May 2025 Summaries
2 posts from Semgrep
Filter
Month:
Year:
Post Summaries
Back to Blog
Replit has partnered with Semgrep to enhance the security of software development by integrating a pre-deployment scanning feature that allows users to automatically detect and fix security issues in their code directly from their browser. This feature, powered by Semgrep CE, enables Replit users to run security scans that identify vulnerabilities, exposed secrets, and outdated dependencies before deployment, supporting languages like Python, JavaScript, and TypeScript. Replit Agent can address these issues with a single click, making secure coding an effortless background process without requiring security expertise or context switching. This collaboration aims to make secure software development accessible to all, from individual developers to enterprise security engineers, by embedding real-time, intelligent scanning and using secure-by-default frameworks and libraries. Interested users can learn more about these features and their benefits in an upcoming webinar titled "Vibe Coding, But Make it Safe."
May 15, 2025
479 words in the original blog post.
RSA 2025 emphasized the theme "Many Voices. One Community," promoting collaboration between developers, security engineers, and operations to create secure, efficient software without hindering development speed. Luke O'Malley, Co-founder of Semgrep, introduced a developer-first vision for application security, advocating for an approach that uses AI to augment human efforts while maintaining developer autonomy. This vision is encapsulated in the "AppSec for Builders" philosophy, which focuses on providing guardrails rather than gates, ensuring real-world impact over audit perfection, and leveraging AI for prioritizing tasks. Semgrep's platform facilitates early and frequent collaboration across teams, aiming to shift security from a bottleneck to a shared responsibility. O'Malley highlighted the importance of context in security decisions and the need for tools that are flexible and developer-centric, contrasting traditional compliance-focused tools that often create noise and inefficiencies. The company envisions a future where enhanced collaboration, empowered by AI and modernized tools, naturally integrates security into the software development lifecycle.
May 12, 2025
841 words in the original blog post.