Opengrep Adds Apex Support and New Rule Controls in Latest Updates
Blog post from Socket
Opengrep, an open-source static application security testing (SAST) engine, has introduced significant updates that include native support for Salesforce's Apex language, allowing it to be the only free and open-source SAST tool with such capability. The updates also feature enhanced rule configuration options, performance improvements, and bug fixes, driven by a rapid weekly release cycle that stems from community feedback and aims to close the gap between open source and commercial SAST tools. Since its fork from Semgrep CE, Opengrep has focused on making its engine more flexible and CI/CD-ready, addressing areas that other open source tools have overlooked, particularly in handling Salesforce-specific query structures in Apex. The new features, such as the `max_match_per_file` option and improved taint tracking, enhance configurability and precision, while performance and usability improvements, like inline metavariables in JSON output, further bolster its utility in enterprise environments. These developments position Opengrep as a viable alternative to costly commercial solutions by providing a more agile, cost-effective tool for enterprise users in need of robust static code analysis capabilities.
No tracked trend matches for this post yet.
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.