Semgrep
CAUTION: Qilin ransomware group publicly listed Semgrep as a victim (claimed May 22, 2026; tracker-reported discovery May 25) alleging data exfiltration — unconfirmed by Semgrep, absent from status.semgrep.dev, scope unknown.
Dimension breakdown
Score · confidenceQilin ransomware group publicly listed Semgrep as a victim (claimed May 22, 2026; tracker-reported discovery May 25) alleging data exfiltration — unconfirmed by Semgrep, absent from status.semgrep.dev, scope unknown.
AI-augmented AppSec platform combining deterministic SAST/SCA/Secrets with LLM reasoning (Semgrep Multimodal GA, March 2026, built on Semgrep Workflows). AI-powered Detection GA-track (March beta → April findings API + Jira ticketing + AI-credits dashboard) for IDOR/broken-auth; Autotriage cuts ~60% of backlog on first use.
MCP server (Hooks + Skills) scans every file from Claude Code/Cursor/Windsurf/Codex. Vendor-reported (not independently validated) 8x true positives / 50% fewer false positives vs foundation models alone.
SOC 2 Type II, SAML/OIDC SSO, RBAC, audit logs, AI training opt-out. 18K+ orgs, 257 employees (+22% YoY), Series D $100M / ~$204M total (Sequoia, Menlo, Lightspeed). Named refs: Snowflake, Figma, Lyft, Dropbox, GitLab, Vanta; LinkedIn runs it as one of several scanners (GitHub Actions + CodeQL + Semgrep, InfoQ Feb 2026).
G2 4.6/55; SAST mindshare 2.8% (2x YoY).
unresolved breach claim; Custom Workflows gated; IntelliJ extension CE-only (no Pro/Supply Chain/Secrets); SCIM unconfirmed; US-only residency; Opengrep fork (Codacy migrated).
Use cases
Not yet assessed — this section fills in as ACES research covers the tool.
Risk flags
No active caps — no risk flags apply to this tool right now.
Status rationale
Tracked because Semgrep has a strong research-based baseline (extensive vendor docs, multiple independent SAST comparisons, third-party case studies via InfoQ/Gartner Peer Insights, G2 4.6/55) but no internal hands-on testing has been performed — and an unresolved, publicly-claimed (Qilin, unverified by Semgrep) ransomware/data-exfiltration listing is itself a reason not to elevate until clarified. Rating 71 with evidence grade B (depth=thorough full-research pass, handsOn=not_tested).
Re-baselined under evalModel claude-opus-4-8. Upgrade to Assessed when WWT pilots Semgrep on a sample codebase and independently validates the Multimodal accuracy claims (which remain vendor-reported), or when an internal evaluation captures real-world false-positive rates against our code patterns — and after the breach claim is resolved with no confirmed customer-data exposure.
Movement triggers
Upgrade if: Semgrep confirms the May 2026 breach claim was contained with no customer source-code/scan-data exposure (post-mortem published) and trust signals recover; Custom Workflows exits gating with documented enterprise adoption; SCIM ships; IntelliJ extension reaches Pro/Supply-Chain/Secrets parity; EU data residency launches; independent (non-vendor) benchmark validates the 8x TP / 50% FP Multimodal claims; named Fortune 500 customer goes on-record with deployment metrics. Downgrade if: Qilin leak materializes with confirmed customer data/source-code exposure (would trigger critical-security-vuln cap → compliance ≤5 and cap signal to Tracked); Opengrep captures additional named platform/enterprise migrations beyond Codacy; AI Detection accuracy complaints surface in community; a second material outage within 90 days; GitHub Advanced Security closes the feature gap with bundled AI detection.
Risks & limitations
Not yet assessed — this section fills in as ACES research covers the tool.
Integration surface
Not yet assessed — this section fills in as ACES research covers the tool.
Adoption & benchmarks
Not yet assessed — this section fills in as ACES research covers the tool.
Spotted something wrong or missing here? Suggest a change →
Per-source contributions
Click any dimension to see the underlying sources and citations.
More in this category