Endor Labs has collaborated with Aikido Security, Arnica, Amplify, Kodem, Legit, Mobb, and Orca Security to introduce Opengrep, an initiative designed to maintain open access to static code analysis tools for application security.
Opengrep, which is a fork of Semgrep OSS, responds to changes by Semgrep that have complicated its open-source capabilities and limited broader access to essential security functions. Many open-source codebases rely on Static Application Security Testing (SAST) as security threats increase in complexity.
The project emerges as Semgrep implemented significant alterations to its open-source features, putting essential rule contributions under a proprietary license and shifting critical scanning features to a commercial SaaS platform. This shift creates barriers for developers and security teams, complicating the process of maintaining security measures throughout the software development lifecycle.
Opengrep is built on the principles of true open source accessibility, community governance, and a roadmap toward foundation management, ensuring long-term viability. It offers full access to all scanning capabilities without restrictions, compatibility with existing workflows, and portable security rules.
“Static code analysis is too important to be restricted,” said Varun Badhwar, CEO and co-founder of Endor Labs. He emphasizes that Opengrep aims to foster collaboration rather than commercial interests in the evolution of security tools.
Developers can benefit from Opengrep's features while adhering to an open-source framework that prioritizes community input and accessibility.
Comments