#opengrep — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #opengrep, aggregated by home.social.
-
Opengrep (open-source Semgrep-fork) in v1.24.0 released
https://secburg.com/posts/opengrep-v1240-released/
#Opengrep #SAST #AppSec #StaticAnalysis #OpenSource #semgrep
-
Opengrep (open-source Semgrep-fork) in v1.24.0 released
https://secburg.com/posts/opengrep-v1240-released/
#Opengrep #SAST #AppSec #StaticAnalysis #OpenSource #semgrep
-
@inyourbits On the topic of "vibe coding" I wasn't referring to the LLM'ing of the fixes but the general quality of the SW that needs to be fixed, independent of whether said piece of software was completely manually crafted or LLM'd to some degree.
I do agree that an LLM'd fix that passes some threshold for quality certainly is better than no fix at all.
Generally I'm of the opinion that just like the CI pipelines and QA tools that enabled some sanity in the manual crafted software age, we'll need the same just at larger scale, more tightly integrated into the LLM loops for all the usual QA topics to achieve the same level of sanity under the scale and speed of LLM-assisted software creation.
Together with the advent of more capable, cheaper models such instrumentation might even raise the bar.
Over time, the use of the resulting better SW being used/copied by the LLMs this might even create a useful feedback loop. A possible counterpoint to LLM-dementia if you will.All the LSPs, plugins/hooks for OpenGrep, SonarQube, OSV etc are a good start.
If we get similar hooks that will enforce the most common issues around the various OWASP top lists etc. this might be part of the way to raise the bar. And as always: Enforcement not as prompt but, just like the build breaker in a CI, as technically hardened gate.
#LLM #QA #softwareengineering #aiassisted #owasp #sonarqube #opengrep #raisingthebar
-
Also, notable mention. unexpected thread: https://github.com/lenucksi/aur-malware-check/issues/5
Are there any plans on some bit more central validation, maybe even with some AI/LLM/... with regular conversion of insights to fixed/deterministic rules as discussed throughout the thread? Something something semgrep/opengrep, yara, flathub manifest style etc pp?
Update: Looping in @archlinux here.
Also, any plans on enforcing this -> https://wiki.archlinux.org/title/DeveloperWiki:Building_in_a_clean_chroot for all the AUR build business?Also: How does this incident not yet have a creative name? I'm not asking for a #bumsrakete but there's gotta be something 🤣
Edit: https://jguer.space/blog/2026-06-15-yay-v13 delivered. It's the #AURpocalypse 😱 🤣
#llm #flathub #abuseprevention #malwareCheck #yara #opengrep #archLinux #archlinuxaur #aur #AURpocalypse
-
Also, notable mention. unexpected thread: https://github.com/lenucksi/aur-malware-check/issues/5
Are there any plans on some bit more central validation, maybe even with some AI/LLM/... with regular conversion of insights to fixed/deterministic rules as discussed throughout the thread? Something something semgrep/opengrep, yara, flathub manifest style etc pp?
Update: Looping in @archlinux here.
Also, any plans on enforcing this -> https://wiki.archlinux.org/title/DeveloperWiki:Building_in_a_clean_chroot for all the AUR build business?Also: How does this incident not yet have a creative name? I'm not asking for a #bumsrakete but there's gotta be something 🤣
Edit: https://jguer.space/blog/2026-06-15-yay-v13 delivered. It's the #AURpocalypse 😱 🤣
#llm #flathub #abuseprevention #malwareCheck #yara #opengrep #archLinux #archlinuxaur #aur #AURpocalypse
-
Also, notable mention. unexpected thread: https://github.com/lenucksi/aur-malware-check/issues/5
Are there any plans on some bit more central validation, maybe even with some AI/LLM/... with regular conversion of insights to fixed/deterministic rules as discussed throughout the thread? Something something semgrep/opengrep, yara, flathub manifest style etc pp?
Update: Looping in @archlinux here.
