Back to Security
Semgrep logo

Semgrep

Semgrep is a static analysis tool that helps developers and security teams find bugs and enforce code standards across codebases.

Primary category: Security
About this data
This page reflects public online discussion, collected and scored by automated systems and summarized using AI. It is not a statement of fact, not an audit, and not our own opinion of the product. Automated analysis can be incomplete or wrong, and scores carry the limitations described in our methodology. Companies can respond with their own perspective. See how this is calculated.

Updated June 29, 2026

Overall Pulse Score

46
Pulse Score

+15 over this period

A 0-100 index summarizing the tone of 452 relevant public mentions gathered from public online communities across 16 weeks in the selected period. It measures online sentiment, not a rating of the product's quality.

Weekly Sentiment Trend

Pulse Score by week over the selected period. Each point is one complete week of mentions.

Download chart

This week in public discussion

Discussion around Semgrep over the recent period was dominated by bug reports and reliability concerns, with commenters raising repeated issues around path handling errors in hook scripts across WSL, Windows, and git worktree environments. Several mentions flagged silent scan failures as a particular frustration. On the positive side, some discussion focused on integration work and CI pipeline improvements. The overall tone skewed negative, with bug and reliability complaints outnumbering praise themes by a considerable margin.

Read the deeper analysis

AI-generated summary of public online discussion during this period. It reflects the tone of that discussion, not facts about the product or our views.

Sentiment mix by week

How the tone of public discussion splits each week.

Ringed points mark weeks with unusually high discussion volume, more than double this product's typical week.

Most-discussed praise

Strong features80
Good integrations48
Compared to rivals21
Security praise13
Feature requests11

Most-discussed complaints

Bugs126
Reliability83
Missing features59
Feature requests32
Lacking integrations8

Themes across the selected period, with mention counts.

How Semgrep compares

Pulse Score over the selected period versus the top tracked competitors in Security.

Where the mentions come from

Share of the 452 relevant public mentions in the selected period, by source.

GitHub100% (452)

Sample public mentions

Showing 5 of 452 analyzed public mentions in this period, with links to the original source. We do not reproduce full threads.

semgrep scan generates findings for ignored code blocks if the --sarif-output option is specified. **Describe the bug** According to the documentation, an inline comment followed by the nosemgrep word can be used to ignore blocks of code. However, if the --sarif-output option is ...

GitHubApr 3, 2026

Hook binary doubles absolute file_path (no IsAbs check) → open: no such file noise + silent SAST no-op in git worktrees. ## Summary The hook registered for Write|Edit|Bash (Pre/PostToolUse) joins the current working directory onto tool_input.file_path **without checking whether f...

GitHubJun 21, 2026

Please make the pyjwt depdency looser. Hello! Currently, semgrep depends on pyjwt~=2.12.0. This means we must use PyJWT 2.12.X in our project. We want to use version 2.13.0, but that conflicts. Can semgrep depend on pyjwt~=2.12 so we can then bump to 2.13.X? Thanks!

GitHubJun 3, 2026

**Semgrep identified an issue in your code:**. **Semgrep identified an issue in your code:** An action sourced from a third-party repository on GitHub is not pinned to a full length commit SHA. Pinning an action to a full length commit SHA is currently the only way to use an acti...

GitHubApr 30, 2026

**Semgrep identified an issue in your code:**. **Semgrep identified an issue in your code:** An action sourced from a third-party repository on GitHub is not pinned to a full length commit SHA. Pinning an action to a full length commit SHA is currently the only way to use an acti...

GitHubApr 30, 2026

447+ more analyzed mentions, full history, and theme breakdowns are part of Pro.

Get Pro

Deeper analysis

  • Bug reports and reliability complaints dominated the conversation, outnumbering praise themes by a wide margin over the four-week window.
  • Sentiment climbed briefly in mid-May then fell back as mention volume spiked in June, ending the period in a flat, middling range without clear recovery.
  • Opinion was divided on dependency pinning strictness, with some commenters expressing friction while others appeared to accept the constraints.
  • Silent failure modes in security scanning contexts drew notably sharper negative tone than bugs that surfaced visible errors.
Praise themeMentions
Strong features80
Good integrations48
Compared to rivals21
Security praise13
Feature requests11
Complaint themeMentions
Bugs126
Reliability83
Missing features59
Feature requests32
Lacking integrations8

Public discussion around Semgrep over the past four weeks was dominated by a persistent undercurrent of frustration, with bug reports and reliability concerns accounting for the largest share of complaint-side mentions by a considerable margin. Commenters surfaced a recurring class of path-handling errors, with several mentions describing hook scripts that incorrectly prepend working directory paths to already-absolute file paths, producing doubled paths and silent scan failures across Windows, WSL, and git worktree environments. This pattern of quiet, hard-to-detect breakdowns seemed to heighten irritation, as discussion suggested that a tool failing silently in a security context is treated as a more serious offense than one that fails loudly.

Sentiment trajectory across the window was unsteady. Early weeks showed very low scores on minimal mention volume, then climbed into the low-to-mid fifties around mid-May before sliding back as mention counts surged in early and mid-June. The largest bursts of activity coincided with score dips, which discussion suggested reflects moments when a wider audience encountered reproducible problems and brought them into public view at once. By the final tracked week sentiment had settled into a narrow, middling band without meaningful recovery.

On the praise side, feature appreciation and integration quality drew the most positive attention, and competitor comparison threads occasionally framed Semgrep favorably, though those threads were a small slice of overall volume. Divided opinion was clearest around dependency management, where commenters expressed frustration with tight version pinning on transitive dependencies while others appeared neutral or sympathetic to the maintenance rationale. Feature-bucketing and workflow classification decisions also drew split reactions, with some discussion questioning whether current categorization choices matched user mental models. Overall tone leaned skeptical, with reliability concerns outweighing positive signals across the window.

AI-generated summary of public online discussion during this period. It reflects the tone of that discussion, not facts about the product or our views.

Member perspectives

Individual opinions from Pro members, posted over time. These are personal member views, not aggregated sentiment data.

Data summary

Total mentions analyzed (all time)
452
Mentions in selected period
452
Weeks in range
16
vs Security average (47)
Below by 1
Pricing
Free tier; paid plans available
Sources
GitHub (452)

Compare with another tool

Semgrep

46

Trainual

88

Full comparison

Score-level preview from live weekly tracking.

Are you Semgrep?

Get a private enterprise dashboard for your product - full history, every source, theme deep-dives, and weekly alerts. You can also respond to the data shown here.

Explore the enterprise dashboard

Try Semgrep

Visit the official website to get started

Visit site

Affiliate disclosure

Some links on this site may be affiliate links. If you click one and make a purchase, we may earn a commission at no extra cost to you. Learn more.

Is Semgrep your product?

See everything behind this page - full history, every source, theme deep-dives, and weekly alerts - in a private enterprise dashboard.

Request early access

Compare with similar tools

Airia logo

Airia

78

Airia is an AI platform designed to help enterprise security and IT teams manage and govern AI usage across their organization.

Strong features
Limited data

Custom pricing

View Details
FortiGate logo

FortiGate

71

A network firewall and security appliance by Fortinet serving enterprise, service provider, and government organizations worldwide.

Strong features
Poor support

Custom pricing

View Details