Skip to main content
opengrep Run Opengrep static analysis for fast security scanning with open-source rules. Use when scanning with truly open-source SAST, avoiding proprietary rule licenses, using community rules freely, or requiring commercial tool integration.
Ir para a instalação Skills Marketplace Descubra e explore skills de IA criadas pela comunidade.
Instalar com Codex ou Claude Copie este prompt, cole no Codex, Claude ou outro assistente e deixe que ele revise a página da skill e instale para você.
Copiar promptMostrar detalhes do prompt Um comando direto ignora o prompt de revisão. Verifique a origem antes de executá-lo.
npx skills add https://github.com/igbuend/grimbard --skill opengrepO comando permanece em uma só linha. Role horizontalmente para revisá-lo antes de copiar.
Prefere uma cópia local? Baixe os arquivos disponíveis atualmente no SkillsMP.
Baixar Zip Baixando... SOC
Baseado na classificação ocupacional SOC
name opengrep description Run Opengrep static analysis for fast security scanning with open-source rules. Use when scanning with truly open-source SAST, avoiding proprietary rule licenses, using community rules freely, or requiring commercial tool integration. allowed-tools ["Bash","Read","Glob","Grep"]
Opengrep - Open Source Code Security Engine
What is Opengrep?
Opengrep is a fork of Semgrep CE (Community Edition), launched in early 2025 by a consortium including JIT, Aikido Security, Endor Labs, and other companies. It was created in response to Semgrep's licensing changes that restricted community-contributed rules from being used in commercial products.
Key Differences from Semgrep:
Fully open-source rules (no license restrictions)
Community-driven governance
No proprietary feature lock-in
Compatible with Semgrep CE syntax and rules
Focused on keeping critical features open
Commercial integration friendly
When to Use Opengrep
Ideal scenarios:
Quick security scans (minutes, not hours)
Pattern-based vulnerability detection
Using community rules without license concerns
Commercial product integration requiring open-source SAST
Dataflow and taint analysis within files
Multi-language security scanning
First-pass security analysis before deeper tools
When Semgrep licensing is a concern
Consider CodeQL instead when:
Need interprocedural taint tracking across files
Complex data flow analysis across modules required
Analyzing custom proprietary frameworks with deep integration
When NOT to Use Do NOT use this skill for:
Complex cross-file data flow analysis (use CodeQL)
Binary or compiled code analysis without source
Deep semantic analysis requiring full program analysis
Runtime vulnerability detection
Secrets scanning (use Gitleaks)
Dependency scanning (use OSV-Scanner or Depscan)
Installation
brew install opengrep
pip install opengrep
pipx install opengrep
docker pull ghcr.io/opengrep/opengrep:latest
git clone https://github.com/opengrep/opengrep.git
cd opengrep
pip install -e .
opengrep --version
Core Workflow
1. Quick Scan
opengrep scan .
opengrep scan -f p/security-audit .
opengrep scan -f p/owasp-top-ten -f p/cwe-top-25 .
2. SARIF Output
opengrep scan --sarif -o results.sarif .
opengrep scan -f p/security-audit --sarif -o results.sarif .
opengrep scan \
--severity=WARNING \
--severity=ERROR \
--sarif \
-o results.sarif \
.
3. Advanced Scanning
opengrep scan --dataflow-traces .
opengrep scan --taint-intrafile .
opengrep scan --experimental .
opengrep scan \
--dataflow-traces \
--taint-intrafile \
--experimental \
.
4. Custom Rules
opengrep scan -f /path/to/rules .
opengrep scan -f ./rules -f ./custom-rules .
opengrep scan \
-f p/security-audit \
--exclude-rule="rule-id-to-skip" \
.
Rulesets
Public Rulesets Ruleset Description p/defaultGeneral security and code quality p/security-auditComprehensive security rules p/owasp-top-tenOWASP Top 10 vulnerabilities p/cwe-top-25CWE Top 25 vulnerabilities p/trailofbitsTrail of Bits security rules p/pythonPython-specific security p/javascriptJavaScript/TypeScript security p/golangGo-specific security p/javaJava security patterns p/rubyRuby security patterns
Community Rules
git clone https://github.com/opengrep/opengrep-rules.git
opengrep scan -f opengrep-rules/ .
git clone https://github.com/trailofbits/semgrep-rules.git
opengrep scan -f semgrep-rules/rules .
Output Formats
opengrep scan .
opengrep scan --sarif .
opengrep scan --json .
opengrep scan --junit-xml .
opengrep scan --gitlab-sast .
opengrep scan --vim .
opengrep scan --emacs .
Configuration
.opengrepignore tests/fixtures/
**/testdata/
generated/
vendor/
node_modules/
__pycache__/
*.test.js
*.spec.ts
Project Configuration rules:
- id: custom-hardcoded-secret
languages: [python , javascript ]
message: "Hardcoded secret detected"
severity: ERROR
pattern: |
$VAR = "$SECRET"
metadata:
cwe: "CWE-798"
owasp: "A07:2021 - Identification and Authentication Failures"
- id: sql-injection-risk
languages: [python ]
message: "Potential SQL injection"
severity: ERROR
mode: taint
pattern-sources:
- pattern: request.args.get(...)
pattern-sinks:
- pattern: cursor.execute($QUERY)
pattern-sanitizers:
- pattern: int(...)
exclude:
- tests/
- vendor/
opengrep scan --config .opengrep.yml .
