Home / Companies / Semgrep / Blog / November 2024

November 2024 Summaries

2 posts from Semgrep

Filter
Month: Year:
Post Summaries Back to Blog
Semgrep Managed Scanning has expanded its integration to include both GitLab.com and GitLab Self-Managed, in addition to its existing support for GitHub.com and GitHub Enterprise, allowing AppSec professionals to deploy code scanning infrastructure with minimal resource expenditure. This new feature, now available in public beta, enables users to onboard repositories seamlessly by connecting to GitLab Groups with an access token, setting up necessary GitLab webhooks, and managing scans without requiring internal servers or CI/CD pipeline configurations. The system conducts full scans weekly and diff scans on every pull request, with findings delivered as merge request comments based on predefined Semgrep policy settings. By eliminating the overhead of managing CI pipelines, Semgrep Managed Scanning allows users to focus on higher priority tasks in application security while ensuring repositories are continuously monitored and secure.
Nov 18, 2024 485 words in the original blog post.
Semgrep, originally an open-source code scanning tool, has evolved into a comprehensive AppSec Platform with an expanded range of products. As the company has grown to over 150 employees and millions of scans monthly, it has faced confusion regarding the distinction between its open-source offering, Semgrep OSS, and its commercial products. The company plans to rename Semgrep OSS to better reflect its purpose and differentiate it from competitors' offerings that may misrepresent its capabilities. To address these concerns, Semgrep is seeking community input via a survey on the new name and is launching efforts to ensure vendors accurately represent the open-source tool. Additionally, a Verified Partners Program will be introduced to support partners who transparently use Semgrep OSS, aligning both open-source and commercial products with their foundational principles. This initiative aims to maintain a balance between growing the business and nurturing a supportive community, with a long-term vision of enhancing software security and reliability.
Nov 01, 2024 414 words in the original blog post.