OpenGrep Restores Fingerprinting in JSON and SARIF Outputs -...
Blog post from Socket
OpenGrep, an open-source static application security testing (SAST) engine, has reintroduced fingerprint and metavariable support in JSON and SARIF outputs, significantly enhancing its utility for CI/CD security automation by restoring functionality that had been removed from Semgrep Community Edition. This update, along with the launch of the Playground desktop app for rule development, addresses automation challenges by providing reliable fingerprinting, which is crucial for tracking issues across code changes. Developed in response to Semgrep's shift towards proprietary licensing, OpenGrep is a collaborative effort by several security vendors to create a more open tool. The team is also working on a major advancement in context-aware fingerprinting to improve the tracking of code changes, which is especially important for large-scale projects. Guided by community feedback and a public roadmap, OpenGrep continues to release updates weekly, with plans for additional features like Elixir language support and cross-function analysis.
No tracked trend matches for this post yet.
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.