Home / Companies / Semgrep / Blog / February 2025

February 2025 Summaries

3 posts from Semgrep

Filter
Month: Year:
Post Summaries Back to Blog
Semgrep's new JavaScript and TypeScript analysis focuses on real-world code to identify nuanced, context-specific vulnerabilities, providing engine-level support for over 50 popular frameworks and libraries such as Express, NestJS, React, and Angular. This approach emphasizes embedding security into daily development workflows rather than relying solely on traditional benchmarks, which often fail to capture the complexities of modern applications. Led by Senior Security Researcher Vasilii Ermilov, Semgrep's initiative has uncovered critical vulnerabilities in open-source projects by addressing OWASP Top Ten vulnerabilities for server-side JavaScript and focusing on client-side issues like DOM XSS and privacy concerns. The evaluation process involves scanning numerous open-source repositories and manually triaging findings to ensure accurate language coverage, boasting a benchmark true positive rate of 63% before AI processing. The upcoming webinar on March 5th will offer a live demo of real vulnerabilities, showcasing how Semgrep's methodology can improve security practices.
Feb 25, 2025 589 words in the original blog post.
Fintech companies, operating in a rapidly evolving sector, face the dual challenge of maintaining security and fostering innovation. Application security tools like Semgrep's SAST (Static Application Security Testing) and SCA (Software Composition Analysis) are crucial for fintechs to manage sensitive data, adhere to complex regulatory requirements, and maintain user trust. These tools facilitate compliance with frameworks such as the Digital Operational Resilience Act (DORA) by integrating security practices into development workflows and providing actionable insights into vulnerabilities. By embedding secure guardrails, Semgrep enhances the speed and efficiency of application security operations, reduces false positives, and incorporates AI-driven remediation guidance, allowing developers to focus on innovation without sacrificing security. Semgrep's solutions are tailored to the dynamic needs of fintech, ensuring applications are secure, scalable, and compliant while minimizing disruption to developer workflows.
Feb 13, 2025 1,159 words in the original blog post.
Semgrep has announced a Series D funding round led by Menlo Ventures, alongside existing investors, to further develop its code scanning platform into an autonomous security solution that reduces noise and commits fixes, thereby freeing security teams for high-impact work. The company aims to address the challenges of an increasing code volume and the stretched capacity of security teams by programming the elimination of classes of security issues and integrating security as a platform engineering exercise. Semgrep's platform, now including a new hybrid engine called Semgrep 2.0, combines traditional techniques with LLM capabilities to provide deterministic, context-aware, and persuasive security analysis. The platform supports approximately 40 languages and serves diverse users from large tech companies to startups, aiming to be a low-noise, high-signal option for application security teams. As part of its growth strategy, Semgrep has welcomed Garrett Souza as VP of Sales and Mark McLaughlin as a board observer, both bringing significant experience to enhance the company's mission of making autonomous application security engineering more accessible and effective.
Feb 05, 2025 920 words in the original blog post.