Meilleures alternatives à Semgrep les mieux notées
Avis sur 31 Semgrep
Sentiment de l'avis global pour Semgrep
Connectez-vous pour consulter les sentiments des avis.

C'est l'intégration la plus efficace et la plus simple à utiliser pour SAST.
Gratuit et dirigé par la communauté
Les discussions sur les canaux Slack offrent une aide précieuse et des perspectives. Avis collecté par et hébergé sur G2.com.
Rien de majeur. Il évolue dans la bonne direction. Avis collecté par et hébergé sur G2.com.
Semgrep makes it really easy to write rules. It's really straightforward and the UI also allows you to easily get feedback on rules as well. The dashboard is also convenient and simple to use. The customer support is also pretty amazing, in that they will help you over a meeting with issues you may have with implementation. Avis collecté par et hébergé sur G2.com.
The binary has been buggy in the past, and has required some debugging and patching to get working correctly. However, the Semgrep team was helpful with the entire process. Avis collecté par et hébergé sur G2.com.
Super easy to implement and manage. Seamless integration into our CI pipeline, and only gets in the developers' way when it needs to. Reachability testing of depenencies is nice. Avis collecté par et hébergé sur G2.com.
Not too much to dislike. The Supply Chain/dependency scanning is new and will need more rules for reachability, but these are gradually being built. Avis collecté par et hébergé sur G2.com.
The upsides are that code scanning is very fast, and the ruleset is complete. Rule management on the rule board is also very easy. Integrations and webhooks are a plus. Avis collecté par et hébergé sur G2.com.
The downsides are that the number of false positives for some of the rules is enormous due to the lack of taint tracking support for PHP. Improving this ruleset, or adding taint tracking for PHP would be most helpful. Avis collecté par et hébergé sur G2.com.
Great analysis of vulnerabilities with ability to review, rank and update status of each incident Avis collecté par et hébergé sur G2.com.
It would be great if Semgrep did further static analysis to cover code smells and code coverage, in addition to security. Avis collecté par et hébergé sur G2.com.
It's a super customizable, fast and effective tool to have as an inline scanner on the CI/CD pipeline. Avis collecté par et hébergé sur G2.com.
Nothing really - support is amazing and while they are still early in developing their product suite, they are super receptive to feedback Avis collecté par et hébergé sur G2.com.
It runs super quickly and consistently produces some of the highest-quality and relevant findings I've seen when comparing against other options. Avis collecté par et hébergé sur G2.com.
The web app could use some polish, but they're focused on rapid improvements. Avis collecté par et hébergé sur G2.com.
Very easy to set up and the time to value is very short. Avis collecté par et hébergé sur G2.com.
I wish the rules had more information on remediation. Avis collecté par et hébergé sur G2.com.
1 - Security inforcment.
2 - Finding common bugs in code. Avis collecté par et hébergé sur G2.com.
It was hard for to set it up with my GitHub repo, so things here can be improved for the future. Avis collecté par et hébergé sur G2.com.
I love how customizable semgrep is in terms of identifying static as well as prod sec vulnerabilities Avis collecté par et hébergé sur G2.com.
No standard set of error checks for static analysis atleast. Has to be customized Avis collecté par et hébergé sur G2.com.