Semgrep
PaketStatic application-code security scanning with a local CLI and MCP server
- Erişim
- None, runs locally
Hakkında
Semgrep Community Edition scans application source code with structural rules from a local CLI without an account. Its official CLI also offers a local MCP server. Advanced cross-file analysis and hosted AppSec workflows are paid features; Community Edition has narrower analysis.
Neler yapabilirsin
- Scan application source code for unsafe patterns before merging changes
- Write custom structural rules for security policies in your codebase
- Let a coding agent invoke the local MCP server to inspect generated code
Başlarken
- Install the Semgrep CLI with Python 3.10 or newer
- Run semgrep scan with a rule configuration or start semgrep mcp
- Use local scans without login; authenticate for paid platform workflows
Örnek kod
semgrep scan --config auto .
# Optional local MCP transport
semgrep mcp --transport stdioAyrıntılar
- Barındırma
- Kendi bilgisayarında
- Kullanılabildiği yerler
- Tüm dünya
- MCP sunucusu
- Yerel sunucu