Home New Trending Search
About Privacy Terms
#
#Semgrep
Posts tagged #Semgrep on Bluesky

Semgrep ai-best-practices: 58 rules catching hardcoded API keys, prompt injection, unsafe Claude Code/Cursor hooks, MCP server flaws and LangChain eval flows across 7 languages. #semgrep #ai_security #tool https://bit.ly/4rdsjuw

1 0 0 0
Preview
Semgrep: Analizando los errores del código | Servidores | CIBERED Semgrep ayuda a los desarrolladores y testers a realizar análisis estático del código a gran velocidad. Características de Semgrep Código abierto, funciona en más de 17 idiomas. Escanea con más de 100...

🔍 Semgrep: Analizando los errores del código
cibered.com/devops/servi...

#Semgrep #Seguridad #DevOps #Cibered

0 0 0 0
Post image Post image Post image Post image

Huge thank you to everyone who joined us for Security Sundowners on the Sunborn Yacht last night 🛥️🍸

And a big shoutout to our partners who helped make it happen: Tines, Cyera, Sublime Security, and Zenity 🙌

#BlackHatEU #BHEU #AppSec #Cybersecurity #Semgrep

0 0 1 0
Original post on infosec.exchange

Hey developers and vulnerability researchers!

I'm currently working on improving my #Semgrep ruleset for C/C++ static code analysis, and I've just published the new v1.1.0 release: https://github.com/0xdea/semgrep-rules

Some notable changes since the previous battle-tested release: new rules […]

0 1 0 0
Post image Post image

Day 2 at AWS re:Invent is underway! If you're exploring the expo floor, come swing by Booth #486 to meet the team, check out live demos, and snag some exclusive Semgrep swag.

#AWSreinvent #Semgrep #AppSec #DevSecOps #Cybersecurity

0 0 0 0
Preview
Semgrep Achieves Major Recognition as Best AI Implementation in 2025 by Inc. Semgrep has been honored as the Best AI Implementation by Inc.'s 2025 Best in Business list, showcasing its revolutionary approach to application security.

Semgrep Achieves Major Recognition as Best AI Implementation in 2025 by Inc. #USA #San_Francisco #Semgrep #AI_Implementation #Code_Security

0 0 0 0
Preview
Semgrep Launches Private Beta of AI-Powered Detection to Combat Business Logic Vulnerabilities Semgrep has introduced a private beta feature utilizing AI to detect business logic vulnerabilities effectively. This innovation aims to enhance application security and address critical coding issues.

Semgrep Launches Private Beta of AI-Powered Detection to Combat Business Logic Vulnerabilities #USA #San_Francisco #Security #AI_Detection #Semgrep

0 0 0 0
Post image

The Semgrep Community Edition (CE) Fall 2025 release is here with:

⚡ Up to 3× faster scans on large repos
💻 Native Windows support — no WSL required
🌍 Now runs on 500 million+ more machines

👉 Read the full blog: semgrep.dev/blog/2025/se...

#Semgrep #AppSec #DevSecOps #OpenSource #SAST

1 0 0 0
Post image Post image Post image

Day 2 at SecureWorld Seattle is underway! 🚀

A huge thank-you to everyone who joined Semgrep, @stackhawk.bsky.social and EVOTEK last night for our Unwind & Dine dinner at La Mar Bellevue — great conversations, great company, and even better connections!

#SecureWorld #AppSec #Semgrep #InfoSec

1 0 1 0
Post image Post image Post image

SecureWorld Seattle is in full swing! 🚀

Stop by the Semgrep booth to meet the team, grab some great swag, and enter for a chance to win our Back to the Future Time Machine LEGO set!

See you soon!

#SecureWorld #Seattle #AppSec #Semgrep

0 0 0 0
Preview
Semgrep Achieves Recognition on Fortune's 2025 Cyber 60 List for Three Consecutive Years Semgrep secures its place on Fortune's 2025 Cyber 60 List for the third year, highlighting its leading role in application security.

Semgrep Achieves Recognition on Fortune's 2025 Cyber 60 List for Three Consecutive Years #USA #Cybersecurity #San_Francisco #Application_Security #Semgrep

1 0 0 0
Post image

🚨 Happening tomorrow!

