Semgrep
Semgrep is a static analysis tool that helps developers and security teams find bugs and enforce code standards across codebases.
About this data
Updated June 29, 2026
Overall Pulse Score
+15 over this period
A 0-100 index summarizing the tone of 452 relevant public mentions gathered from public online communities across 16 weeks in the selected period. It measures online sentiment, not a rating of the product's quality.
Weekly Sentiment Trend
Pulse Score by week over the selected period. Each point is one complete week of mentions.
This week in public discussion
Discussion around Semgrep over the recent period was dominated by bug reports and reliability concerns, with commenters raising repeated issues around path handling errors in hook scripts across WSL, Windows, and git worktree environments. Several mentions flagged silent scan failures as a particular frustration. On the positive side, some discussion focused on integration work and CI pipeline improvements. The overall tone skewed negative, with bug and reliability complaints outnumbering praise themes by a considerable margin.
Read the deeper analysisAI-generated summary of public online discussion during this period. It reflects the tone of that discussion, not facts about the product or our views.
Sentiment mix by week
How the tone of public discussion splits each week.
Ringed points mark weeks with unusually high discussion volume, more than double this product's typical week.
Most-discussed praise
Most-discussed complaints
Themes across the selected period, with mention counts.
How Semgrep compares
Pulse Score over the selected period versus the top tracked competitors in Security.
Where the mentions come from
Share of the 452 relevant public mentions in the selected period, by source.
Sample public mentions
Showing 5 of 452 analyzed public mentions in this period, with links to the original source. We do not reproduce full threads.
“semgrep scan generates findings for ignored code blocks if the --sarif-output option is specified. **Describe the bug** According to the documentation, an inline comment followed by the nosemgrep word can be used to ignore blocks of code. However, if the --sarif-output option is ...”
“Hook binary doubles absolute file_path (no IsAbs check) → open: no such file noise + silent SAST no-op in git worktrees. ## Summary The hook registered for Write|Edit|Bash (Pre/PostToolUse) joins the current working directory onto tool_input.file_path **without checking whether f...”
“Please make the pyjwt depdency looser. Hello! Currently, semgrep depends on pyjwt~=2.12.0. This means we must use PyJWT 2.12.X in our project. We want to use version 2.13.0, but that conflicts. Can semgrep depend on pyjwt~=2.12 so we can then bump to 2.13.X? Thanks!”
“**Semgrep identified an issue in your code:**. **Semgrep identified an issue in your code:** An action sourced from a third-party repository on GitHub is not pinned to a full length commit SHA. Pinning an action to a full length commit SHA is currently the only way to use an acti...”
“**Semgrep identified an issue in your code:**. **Semgrep identified an issue in your code:** An action sourced from a third-party repository on GitHub is not pinned to a full length commit SHA. Pinning an action to a full length commit SHA is currently the only way to use an acti...”
447+ more analyzed mentions, full history, and theme breakdowns are part of Pro.
Get ProDeeper analysis
- Bug reports and reliability complaints dominated the conversation, outnumbering praise themes by a wide margin over the four-week window.
- Sentiment climbed briefly in mid-May then fell back as mention volume spiked in June, ending the period in a flat, middling range without clear recovery.
- Opinion was divided on dependency pinning strictness, with some commenters expressing friction while others appeared to accept the constraints.
- Silent failure modes in security scanning contexts drew notably sharper negative tone than bugs that surfaced visible errors.
| Praise theme | Mentions |
|---|---|
| Strong features | 80 |
| Good integrations | 48 |
| Compared to rivals | 21 |
| Security praise | 13 |
| Feature requests | 11 |
| Complaint theme | Mentions |
|---|---|
| Bugs | 126 |
| Reliability | 83 |
| Missing features | 59 |
| Feature requests | 32 |
| Lacking integrations | 8 |
Public discussion around Semgrep over the past four weeks was dominated by a persistent undercurrent of frustration, with bug reports and reliability concerns accounting for the largest share of complaint-side mentions by a considerable margin. Commenters surfaced a recurring class of path-handling errors, with several mentions describing hook scripts that incorrectly prepend working directory paths to already-absolute file paths, producing doubled paths and silent scan failures across Windows, WSL, and git worktree environments. This pattern of quiet, hard-to-detect breakdowns seemed to heighten irritation, as discussion suggested that a tool failing silently in a security context is treated as a more serious offense than one that fails loudly.
Sentiment trajectory across the window was unsteady. Early weeks showed very low scores on minimal mention volume, then climbed into the low-to-mid fifties around mid-May before sliding back as mention counts surged in early and mid-June. The largest bursts of activity coincided with score dips, which discussion suggested reflects moments when a wider audience encountered reproducible problems and brought them into public view at once. By the final tracked week sentiment had settled into a narrow, middling band without meaningful recovery.
On the praise side, feature appreciation and integration quality drew the most positive attention, and competitor comparison threads occasionally framed Semgrep favorably, though those threads were a small slice of overall volume. Divided opinion was clearest around dependency management, where commenters expressed frustration with tight version pinning on transitive dependencies while others appeared neutral or sympathetic to the maintenance rationale. Feature-bucketing and workflow classification decisions also drew split reactions, with some discussion questioning whether current categorization choices matched user mental models. Overall tone leaned skeptical, with reliability concerns outweighing positive signals across the window.
AI-generated summary of public online discussion during this period. It reflects the tone of that discussion, not facts about the product or our views.
Member perspectives
Individual opinions from Pro members, posted over time. These are personal member views, not aggregated sentiment data.
Overall Pulse Score
+15 over this period
A 0-100 index summarizing the tone of 452 relevant public mentions gathered from public online communities across 16 weeks in the selected period. It measures online sentiment, not a rating of the product's quality.
Data summary
Compare with another tool
Semgrep
46
Trainual
88
Score-level preview from live weekly tracking.
Are you Semgrep?
Get a private enterprise dashboard for your product - full history, every source, theme deep-dives, and weekly alerts. You can also respond to the data shown here.
Explore the enterprise dashboardAffiliate disclosure
Some links on this site may be affiliate links. If you click one and make a purchase, we may earn a commission at no extra cost to you. Learn more.
Is Semgrep your product?
See everything behind this page - full history, every source, theme deep-dives, and weekly alerts - in a private enterprise dashboard.
Request early accessCompare with similar tools
Airia
Airia is an AI platform designed to help enterprise security and IT teams manage and govern AI usage across their organization.
Custom pricing
View DetailsFortiGate
A network firewall and security appliance by Fortinet serving enterprise, service provider, and government organizations worldwide.
Custom pricing
View Details