A fast universal code security scanner, written in Rust. Batteries included: supports 14 languages, TUI for triage, secrets, post-quantum audits, diff-aware scans and more 𓃥
-
Updated
Jul 27, 2026 - Rust
A fast universal code security scanner, written in Rust. Batteries included: supports 14 languages, TUI for triage, secrets, post-quantum audits, diff-aware scans and more 𓃥
Prevent merging of malicious code in pull requests
Focused malicious code detection ruleset, with a high protection-to-noise ratio
Autogrep automates Semgrep rule generation and filtering by using LLMs to analyze vulnerability patches, enabling automatic creation of high-quality security rules without manual curation.
Local-first MCP security scanner for AI-generated apps. Scan → fix → rescan from Claude Code, Cursor, Codex, and other agents.
Reusable GitHub Actions guardrails for pull requests: OpenGrep SAST, verified TruffleHog secrets, dependency review, and Trivy supply-chain checks — high signal, low noise.
Mine bug-fix history → synthesize static-analysis rules → validate → ship as CI gates
Official redistributable gate-pack manifests for Hardrails
Manage OpenGrep security rules, run project scans, and triage findings through a self-hosted dashboard.
Add a description, image, and links to the opengrep topic page so that developers can more easily learn about it.
To associate your repository with the opengrep topic, visit your repo's landing page and select "manage topics."