Home / Companies / Socket / Blog / Post Details
Content Deep Dive

OpenGrep Restores Fingerprinting in JSON and SARIF Outputs -...

Blog post from Socket

Post Details
Company
Date Published
Author
Sarah Gooding
Word Count
510
Company Posts That Month
19
Language
English
Hacker News Points
-
Post removed?
No
Summary

OpenGrep, an open-source static application security testing (SAST) engine, has reintroduced fingerprint and metavariable support in JSON and SARIF outputs, significantly enhancing its utility for CI/CD security automation by restoring functionality that had been removed from Semgrep Community Edition. This update, along with the launch of the Playground desktop app for rule development, addresses automation challenges by providing reliable fingerprinting, which is crucial for tracking issues across code changes. Developed in response to Semgrep's shift towards proprietary licensing, OpenGrep is a collaborative effort by several security vendors to create a more open tool. The team is also working on a major advancement in context-aware fingerprinting to improve the tracking of code changes, which is especially important for large-scale projects. Guided by community feedback and a public roadmap, OpenGrep continues to release updates weekly, with plans for additional features like Elixir language support and cross-function analysis.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.