$npx skillfedfor your agent

semgrep

Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.

With conditionsPyPI SecurityReleased Aug 202635.5M downloads / moLGPL-2.1-or-laterPlatform wheel

Decision gist · record as of 2026-08-14

platform wheels — semgrep-1.173.0-cp310.cp311.cp312.cp313.cp314.py310.py311.py312.py313.py314-none-macosx_10_14_x86_64.whl · semgrep-1.173.0-cp310.cp311.cp312.cp313.cp314.py310.py311.py312.py313.py314-none-macosx_11_0_arm64.whl · semgrep-1.173.0-cp310.cp311.cp312.cp313.cp314.py310.py311.py312.py313.py314-none-manylinux_2_34_aarch64.whl
v1.173.0 · released 2026-08-13 · Python >=3.10 · 27 runtime deps: attrs, boltons, click-option-group, click, colorama, exceptiongroup, glom, jsonschema

Yes, with conditions. Semgrep is actively maintained, widely used (top 1000 PyPI packages), has no known vulnerabilities, and is suitable for development-time code scanning and policy enforcement. Install it if you need multi-language static analysis and are comfortable with the LGPL-2.1-or-later license. For production security scanning (SAST, SCA, secrets), the AppSec Platform is strongly recommended over Community Edition alone, as single-file analysis misses cross-function vulnerabilities.AI-flagged interpretation of the facts on this page — verify before relying

Before you install

  • Requires Python 3.10 or later.
  • For full security scanning capabilities (SAST, SCA, secrets), the Semgrep AppSec Platform is recommended; Community Edition has single-file/function analysis limits.
  • Medium install friction due to 27 runtime dependencies and compiled wheels for multiple platforms.

License · maintenance · safety

LGPL-2.1-or-later (copyleft) — Semgrep is licensed under LGPL-2.1-or-later (copyleft). This means any modifications to the package itself must be released under the same or compatible license, though using it as a dependency in your own projects does not impose this requirement on your code.

last release 2026-08-13 (1 days) · last repo commit 2026-08-14 · 16,208 stars

0 known vulnerabilities (OSV.dev, 2026-08-14) · 35,516,275 downloads/mo, #746 on PyPI

Verify before relying

pip install semgrep
semgrep --version
semgrep -e '$X == $X' --lang=py path/to/src
  • Whether the 30+ language support claim includes all languages equally or if some have limited rule coverage
  • Performance characteristics and typical scan time for codebases of various sizes
  • Whether all 27 runtime dependencies are required for basic CLI usage or if some are optional
Same gist for agents: .md · .json

What it is and what it does

Semgrep is a semantic code analysis engine that finds bugs and security issues by matching code patterns rather than simple text strings. It works locally on your machine or build environment—code is not uploaded by default—and supports 30+ languages including Python, JavaScript, Java, Go, Rust, and many others. The Community Edition is suitable for ad-hoc scanning and development workflows, though it analyzes code within single-file or single-function boundaries.

The package includes a CLI for running scans, integrations with CI/CD systems, and optional login to access the Semgrep AppSec Platform, which adds cross-file analysis, AI-powered triage, and 600+ proprietary security rules. It can be deployed as a pre-commit hook, in an IDE, or as part of automated security workflows. The tool requires Python 3.10 or later and has a substantial dependency tree (27 runtime packages) that includes CLI utilities, telemetry, and data processing libraries.

Use it for

  • Run ad-hoc security scans on your codebase to find common vulnerability patterns before committing code
  • Enforce custom coding standards and policy checks across a team by writing patterns that match your organization's rules
  • Integrate into CI/CD pipelines to automatically scan pull requests for bugs and security issues
  • Scan dependencies for known vulnerabilities via Semgrep Supply Chain (requires login to AppSec Platform)
  • Use as a pre-commit hook to catch issues locally before code reaches version control

Worth the install?

AI-flagged interpretation of the facts on this page. Verify before relying on it.

With conditions

Yes, with conditions.

Semgrep is actively maintained, widely used (top 1000 PyPI packages), has no known vulnerabilities, and is suitable for development-time code scanning and policy enforcement. Install it if you need multi-language static analysis and are comfortable with the LGPL-2.1-or-later license. For production security scanning (SAST, SCA, secrets), the AppSec Platform is strongly recommended over Community Edition alone, as single-file analysis misses cross-function vulnerabilities.

Install

semgrep on PyPI

Before you install

Medium install friction due to 27 runtime dependencies and compiled wheels for multiple platforms. The package is actively maintained with a recent release (1 day old) and strong community backing (16208 GitHub stars), indicating reliable ongoing support.

Requires Python 3.10 or later. For full security scanning capabilities (SAST, SCA, secrets), the Semgrep AppSec Platform is recommended; Community Edition has single-file/function analysis limits.

License in practice

Semgrep is licensed under LGPL-2.1-or-later (copyleft). This means any modifications to the package itself must be released under the same or compatible license, though using it as a dependency in your own projects does not impose this requirement on your code.

