Semgrep + GitLab

Find bugs and enforce code standards on every merge request

Security designed and built 
for engineers

Scan merge requests with any of thousands of rules

Customize your security scans using 2,000+ community rules. Semgrep supports 30 languages, with rules for technologies like Docker, Kubernetes, secret scanning, and more.

Go beyond pre-built rules by writing your own. Learn how in 5 minutes.

Discuss findings in merge requests

Semgrep fits right into your existing developer workflow. Scans can report their results as merge request discussions, so they look just like regular code review.

Available with a free Semgrep Cloud Platform account.

Keep your GitLab workflow

Semgrep can publish results to GitLab’s security ecosystem. Review findings over time in the dashboard, and see results in a dedicated panel on the merge request page.

Available in GitLab Ultimate.

Get results at ludicrous speed

Semgrep can publish results to GitLab’s security ecosystem. Review findings over time in the dashboard, and see results in a dedicated panel on the merge request page.

Available in GitLab Ultimate.