softwarefactory.build

Directory / Semgrep

Semgrep

Verified

Teachably fast static analysis with optional AI-assisted rules.

Semgrep is a static analysis engine with pattern rules, a registry, CI integration, and a commercial app. The deterministic verification layer can also check rules generated by agents.

Model support
Multi-model
Deployment
Cloud, Self-hosted
Open source
Yes
License
LGPL-2.1 (engine); Semgrep App is commercial
Pricing model
Mixed
Added / updated
19 Aug 2026 / 19 Aug 2026

semgrep.dev · Docs · Source

Assessment

Semgrep provides deterministic checks without a judge model. Protect rule configuration from agent edits, and treat the open engine separately from the Team and Enterprise application.

Strengths

  • Deterministic, fast, CI-native analysis.
  • Open engine you can run offline.
  • Rules can encode factory invariants the LLM must not violate.

Limitations

  • Not an agent. Will not implement the feature.
  • App vs OSS feature split.
  • Rule quality is still engineering work.

Fields last checked against primary sources on . Pricing and plan names change; check the vendor URL.