Semgrep Fall '23 Launch: improved coverage + enterprise fit
Blog post from Semgrep
This quarter, Semgrep has focused on expanding language coverage and enhancing enterprise features, launching Semgrep Secrets and introducing significant support updates for languages like C#, Swift, Rust, and Dart. The updates are designed to ensure comprehensive language support for modern engineering teams, with C# now fully supported in both Semgrep Code and Semgrep Supply Chain, allowing for advanced reachability analysis and cross-file vulnerability detection. Swift support is in beta, Rust support has reached general availability, and experimental Dart support has been added. Additionally, Semgrep is enhancing developer workflows by introducing a beta plugin for IntelliJ IDE products, complementing existing support for Visual Studio Code, and integrating Semgrep Assistant with GitLab to aid in identifying and fixing vulnerabilities. Semgrep Supply Chain now supports SBOM exports in the CycloneDX format, enriched with vulnerability data to help security engineers maintain compliance with the latest regulations. These updates underscore Semgrep's commitment to providing a unified platform for application security that caters to both developers and security teams without compromising on quality or productivity.