Do these 3 things before closing this tab:
1Scan for outdated or missing drivers - takes under a minute2Clear out junk files and repair common Windows errors3Fix the driver behind crashes, sound loss and screen glitchesOpengrep is a fork of Semgrep created in January 2025 after a dispute over Semgrep’s Community Edition rules and the capabilities available in its community engine. Security companies backing the project said they wanted to preserve an open, vendor-neutral static-analysis option; Semgrep said its scanning engine remained under the LGPL 2.1 license while separately changing the terms for its maintained rules.
What is Opengrep?
Opengrep is a static application security testing (SAST) tool and a fork of Semgrep, rather than an unrelated scanner. Its project repository identifies it as a fork of Semgrep v1.100.0 and says it is not affiliated with or endorsed by Semgrep Inc.
The project describes itself as an LGPL 2.1 fork that supports Semgrep rules and can produce JSON and SARIF output. Its repository also claims support for more than 30 languages and lists install scripts and release binaries. These are project descriptions, not independent performance or compatibility tests; teams should verify the current release and test the languages and rules they actually use.
Why did companies create Opengrep?
The fork followed a December 2024 announcement from Semgrep that changed both the licensing terms for Semgrep-maintained rules and what the company planned to include in its community engine. Some security firms and open-source stakeholders objected to the changes, particularly their implications for vendors and access to advanced analysis capabilities.
#1 Best Overall
Opengrep’s launch site framed the fork as a way to preserve full open-source access to advanced static analysis, common outputs and backward compatibility. That describes the project’s rationale; it is not independent verification of every comparison it makes with Semgrep.
CyberScoop reported the launch in January 2025 and said more than ten security firms were participating or supporting it. The article named firms including Endor Labs, Aikido Security, Arnica, Amplify Security, Jit, Kodem, Legit Security, Mobb and Orca Security. The current repository description names Aikido, Amplify, Endor Labs, Kodem and Orca among the consortium’s backers; company lists can change over time.
What changed in Semgrep’s license?
In its December 13, 2024 announcement, Semgrep said its maintained rules would move to Semgrep Rules License v1.0. The company described the permitted contexts as internal, non-competing and non-SaaS use, and set January 31, 2025 as the end of a grace period for vendors to phase out use of those rules in their products.
Semgrep distinguished the rules from the scanning engine. The company said the engine remained LGPL 2.1, writing: “Despite claims to the contrary, Semgrep’s engine remains LGPL 2.1!” Semgrep explained that the new rules terms were intended to clarify that other vendors could not use Semgrep Community Edition rules in a competing SaaS offering.
Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minuteWindows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallRank #3
Opengrep’s backers characterized the overall changes as restricting the open-source nature of Semgrep CE, including by removing features from the open engine and limiting community access and progress. Semgrep’s explanation emphasized that its engine remained LGPL 2.1 while the separately licensed rules received new terms. These are the parties’ stated positions, not a legal ruling: no court, regulator or standards body ruling on the dispute is identified in the cited sources.
How should a team evaluate Opengrep and Semgrep?
Choose based on the exact code, rules, workflow and deployment model you need—not on the word “open” alone. The distinction between an engine’s license and the terms on a rule set can matter as much as feature availability.
Rank #4
- Check rule terms: Identify whether you use Semgrep-maintained rules or your own, and whether your use is internal, commercial, SaaS or part of a competing security product. Review the applicable license for the specific rules and version.
- Compare required analysis: Confirm that the exact engine version supports the analysis you rely on, including any checks that span functions or files. Opengrep’s repository describes improvements to taint analysis, but those are project claims rather than independent benchmarks. Check current documentation and test representative code.
- Validate language and workflow fit: Test your actual languages, Semgrep rules, JSON or SARIF integrations, and CI or IDE workflow. A project’s language-support count does not establish that every rule or analysis feature behaves identically in every language.
- Assess maintenance and governance: Check who maintains releases, reviews contributions, handles security reports and funds ongoing work. Opengrep launch materials discussed community-led, vendor-neutral governance; verify the project’s current arrangements rather than treating a proposed model as completed.
- Review security and support needs: Consider release integrity, maintenance cadence, issue response and whether self-hosted tooling or a managed platform fits your obligations. Semgrep’s repository recommends its AppSec Platform for security-scanning use cases; that is Semgrep’s guidance, not an independent endorsement.
What the launch signaled
The episode showed how a change to a widely used security tool can prompt competitors to coordinate around a fork when they disagree about licensing boundaries or the scope of community features. Endor Labs CEO Varun Badhwar told CyberScoop, “It’s rare to see competitors in the security space unite behind a single cause.” The lasting significance of Opengrep will depend on its maintenance, governance and compatibility over time, not simply on the number of companies present at launch.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