Also, any plans on enforcing this -> https://wiki.archlinux.org/title/DeveloperWiki:Building_in_a_clean_chroot for all the AUR build business?Also: How does this incident not yet have a creative name? I'm not asking for a #bumsrakete but there's gotta be something 🤣
Edit: https://jguer.space/blog/2026-06-15-yay-v13 delivered. It's the #AURpocalypse 😱 🤣
#llm #flathub #abuseprevention #malwareCheck #yara #opengrep #archLinux #archlinuxaur #aur #AURpocalypse
-
«1-РБПО для бедных»: сказ о том, как стартап безопасность прикручивал
https://habr.com/ru/companies/bastion/articles/1038686/«2-РБПО для бедных»: разворачиваем виртуальные машины
https://habr.com/ru/companies/bastion/articles/1038692/«3-РБПО для бедных»: разворачиваем сервисы безопасной разработки
https://habr.com/ru/companies/bastion/articles/1038710/«4-РБПО для бедных»: собираем CI/CD-конвейер безопасной разработки
https://habr.com/ru/companies/bastion/articles/1041724/#devops #security #DefectDojo #PostgreSQL #Redis #Nginx #uWSGI #Celery #DependencyTrack #Checkov #Trivy #Gitleaks #OpenGrep #Nuclei
-
«1-РБПО для бедных»: сказ о том, как стартап безопасность прикручивал
https://habr.com/ru/companies/bastion/articles/1038686/«2-РБПО для бедных»: разворачиваем виртуальные машины
https://habr.com/ru/companies/bastion/articles/1038692/«3-РБПО для бедных»: разворачиваем сервисы безопасной разработки
https://habr.com/ru/companies/bastion/articles/1038710/«4-РБПО для бедных»: собираем CI/CD-конвейер безопасной разработки
https://habr.com/ru/companies/bastion/articles/1041724/#devops #security #DefectDojo #PostgreSQL #Redis #Nginx #uWSGI #Celery #DependencyTrack #Checkov #Trivy #Gitleaks #OpenGrep #Nuclei
-
«1-РБПО для бедных»: сказ о том, как стартап безопасность прикручивал
https://habr.com/ru/companies/bastion/articles/1038686/«2-РБПО для бедных»: разворачиваем виртуальные машины
https://habr.com/ru/companies/bastion/articles/1038692/«3-РБПО для бедных»: разворачиваем сервисы безопасной разработки
https://habr.com/ru/companies/bastion/articles/1038710/«4-РБПО для бедных»: собираем CI/CD-конвейер безопасной разработки
https://habr.com/ru/companies/bastion/articles/1041724/#devops #security #DefectDojo #PostgreSQL #Redis #Nginx #uWSGI #Celery #DependencyTrack #Checkov #Trivy #Gitleaks #OpenGrep #Nuclei
-
«1-РБПО для бедных»: сказ о том, как стартап безопасность прикручивал
https://habr.com/ru/companies/bastion/articles/1038686/«2-РБПО для бедных»: разворачиваем виртуальные машины
https://habr.com/ru/companies/bastion/articles/1038692/«3-РБПО для бедных»: разворачиваем сервисы безопасной разработки
https://habr.com/ru/companies/bastion/articles/1038710/«4-РБПО для бедных»: собираем CI/CD-конвейер безопасной разработки
https://habr.com/ru/companies/bastion/articles/1041724/#devops #security #DefectDojo #PostgreSQL #Redis #Nginx #uWSGI #Celery #DependencyTrack #Checkov #Trivy #Gitleaks #OpenGrep #Nuclei
-
Better Code Scanning? Putting #Opengrep to the Test 🧐
Part of consistently improving our #pentesting procedures includes evaluating the tools we use in our assessments. When conducting code-reviews and pentests of fat-client applications we are often faced with the challenge of identifying vulnerabilities in the targets source code. 🧵
#AppSec #CyberSecurity #InfoSec #Hacking #CodeReview #SourceCode #Semgrep
-
Better Code Scanning? Putting #Opengrep to the Test 🧐
Part of consistently improving our #pentesting procedures includes evaluating the tools we use in our assessments. When conducting code-reviews and pentests of fat-client applications we are often faced with the challenge of identifying vulnerabilities in the targets source code. 🧵
#AppSec #CyberSecurity #InfoSec #Hacking #CodeReview #SourceCode #Semgrep
-
Semgrep Raises $100M for AI-Powered Code Security Platform https://www.securityweek.com/semgrep-raises-100m-for-ai-powered-code-security-platform/ #ApplicationSecurity #MenloVentures #Funding/M&A #Opengrep #Semgrep
-
Semgrep Raises $100M for AI-Powered Code Security Platform https://www.securityweek.com/semgrep-raises-100m-for-ai-powered-code-security-platform/ #ApplicationSecurity #MenloVentures #Funding/M&A #Opengrep #Semgrep
-
Semgrep Raises $100M for AI-Powered Code Security Platform https://www.securityweek.com/semgrep-raises-100m-for-ai-powered-code-security-platform/ #ApplicationSecurity #MenloVentures #Funding/M&A #Opengrep #Semgrep
-
Semgrep Raises $100M for AI-Powered Code Security Platform https://www.securityweek.com/semgrep-raises-100m-for-ai-powered-code-security-platform/ #ApplicationSecurity #MenloVentures #Funding/M&A #Opengrep #Semgrep
-
Here's what #opengrep should have said, IMO:
"Semgrep has made the decision to move some previously-open-source features under a proprietary license for any future development. This left us with a problem to solve, as our customers -- and other users of semgrep-oss -- rely on those features.
