The Semgrep Summer '26 release is built around three ideas, at a moment when frontier models like Mythos are shifting the balance toward attackers:
(i) AI & SAST are better together
(ii) Security should work where builders work
(iii) Malware needs to be stopped before it ever reaches a codebase.
In this 60-minute live demo, see how detection, triage, and remediation work as one system.
Detecting
Multimodal AI Detection: Rules engine + AI reasoning + Context. 8× more true positives, 50% fewer false positives than AI alone.
Context Engine: Models your app's endpoints, data access, and auth patterns.
Custom Rules & Policies: Org-specific detection tuned to your codebase.
Semgrep for Builders
Semgrep Guardian: Stop malware, vulns/secrets before they reach your codebase.
Custom Security Workflows: Build your own security pipeline in Python.
Triaging
Autotriage + Assistant Memories: Devs only see exploitable issues. 96% agreement rate.
Supply Chain Autotriage: Up to 98% SCA noise reduction before it reaches devs.
Fixing
Autofix PRs + Breaking Change Guidance: Know exactly what will break before the upgrade so developers stay in control.
Code Autofix: Accurate, multi-file fixes for complex authorization issues.
Roadmap preview, open Q&A, and a chance to win a Bambu Lab A1 Mini 3D Printer.