Skip to content

project

Semgrep

Open-source static analysis tool that scans source code in many languages for bugs, security flaws, and anti-patterns using customizable rules.

Current stories

build1 publisher

Compromised MemOS packages scan for developer tokens the moment Python imports them

Semgrep found sckit hidden in the genuine MemOS npm and PyPI packages, where it fires on Python import to scan for npm, GitHub, cloud and Slack tokens. It runs on import, not on install, so install-time scanning misses it, and anyone who imported an affected version should rotate those tokens.

Publishers:dev.to

Reality

Evidence45
Adoption
Insufficient
Hype gap+25
Incentives
Insufficient
Confidence50