Semgrep

Semgrep themed logo

Find bugs and reachable dependency vulnerabilities in code. Enforce your code standards on every commit.

Scan with Semgrep AppSec Platform

Deploy static application security testing (SAST), software composition analysis (SCA), and secrets scans from one platform.

Supported languages

ProductLanguages
Semgrep Code

Generally available (GA)
C and C++ • C# • Generic • Go • Java • JavaScript • JSON • Kotlin • Python • TypeScript • Ruby • Rust • JSX • PHP • Scala • Swift • Terraform

Beta
APEX • Elixir

Experimental
Bash • Cairo • Circom • Clojure • Dart • Dockerfile • Hack • HTML • Jsonnet • Julia • Lisp • Lua • Move on Aptos • Move on Sui • OCaml • R • Scheme • Solidity • YAML • XML

Semgrep Supply Chain

Generally available reachability
C# • Go • Java • JavaScript and TypeScript • Kotlin • PHP • Python • Ruby • Rust • Scala • Swift

Languages without support for reachability analysis
Dart • Elixir

Semgrep SecretsLanguage-agnostic; can detect 630+ types of credentials or keys.

See Supported languages documentation for more details.

What’s New

See the latest Semgrep product highlights and weekly release notes.

Read the original on docs.semgrep.dev ↗