Integrating open source static analysis into Jenkins jobs

The Jenkins Online Meetup kindly invited us to present at their event on February 10th.

In the talk we presented Semgrep, the open-source static analysis tool that support 12+ languages and simplifies writing custom rules for organization-specific code patterns. We showed how to integrate Semgrep into a Jenkins Pipeline for scanning every commit or PR.

Here’s the video of the presentation and you can also download the slides.


Semgrep lets security teams partner with developers and shift left organically, without introducing friction. Semgrep gives security teams confidence that they are only surfacing true, actionable issues to developers, and makes it easy for developers to fix these issues in their existing environments.

Find and fix the issues that matter before build time

Semgrep helps organizations shift left without the developer productivity tax.

