Sign in
Categories
Your Saved List Become a Channel Partner Sell in AWS Marketplace Amazon Web Services Home Help

Application Security Platform

Semgrep, Inc. | 1

Reviews from AWS Marketplace

0 AWS reviews
  • 5 star
    0
  • 4 star
    0
  • 3 star
    0
  • 2 star
    0
  • 1 star
    0

External reviews

29 reviews
from G2

External reviews are not included in the AWS star rating for the product.


    Shivam J.

Perfect code security analysis tool to check and eliminate vulnerabilities

  • February 20, 2024
  • Review verified by G2

What do you like best about the product?
The sast engine and the wholesome dashboard makes everything looks great and crisp
What do you dislike about the product?
I am not satisfied with the accuracy of the integration tools with it
What problems is the product solving and how is that benefiting you?
Making it easy to go shift left in security and in supply chain management security


    Abhineet S.

Just a right way to test and catch your code vulnerability

  • February 20, 2024
  • Review verified by G2

What do you like best about the product?
I like the SAST engine, it is powerful and capable alongwith less % of false positives. Apart from it, the pro and lot other built rules make it easy to integrate with any DevSecOps process.
What do you dislike about the product?
Currently the newer offering like SEMGREP AI and secrets manager does not add up perfectly
What problems is the product solving and how is that benefiting you?
It is catching the essential, critical and tainted in nature vulnerabilities in day to day code making it is good way to follow shift left practices.


    Computer Games

Simple yet powerful SAST & SCA

  • November 07, 2023
  • Review verified by G2

What do you like best about the product?
- Easy to integrate in CICD and custom workflows
- CLI configurations are simple
- Powerful scanning capabilities
- Supports many languages
- Reachability analysis is helpful
- Stable and reliable
What do you dislike about the product?
- Doesn't handle unicode chars properly at many places, if there are unicodes in your code then semgrep can crash
- No GUI for OSS version, they should atleast provide a basic GUI for OSS version
What problems is the product solving and how is that benefiting you?
Semgrep is helping us identify vulnerabilities at the early stages of the development by continously identifying the vulnerabilities in our codebase and highlighting the vulnerable OSS libraries being used.


    Dhaval D.

Free and open-source static code analysis tool

  • June 27, 2023
  • Review verified by G2

What do you like best about the product?
-Installation is pretty straightforward
-Supports almost all programming languages
-Scans are relatively faster than other static code analysis tool
-In certain cases, I have noticed results/findings from Semgrep were more accurate
What do you dislike about the product?
-There were quite a few false positives as well
-Other tools such as Sonarqube has more features and provides thorough reports
-Troubleshooting can be difficult
What problems is the product solving and how is that benefiting you?
In my case, I use Semgrep to find initial bugs in my code and it works almost perfectly in almost all cases and pass on the report to tester to debug more and fix the same issues.


    Stéphane S.

Amazing quality product and affordable for SMBs with great support team and community !

  • May 29, 2023
  • Review verified by G2

What do you like best about the product?
Semgrep helped us in no time narrowing down important vulnerabilities and focusing on what matters thanks to Semgrep Supply Chain.

It is the product with the best ROI I would recommend to add to your SSDLC. it fast, extendable and customizable, with a handy CLI.
What do you dislike about the product?
Less advanced Bitbucket / Jira integration compared to GitHub but catching up fast!
What problems is the product solving and how is that benefiting you?
Making sure we maintain cybersecurity compliance and ensure safety of the data we process. Semgrep Supply Chain ensure we are focusing the most important security issues first.


    Financial Services

A Highly Customizable SAST

  • March 24, 2023
  • Review verified by G2

What do you like best about the product?
Semgrep is an easy-to-use and highly customizable static code analysis tool. Its intuitive interface and flexible rules library make running scans on any codebase effortless, big or small. With its active community of contributors and open-source nature, Semgrep is an essential tool for developers looking to enhance code quality and security quickly and efficiently.
What do you dislike about the product?
I have not encountered any major issues while using the product so far. During onboarding, I experienced some minor UI issues, but they did not significantly impact my overall experience.
What problems is the product solving and how is that benefiting you?
It helps identify potential issues before they become major problems, saving time and resources in the long run. By finding and fixing issues early on in the development process, developers can improve the overall quality of the codebase and reduce the likelihood of future problems.


    Kiko E.