Join us for the Semgrep Community Edition (Fall Release) webinar. See what’s new, what’s faster, and what’s next.

🗓️ Oct 23 | 10 AM PT
💻 Cross-platform support, 2x faster scans, and more!

🔗 semgrep.dev/events/semgr...

#Semgrep #AppSec #DevSecOps

0 0 0 0
Preview
Semgrep Achieves First-time Recognition in Gartner's Magic Quadrant for Application Security Testing Semgrep, a top-tier Application Security platform, celebrates its first recognition in the 2025 Gartner Magic Quadrant for Application Security Testing, marking a notable achievement in code security.

Semgrep Achieves First-time Recognition in Gartner's Magic Quadrant for Application Security Testing #USA #San_Francisco #Gartner #Application_Security #Semgrep

0 0 0 0
Post image

LeadDev and BSides NY, and we’d love to connect while we’re there! 🗽

Catch Leif Dreizler speaking at LeadDev/StaffPlus New York, then meet the team at BSides NY to learn how Semgrep’s low-noise results and AI guidance can help you ship faster and reduce risk.

#Semgrep #LeadDev #BSides #AppSec

0 0 1 0
Video thumbnail

We’ve got three great webinars coming up next week, and there’s something for everyone! 🙌

✨ Register for one (or all three!) We can't wait to see you there!

Details in the 🧵

#Semgrep #AppSec #AI #DevSecOps #SAST #SecureCoding

0 0 1 0
Post image

Toronto, we’re ready for you! 🇨🇦🏙️

Heading to SecTor? Swing by booth #338 to learn how our low-noise results and AI guidance across SAST, SCA, and Secrets help you:
⚡️ Fix vulnerabilities early
⚡️ Speed up releases
⚡️ Reduce risk

We can’t wait to meet you!

#SecTor #AppSec #DevSecOps #Semgrep

0 0 0 0
Post image Post image

DevOpsDays Denver is in full swing and the Semgrep team is live on-site! 🎉

It’s been amazing connecting with so many of you already, and we’re not done yet.

✨ Let’s keep the conversations going—see you out there! ✨

#DevOpsDaysRockies #Semgrep #AppSec #DevSecOps #Security #AI

0 0 0 0

🔗 Watch the full webinar with Jack Moxon and Erik Buchanan to see how Secure Vibe Coding with Semgrep MCP keeps your AI-powered workflows safe: semgrep.dev/events/video...

#AppSec #SecureCoding #DevSecOps #AI #Semgrep #LLMs

0 0 0 0
Post image

I interviewed Kim Wuyts for a #Semgrep fireside chat called Privacy by Design: Making Threat Modeling Work for Data Protection, and it was super fun!

Watch us here: https://twp.ai/9PUxWA

@KimWuyts #privacy #threatmodeling

2 1 0 0
Preview
Semgrep and Static Code Analysis for Projects on JuliaHub Secure your Julia code with JuliaHub + Semgrep. Learn static analysis, compliance tips & secure coding in this live webinar.

Secure Julia code matters—especially in #Pharma, #Finance & Life Sciences. Join our #webinar to see how JuliaHub + Semgrep simplify static analysis, #coding #compliance & audit readiness in the cloud. juliahub.com/company/reso...
#JuliaLang #JuliaHub #SecureCoding #Semgrep

0 0 0 0
Post image

#Semgrep static analysis tool for #code scanning at ludicrous speed 🔍

🔍 Supports 30+ languages including #Python #JavaScript #Java #Go #C #Rust #TypeScript #php and more

🛡️ Finds bugs, enforces #security guardrails and coding standards with semantic pattern matching