Quickstart

pip install semgrep
semgrep --version
semgrep -e '$X == $X' --lang=py path/to/src

Verify before relying

  • Whether the 30+ language support claim includes all languages equally or if some have limited rule coverage
  • Performance characteristics and typical scan time for codebases of various sizes
  • Whether all 27 runtime dependencies are required for basic CLI usage or if some are optional

Package facts

LicenseLGPL-2.1-or-later copyleft
Python supportSupports the current Python release >=3.10
Install frictionMedium. Platform-specific wheel
Runtime dependencies
27 packages
attrsboltonsclick-option-groupclickcoloramaexceptiongroupglomjsonschemamcpopentelemetry-apiopentelemetry-sdkopentelemetry-exporter-otlp-proto-httpopentelemetry-instrumentation-requestsopentelemetry-instrumentation-threadingpackagingpeeweepyjwtrequestsrichruamel.yamlruamel.yaml.clibsemantic-versiontomlityping-extensionsurllib3wcmatchpywin32
MaintenanceActively maintained 1 days since the last release
Last repo commit
First released
Downloads35,516,275 / month, #746 on PyPI 30-day window, as of 2026-08-14
Known vulnerabilitiesNone known OSV.dev, checked 2026-08-14
Classifiers
Environment :: ConsoleOperating System :: MacOSOperating System :: Microsoft :: WindowsOperating System :: POSIX :: LinuxProgramming Language :: Python :: 3.10Programming Language :: Python :: 3.11Programming Language :: Python :: 3.12Programming Language :: Python :: 3.13Programming Language :: Python :: 3.14Topic :: SecurityTopic :: Software Development :: Quality Assurance

Evidence: semgrep-1.173.0-cp310.cp311.cp312.cp313.cp314.py310.py311.py312.py313.py314-none-macosx_10_14_x86_64.whl; semgrep-1.173.0-cp310.cp311.cp312.cp313.cp314.py310.py311.py312.py313.py314-none-macosx_11_0_arm64.whl; semgrep-1.173.0-cp310.cp311.cp312.cp313.cp314.py310.py311.py312.py313.py314-none-manylinux_2_34_aarch64.whl; semgrep-1.173.0-cp310.cp311.cp312.cp313.cp314.py310.py311.py312.py313.py314-none-manylinux_2_34_x86_64.whl; semgrep-1.173.0-cp310.cp311.cp312.cp313.cp314.py310.py311.py312.py313.py314-none-musllinux_1_2_aarch64.whl; semgrep-1.173.0-cp310.cp311.cp312.cp313.cp314.py310.py311.py312.py313.py314-none-musllinux_1_2_x86_64.whl; semgrep-1.173.0-cp310.cp311.cp312.cp313.cp314.py310.py311.py312.py313.py314-none-win_amd64.whl

Tags

Capabilities
static code analysissecurity vulnerability scanningcode pattern matchingSAST toolbug detectionpolicy enforcementmulti-language code scanner
Topics
security-scanningstatic-analysisci-cd

Let your AI agent find packages like this

Example. Real query, live index.

An agent finds packages by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language. Give your agent the search over MCP.

More Security packages

SecretStorage With conditions
PyPI · Python Modules · released Nov 2025

Provides Python bindings to the FreeDesktop.org Secret Service API for securely storing and retrieving passwords and secrets through GNOME Keyring, KWallet, or KeePassXC.

BSD-3-Clausepure Python · 3.10+aging
226.9Mdownloads / mo
msal Worth it
PyPI · Security · released May 2026

MSAL for Python handles OAuth2 and OpenID Connect authentication with Microsoft identity services, managing token acquisition, caching, and refresh for applications integrating with Microsoft Entra ID, Microsoft Accounts, and Azure AD B2C.

MITpure Python · 3.9+
223.0Mdownloads / mo
joserfc Worth it
PyPI · Security · released Jul 2026

joserfc implements JOSE standards (JWS, JWE, JWK, JWT, and related RFCs) for signing, encrypting, and managing JSON-based cryptographic tokens in Python.

BSD-3-Clausepure Python · 3.10+
155.5Mdownloads / mo
Authlib Worth it
PyPI · Security · released May 2026

Authlib provides a complete implementation of OAuth 1.0, OAuth 2.0, and OpenID Connect 1.0 for building both authentication clients and servers, with built-in support for JWS, JWK, JWA, and JWT standards.

BSD-3-Clausepure Python · 3.10+
155.1Mdownloads / mo
argon2-cffi-bindings With conditions
PyPI · Python Modules · released Jul 2025

Provides low-level CFFI bindings to the official Argon2 password hashing algorithm for use by libraries and applications that need direct access to Argon2 without higher-level abstractions.

MITcompiled wheel · 3.9+
74.2Mdownloads / mo
adal Skip
PyPI · Security · released Apr 2021

ADAL for Python authenticates applications with Azure Active Directory to obtain tokens for accessing Azure AD-protected resources.

Install only if maintaining existing code that already depends on it, and plan a migration.

MITpure Pythonabandoned
44.5Mdownloads / mo

See also njsscan · skylos · libsast · mobsfscan · kingfisher-bin · cycode · bbot · bandit · truffleHog · sigmatools

Further reading