Find bugs and enforce code standards on every merge request
Customize your security scans using 2,000+ community rules. Semgrep supports 30 languages, with rules for technologies like Docker, Kubernetes, secret scanning, and more.
Go beyond pre-built rules by writing your own. Learn how in 5 minutes.
Semgrep fits right into your existing developer workflow. Scans can report their results as merge request discussions, so they look just like regular code review.
Available with a free Semgrep Cloud Platform account.
Semgrep can publish results to GitLab’s security ecosystem. Review findings over time in the dashboard, and see results in a dedicated panel on the merge request page.
Available in GitLab Ultimate.
Semgrep can publish results to GitLab’s security ecosystem. Review findings over time in the dashboard, and see results in a dedicated panel on the merge request page.
Available in GitLab Ultimate.