A Seamless Static Analysis Tool

  • February 22, 2023
  • Review verified by G2

What do you like best about the product?
One of the things that I love most about Semgrep is how easy it is to use. As a static analysis tool, it has a reputation for being intimidating or difficult to integrate into existing workflows. But with Semgrep, developers don't have to worry about that at all. It seamlessly integrates with many popular code editors, version control systems, and continuous integration tools. This means that it's a breeze to set up and start using to detect potential security vulnerabilities, performance issues, and other code quality problems.

But what's really cool about Semgrep is how it feels like a tool that's designed with developers in mind. The pre-built rules are incredibly comprehensive and cover a wide range of potential issues. But if you need to customize them for your project, it's easy to do so. And if you ever get stuck, the community is always there to help you out.

All in all, Semgrep is a powerful tool that can help developers improve the quality of their code. But more importantly, it feels like a tool that was designed to make our lives easier. And who doesn't love that?
What do you dislike about the product?
As with any tool, Semgrep has some potential downsides to consider. Here are a few:

Learning curve: While Semgrep is generally considered to be user-friendly and easy to use, there is still a learning curve to using any new tool. Some developers may need to spend some time getting familiar with Semgrep's syntax and how to write and modify rules.

False positives/negatives: Like any static analysis tool, Semgrep can generate false positives (i.e., flagging code as problematic when it's not) or false negatives (i.e., failing to flag problematic code). This can be frustrating and may require some additional time and effort to sort out.

Resource-intensive: Depending on the size of your codebase, running Semgrep can be resource-intensive and may slow down your development process. It's important to consider this when integrating Semgrep into your workflow and ensure that your hardware and infrastructure can handle it.

Overall, these potential downsides are relatively minor compared to the benefits that Semgrep can provide. However, it's important to consider these factors when deciding whether or not Semgrep is the right tool for your project.
What problems is the product solving and how is that benefiting you?
The problem that Semgrep is solving is that it can be difficult for developers to manually review code for potential issues. With codebases that are constantly growing and changing, it can be easy to miss potential issues or introduce new ones. Semgrep automates this process and enables developers to quickly identify and address potential issues before they become larger problems.


    Aleksandr K.

Semgrep - future of SAST

  • February 22, 2023
  • Review verified by G2

What do you like best about the product?
context aware scanning that allows a security engineer to see true metrics on vulnerabilities in the code. Its offering of IaC shows how much context aware it can be with its custom data flows.
What do you dislike about the product?
It's hard to name anything in particular, but the one thing that is challenging is to get onboarded with this. There is definitely a learning curve to get started with writing your own rules.
What problems is the product solving and how is that benefiting you?
All things related to code security: putting security guardrails for developers in pre-commit stage, ensuring no secrets are ever committed, keeping our lockfiles with libraries up to date.


    Information Technology and Services

Game-changer for application security

  • December 30, 2022
  • Review verified by G2

What do you like best about the product?
The Semgrep supply chain is a boon for application and product security teams. Backed by the already solid Semgrep engine, it can quickly surface vulnerabilities that are *actually* vulnerabilities and materially improves our security and risk management. It feels like it gave me new superpowers. I would recommend this to any security team, along with the base product. Most importantly, the r2c engineers and support team are first-rate. They are incredibly supportive and responsive, and I felt like their most important customer every step of the way.
What do you dislike about the product?
There are very few downsides I can think of, but one that comes to mind is the ability to extend or templatize existing rules. The base rules and rulesets are good but may produce false positives without customization. I would love the ability for Semgrep to offer a way to further customize rules and layer on specificity that increase accuracy.
What problems is the product solving and how is that benefiting you?
Semgrep saves us innumerable hours of manual work and toil. It allows us to multiply our impact, "shift left," and free up valuable time that we can use to focus on higher-impact security efforts. I can't imagine running a security program without it.


    Information Technology and Services

Easy to use and powerful

  • December 30, 2022
  • Review provided by G2

What do you like best about the product?
Very easy to use, no matter which language you are using. Unlike more legacy static code analysis tools, there is no need to spend a lot of time learning rule types and syntaxes; new rules can be spun up and tested very quickly. Also, results are of high quality.
What do you dislike about the product?
Community support is not as developed as they are pretty new. The breadth of rules and integrations is not as extensive as some other tools. However, this is improving rapidly and the rules that are present have much lesser false positives.
What problems is the product solving and how is that benefiting you?
We use semgrep as part of our static code analysis process. We use a combination of community and custom rules to suit our purposes. This helps us automate finding of common pattern matches to look out for.