CI/CD Integration (GitHub Actions) name: Opengrep Security Scan
on:
push:
branches: [main ]
pull_request:
schedule:
- cron: '0 0 * * 1'
jobs:
opengrep:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- name: Setup Python
uses: actions/setup-python@v5
with:
python-version: '3.11'
- name: Install Opengrep
run: pip install opengrep
- name: Run Opengrep
run: |
opengrep scan \
-f p/security-audit \
-f p/owasp-top-ten \
--dataflow-traces \
--taint-intrafile \
--experimental \
--sarif \
-o opengrep-results.sarif \
--severity=WARNING \
--severity=ERROR \
--exclude=test \
--exclude=tests \
.
- name: Upload SARIF
if: always()
uses: github/codeql-action/upload-sarif@v3
with:
sarif_file: opengrep-results.sarif
category: opengrep
- name: Upload Results
if: always()
uses: actions/upload-artifact@v4
with:
name: opengrep-results
path: opengrep-results.sarif
Writing Custom Rules
Basic Rule Structure rules:
- id: dangerous-eval
languages: [javascript , python ]
message: "Use of eval() is dangerous"
severity: ERROR
patterns:
- pattern: eval($CODE)
- pattern-not: eval("...")
Pattern Syntax Syntax Description Example ...Match anything func(...)$VARCapture metavariable $FUNC($INPUT)<... ...>Deep expression match <... user_input ...>
Pattern Operators Operator Description patternMatch exact pattern patternsAll must match (AND) pattern-eitherAny matches (OR) pattern-notExclude matches pattern-insideMatch only inside context pattern-not-insideMatch only outside context pattern-regexRegex matching metavariable-regexRegex on captured value
Taint Mode rules:
- id: xss-vulnerability
languages: [javascript ]
message: "User input flows to innerHTML (XSS risk)"
severity: ERROR
mode: taint
pattern-sources:
- pattern: req.query.$PARAM
- pattern: req.body.$PARAM
pattern-sinks:
- pattern: $ELEMENT.innerHTML = $DATA
pattern-sanitizers:
- pattern: escapeHtml(...)
- pattern: DOMPurify.sanitize(...)
Common Use Cases
1. Comprehensive Security Audit
opengrep scan \
-f p/security-audit \
-f p/owasp-top-ten \
-f p/cwe-top-25 \
--dataflow-traces \
--experimental \
--sarif \
-o security-audit.sarif \
.
2. Language-Specific Scan
opengrep scan \
-f p/python \
--taint-intrafile \
--sarif \
-o python-security.sarif \
./src
opengrep scan \
-f p/javascript \
-f p/typescript \
--dataflow-traces \
--sarif \
-o js-security.sarif \
./frontend
3. Pre-commit Hook
git diff --cached --name-only --diff-filter=ACMR | \
grep -E '\.(py|js|ts|go|java|rb)$' | \
xargs opengrep scan -f p/security-audit
5. Diff Scan (Changed Files Only)
git diff --name-only origin/main...HEAD | \
xargs opengrep scan -f p/security-audit --sarif -o diff-scan.sarif
Suppressing False Positives
Inline Suppressions
password = get_from_vault()
eval (safe_code)
element.innerHTML = sanitizedContent;
Configuration-Based Suppressions
exclude-rules:
- rule-id-1
- rule-id-2
exclude-paths:
- tests/
- generated/
Performance Optimization
opengrep scan --include='*.py' --include='*.js' .
opengrep scan --exclude=node_modules --exclude=vendor .
opengrep scan --timeout 60 .
opengrep scan -f p/security-audit .
Comparing with Semgrep
Compatibility Opengrep maintains compatibility with Semgrep CE:
Same rule syntax (YAML)
Same pattern language
Same command-line interface
Can use Semgrep rules directly
Key Differences Feature Opengrep Semgrep CE License LGPL 2.1 (fully open) LGPL 2.1 (engine), restrictive rules Rules Fully open, no restrictions Community rules have usage restrictions Governance Community consortium r2c/Semgrep Inc. Commercial Use Unrestricted Restricted for community rules Pro Features Being migrated to open Proprietary Development Community-driven Company-driven
Migration from Semgrep
alias opengrep=semgrep
opengrep scan -f p/security-audit .
sed -i 's/semgrep/opengrep/g' .github/workflows/security.yml
Supported Languages
Web : JavaScript, TypeScript, JSX, TSX
Backend : Python, Go, Java, Kotlin, Scala
Systems : C, C++, Rust
Mobile : Swift, Kotlin, Java
Scripting : Ruby, PHP, Bash, Lua
Infrastructure : Terraform, Dockerfile, YAML, JSON
Other : C#, Elixir, Solidity, Apex
Limitations
Intra-file taint only : Cross-file dataflow requires CodeQL
Pattern-based : Can't understand complex program semantics
No runtime analysis : Static analysis only
Performance : Large codebases may be slow with all features enabled
Experimental features : May have bugs or incomplete coverage
Rationalizations to Reject Shortcut Why It's Wrong "Opengrep found nothing = code is secure" Pattern-based analysis can miss context-specific vulnerabilities "Just use default rules" Default rules are generic; custom rules for your stack are essential "Skip dataflow/taint analysis for speed" These features catch vulnerabilities simple patterns miss "Semgrep and Opengrep are identical" Licensing differences matter for commercial use; feature sets diverging "Don't need both Opengrep and CodeQL" Complementary: Opengrep is fast/broad, CodeQL is deep/precise
References