Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Opengrep is a fork of Semgrep created in January 2025 after a dispute over Semgrep’s Community Edition rules and the capabilities available in its community engine. Security companies backing the project said they wanted to preserve an open, vendor-neutral static-analysis option; Semgrep said its scanning engine remained under the LGPL 2.1 license while separately changing the terms for its maintained rules.

What is Opengrep?

Opengrep is a static application security testing (SAST) tool and a fork of Semgrep, rather than an unrelated scanner. Its project repository identifies it as a fork of Semgrep v1.100.0 and says it is not affiliated with or endorsed by Semgrep Inc.

The project describes itself as an LGPL 2.1 fork that supports Semgrep rules and can produce JSON and SARIF output. Its repository also claims support for more than 30 languages and lists install scripts and release binaries. These are project descriptions, not independent performance or compatibility tests; teams should verify the current release and test the languages and rules they actually use.

Why did companies create Opengrep?

The fork followed a December 2024 announcement from Semgrep that changed both the licensing terms for Semgrep-maintained rules and what the company planned to include in its community engine. Some security firms and open-source stakeholders objected to the changes, particularly their implications for vendors and access to advanced analysis capabilities.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Opengrep’s launch site framed the fork as a way to preserve full open-source access to advanced static analysis, common outputs and backward compatibility. That describes the project’s rationale; it is not independent verification of every comparison it makes with Semgrep.

CyberScoop reported the launch in January 2025 and said more than ten security firms were participating or supporting it. The article named firms including Endor Labs, Aikido Security, Arnica, Amplify Security, Jit, Kodem, Legit Security, Mobb and Orca Security. The current repository description names Aikido, Amplify, Endor Labs, Kodem and Orca among the consortium’s backers; company lists can change over time.

What changed in Semgrep’s license?

In its December 13, 2024 announcement, Semgrep said its maintained rules would move to Semgrep Rules License v1.0. The company described the permitted contexts as internal, non-competing and non-SaaS use, and set January 31, 2025 as the end of a grace period for vendors to phase out use of those rules in their products.

Semgrep distinguished the rules from the scanning engine. The company said the engine remained LGPL 2.1, writing: “Despite claims to the contrary, Semgrep’s engine remains LGPL 2.1!” Semgrep explained that the new rules terms were intended to clarify that other vendors could not use Semgrep Community Edition rules in a competing SaaS offering.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Opengrep’s backers characterized the overall changes as restricting the open-source nature of Semgrep CE, including by removing features from the open engine and limiting community access and progress. Semgrep’s explanation emphasized that its engine remained LGPL 2.1 while the separately licensed rules received new terms. These are the parties’ stated positions, not a legal ruling: no court, regulator or standards body ruling on the dispute is identified in the cited sources.

How should a team evaluate Opengrep and Semgrep?

Choose based on the exact code, rules, workflow and deployment model you need—not on the word “open” alone. The distinction between an engine’s license and the terms on a rule set can matter as much as feature availability.

  • Check rule terms: Identify whether you use Semgrep-maintained rules or your own, and whether your use is internal, commercial, SaaS or part of a competing security product. Review the applicable license for the specific rules and version.
  • Compare required analysis: Confirm that the exact engine version supports the analysis you rely on, including any checks that span functions or files. Opengrep’s repository describes improvements to taint analysis, but those are project claims rather than independent benchmarks. Check current documentation and test representative code.
  • Validate language and workflow fit: Test your actual languages, Semgrep rules, JSON or SARIF integrations, and CI or IDE workflow. A project’s language-support count does not establish that every rule or analysis feature behaves identically in every language.
  • Assess maintenance and governance: Check who maintains releases, reviews contributions, handles security reports and funds ongoing work. Opengrep launch materials discussed community-led, vendor-neutral governance; verify the project’s current arrangements rather than treating a proposed model as completed.
  • Review security and support needs: Consider release integrity, maintenance cadence, issue response and whether self-hosted tooling or a managed platform fits your obligations. Semgrep’s repository recommends its AppSec Platform for security-scanning use cases; that is Semgrep’s guidance, not an independent endorsement.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What the launch signaled

The episode showed how a change to a widely used security tool can prompt competitors to coordinate around a fork when they disagree about licensing boundaries or the scope of community features. Endor Labs CEO Varun Badhwar told CyberScoop, “It’s rare to see competitors in the security space unite behind a single cause.” The lasting significance of Opengrep will depend on its maintenance, governance and compatibility over time, not simply on the number of companies present at launch.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.