We respect Semgrep's business decision. Nevertheless, our concern about this decision and the message that we can't rely on their "open core" to continue to provide popular features has led us to exercise our rights under the LGPL and create Opengrep. We're committed to changing our products to use this fork in order to preserve the features our customers rely on, and intend place governance of the project into the hands of a non-profit foundation to ensure that no single vendor can change licenses or remove features in the future.
We believe that there's a place for both opengrep and semgrep-oss, and are hopeful that good ideas can cross-polinate between the projects."
-
Welp, #opengrep (https://www.opengrep.dev/) is a great example of something that seems like it was a reasonable thing to do, but put together by people who do not understand community relations or messaging.
It's pretty clear that what really happened is that Semgrep moved some features from their LGPL-licensed open-source core into their proprietary-licensed "pro" product (and there were some license changes around community rules, but those were never open-source anyway, so that's whatever).
A bunch of companies that compete with Semgrep at some level relied on those features. They had pretty limited choices to respond, and decided to fork semgrep-oss into opengrep, and commit to giving it to a foundation to defend against future license changes. This is the least-bad outcome for the community (more on that in 🧵 ).
However, the way they made the announcement tries to cast Semgrep as a "bad guy" and act like the opengrep cabal is somehow a champion of open-source -- which is precious because they contributed very little to the open core as it was.
-
Endor Labs and Allies Launch Opengrep, Reviving True OSS for SAST – Source: www.securityweek.com https://ciso2ciso.com/endor-labs-and-allies-launch-opengrep-reviving-true-oss-for-sast-source-www-securityweek-com/ #rssfeedpostgeneratorecho #ApplicationSecurity #SupplyChainSecurity #CyberSecurityNews #securityweekcom #securityweek #opensource #Opengrep
-
Endor Labs and Allies Launch Opengrep, Reviving True OSS for SAST – Source: www.securityweek.com https://ciso2ciso.com/endor-labs-and-allies-launch-opengrep-reviving-true-oss-for-sast-source-www-securityweek-com/ #rssfeedpostgeneratorecho #ApplicationSecurity #SupplyChainSecurity #CyberSecurityNews #securityweekcom #securityweek #opensource #Opengrep
-
Endor Labs and Allies Launch Opengrep, Reviving True OSS for SAST https://www.securityweek.com/endor-labs-and-allies-launch-opengrep-reviving-true-oss-for-sast/ #ApplicationSecurity #SupplyChainSecurity #opensource #Opengrep
-
Endor Labs and Allies Launch Opengrep, Reviving True OSS for SAST https://www.securityweek.com/endor-labs-and-allies-launch-opengrep-reviving-true-oss-for-sast/ #ApplicationSecurity #SupplyChainSecurity #opensource #Opengrep
-
Endor Labs and Allies Launch Opengrep, Reviving True OSS for SAST https://www.securityweek.com/endor-labs-and-allies-launch-opengrep-reviving-true-oss-for-sast/ #ApplicationSecurity #SupplyChainSecurity #opensource #Opengrep
-
Endor Labs and Allies Launch Opengrep, Reviving True OSS for SAST https://www.securityweek.com/endor-labs-and-allies-launch-opengrep-reviving-true-oss-for-sast/ #ApplicationSecurity #SupplyChainSecurity #opensource #Opengrep
-
"We’re launching #Opengrep a fork of SemgrepCS (formerly SemgrepOSS), in response to recent changes by #Semgrep that affect its open-source nature and shift focus to its paid offering, limiting access and innovation for the broader community."
https://www.opengrep.dev/
https://github.com/opengrep/opengrep -
"We’re launching #Opengrep a fork of SemgrepCS (formerly SemgrepOSS), in response to recent changes by #Semgrep that affect its open-source nature and shift focus to its paid offering, limiting access and innovation for the broader community."
https://www.opengrep.dev/
https://github.com/opengrep/opengrep -
OpenGrep sounds like a very interesting community initiative. I really hope this will get traction. The community needs open source tools without licensing pain.
Semgrep has been a great tool and it was just too disappointing to see it go pay walled with time.
#opengrep #semgrep
https://www.opengrep.dev/