🧵 👇

3 1 1 0
Preview
What is Privacy Engineering and Why Its not as complicated as it sounds with Cat Easdon "Privacy engineering is the art of translating privacy laws and policies into code, figuring out how to make legal requirements such as ‘an individual must be able to request deletion of all their personal data’ a technical reality.", was the elegant explanation from Cat Easdon when asked about what she is doing in her day job. If you want to learn more then tune in to this episode. Cat, Privacy Engineer at Dynatrace, shares her learnings about things such as: When the right time is to form your own privacy engineering team, why privacy means different things for different people and regulators and what privacy considerations we specifically have in the observability industry so that our users trust our services! Links: Cat's LinkedIn Profile: https://www.linkedin.com/in/easdon/ Publications from Cat: https://www.dynatrace.com/engineering/persons/catherine-easdon/ Blog on Managing Sensitive Data at Scale: https://www.dynatrace.com/news/blog/manage-sensitive-data-and-privacy-requirements-at-scale/ Semgrep for lightweight code scanning: https://github.com/semgrep/semgrep The IAPP: https://iapp.org/ 'Meeting your users' expectations' is formally described by the theory of contextual integrity: https://www.open.edu/openlearncreate/mod/page/view.php?id=214540 Facebook's $5 billion fine from the FTC: http://ftc.gov/news-events/news/press-releases/2019/07/ftc-imposes-5-billion-penalty-sweeping-new-privacy-restrictions-facebook Fact-check: "The $5 billion penalty against Facebook is the largest ever imposed on any company for violating consumers’ privacy and almost 20 times greater than the largest privacy or data security penalty ever imposed worldwide. It is one of the largest penalties ever assessed by the U.S. government for any violation." I think that's still true; the largest fine under the GDPR was €1.2 billion (again for Facebook/Meta)

📣 New Podcast! "What is Privacy Engineering and Why Its not as complicated as it sounds with Cat Easdon" on @Spreaker #data #dynatrace #engineering #observability #personal #privacy #regulation #regulators #semgrep #sensitive

1 0 0 0
Post image

Need help with Semgrep or have questions about best practices and implementation? Our Slack community is here for you! With over 4,000 active members, you’ll find plenty of guidance and support.

semgrep.slack.com/join/shared_...

#AppSec #OpenSource #Semgrep #Community

1 1 0 0
Post image

🕵️‍♂️ Something strange is happening at Meow Wolf’s Omega Mart. Join Semgrep to challenge your perception of the limits of AppSec reality in the agentic era on Tuesday, August 5th from 6-9 pm.

🎟️ Register: semgrep.dev/events/omega...

#HackerSummerCamp #Semgrep #OmegaMart #MeowWolf #AppSec #BlackHat

4 2 0 2
Post image

I interviewed Kim Wuyts for a #Semgrep fireside chat called Privacy by Design: Making Threat Modeling Work for Data Protection, and it was super fun!

Watch us here: https://twp.ai/9PTD2Y

@KimWuyts #privacy #threatmodeling

3 1 0 0
Post image

I interviewed Kim Wuyts for a #Semgrep fireside chat called Privacy by Design: Making Threat Modeling Work for Data Protection, and it was super fun!

Watch us here: https://twp.ai/9PTGHj

@KimWuyts #privacy #threatmodeling

1 0 0 0
Hands typing at a keyboard with sparks coming out of the screen.

Hands typing at a keyboard with sparks coming out of the screen.

Just published - Our new white paper comparing Semgrep's Code and Community editions! We dove into both versions of this popular tool to see what the differences were and how they performed against each other. Check it out!
www.doyensec.com/resources/Co...

#doyensec #appsec #security #semgrep

0 0 0 0
Post image

📅 Happening this week!

This Wednesday, June 25 at 9AM PT, join Chushi Li and Erik Buchanan for a live webinar on how we’re using AI to make Semgrep smarter, quieter, and more adaptable to real-world environments.

🔗 Register here: semgrep.dev/events/conte...

#AppSec #AI #SAST #DevSecOps #Semgrep

0 0 0 0
A ruler applied to a computer monitor to help with yaml indentation...

A ruler applied to a computer monitor to help with yaml indentation...

Current status:

