
    • Freemium
    • Free Trial
    • $150.0 / Annually

    #Code Analysis #Code Review #Code Coverage 1 social mentions

  2. 2
    Snyk helps you use open source and stay secure. Continuously find and fix vulnerabilities for npm, Maven, NuGet, RubyGems, PyPI and much more.
    Pricing:
    • Open Source

    #Security #Security Monitoring #Security CI 85 social mentions

  3. Cppcheck is an analysis tool for C/C++ code. It detects the types of bugs that the compilers normally fail to detect. The goal is no false positives. CppCheckDownload cppcheck for free.
    Pricing:
    • Open Source

    #Code Analysis #Code Coverage #Development 10 social mentions

  4. ShellCheck finds bugs in your shell scripts
    Pricing:
    • Open Source

    #Code Analysis #Code Coverage #Code Quality 29 social mentions

  5. 5
    Bearer is an open source, fast and accurate static application security testing (SAST) tool that analyze your source code to discover, filter and prioritize security and privacy risks.
    Pricing:
    • Open Source
    • Freemium
    • Free Trial

    #Code Analysis #Security & Privacy #Security

  6. Code Climate provides automated code review for your apps, letting you fix quality and security issues before they hit production. We check every commit, branch and pull request for changes in quality and potential vulnerabilities.
    Pricing:
    • Open Source

    #Code Coverage #Code Quality #Code Analysis 11 social mentions

  7. Detect secrets in source code, public and private!
    Pricing:
    • Open Source

    #Security & Privacy #Chrome Extensions #Security 2 social mentions

  8. Brakeman is a static analysis security vulnerability scanner for Ruby on Rails applications.
    Pricing:
    • Open Source

    #Code Analysis #Code Coverage #Code Review 7 social mentions

  9. Enhance your workflow with continuous code quality, SonarCloud automatically analyzes and decorates pull requests on GitHub, Bitbucket, Azure DevOps and GitLab on major languages.
    Pricing:
    • Open Source
    • Freemium
    • Free Trial
    • €10.0 / Monthly (100,000 Lines of Code)

    #Developer Tools #DevOps Tools #SAST 12 social mentions

  10. OWASP Dependency-Track is an intelligent Software Composition Analysis (SCA) platform that allows...
    Pricing:
    • Open Source

    #Security #Code Analysis #Security & Privacy 19 social mentions

  11. 11
    The fully pluggable JavaScript code quality tool
    Pricing:
    • Open Source

    #Code Coverage #Developer Tools #Code Quality 229 social mentions

  12. Cloud-Native Cybersecurity Software that secures both Cloud and Code
    Pricing:
    • Open Source

    #Cyber Security #IT And Cybersecurity #Developer Tools

Suggest an alternative
If you think we've missed something, please suggest an alternative to Semgrep.
Please use the Feedback button if you think any of the listed products shouldn't be regarded as open-source.

Semgrep discussion

Log in or Post with