#yaml #semgrep

0 0 0 0
Preview
Replit GenAI Security Scans and Shadow AI A roundup of recent headlines about Semgrep in the past month. $ grep -rh -A 5 -m 10 “<h1>” semgrep-news.html | more ## Replit Partners with Semgrep for AI Security Scans Replit is an AI-powered platform that lets you create and deploy apps from a browser. This is great for dev teams to enable quick product development cycles. For security teams, well… like other LLM tools, this can introduce risks. Replit turned to Semgrep to power its security scanning, directly within the Replit IDE. Learn more in the blog post about the Replit + Semgrep partnership. ## RSAC Industry Leader Interviews The team had a great show at RSA and BSidesSF this year. We had a chance to turn the camera on and have a chat with some friends: * Phil Venables, Partner at Ballistic Ventures, shared his insights with Clint Gibler (Semgrep Head of Security Research) about the things he’s learned from senior security research roles at companies like Deutsche Bank, Goldman Sachs, Google, and more. Watch the video interview. * Cristin Flynn Goodwin, Consultant with Good Harbour, shared her experiences for a legal perspective on cybersecurity with Tanya Janca (Semgrep Developer Advocate). Watch the video interview. Other interviews include Jason Haddix (Arcanum), Nariman Aga-Tagiyev (SecureHabits.nl), and more. ## Shadow AI Scan for Unauthorized Usage Unaccounted for AI usage can lead to compliance violations, sensitive data exposure (including secret keys!), and many other GenAI security risks when not using a proper approval process. We’ve built a new ruleset to detect unauthorized use of AI and LLM libraries including OpenAI, Anthropic Claude, LangChain, HuggingFace, Grok, Gemini, Deepseek, and more. See the Semgrep Shadow AI page from RSAC to learn more. ## Scaling Security and AI with AWS Cameron Smith, Sr. Security Solutions Architect at AWS, joined Jack Moxon, Staff Product Manager, to talk about rapid development and cloud-native deployment at speed. Video interview on Youtube. ## Semgrep Rulez for Vibe Code We’ve partnered with Replit to incorporate Semgrep rules directly in a Security Scanner for AI generated code. This puts users of Replit one step ahead so that this doesn’t happen to you: For everybody else, the Semgrep MCP server provides a path for any technology team to incorporate Semgrep security scans into their LLM generated source-code production workflows. This enables a secure-by-default AI solution. View the README.md for setup instructions usable with tools like Anthropic, OpenAI, Cursor, Windsurf, Lovable, etc. ## Rulesets for Customizing Security Checks Want to improve your security posture by writing custom Semgrep rules for your organization? Watch the Rule Writing 101 (video) and Rule Writing 201 (video) to learn how step-by-step. The documentation for writing rules goes into more detail on the pattern and rule syntax which you can test interactively in the Playground. The Custom Rules course from Semgrep Academy goes even more in depth. Visit the semgrep-rules github repository to see examples or if you built rules that you are willing to share like Trail of Bits and Gitlab have contributed. ## FinTech and the Role of AI in Security What is different about security engineering in a FinTech context? Industry security veterans Rinki Sethi (BILL) and Lee Laslo (Alloy) share their perspective. Watch the video interview. ## AppSec for Builders: A Manifesto Luke O'Malley was interviewed at RSA about his manifesto for builders and the future of artificial intelligence. > “If you want to empower your builder, you need to give them agency... it’s not about control, it’s about empowerment. We want to notify them if they’re doing something risky and provide a guardrail and nudge them back onto the paved road—a safer path that still lets them move fast.” Watch the video or read the blog post with highlights from the session. ## Community Headlines It is fascinating to see all the ways other community projects are using Semgrep! * DeepWiki uses AI to generate documentation, including the semgrep/semgrep open-source project. Helpful for those who want to contribute. * Replit’s perspective on The Safest Place for Vibe Coding. * Watch the recording of the Fireside Chat with Tanya Janca and Laura Bell Main, founder of SafeStack. * Meta’s PurpleLlama CyberSecEval project includes tools like CodeShield and Insecure Code Detector (ICD) to identify insecure coding practices such as LLM output and has built some custom rules as part of the project. * Anthropic Case Study: How Semgrep delivers AI-powered code security with Claude in Amazon Bedrock Have a Semgrep story? Share it with us! ## How to Get Started with Semgrep If you've only just learned about Semgrep, here's some ways to get started: * The Semgrep Community Edition is free open-source software that powers many teams with basic functionality. * The Semgrep AppSec Platform capabilities are available to test on any project with fewer than ten (10) contributors for free. Just hop over to semgrep.dev, sign up, and follow the Quick Start. If you have any questions or feedback, hop onto the Community Slack and let’s chat (I’m @j12y)! If you want to talk to us virtually or see us in-person, check out the events page to see where we’ll be.
0 0 0 0