Endor Labs has taken a huge leap forward against what it calls “a shift away from open-source principles” by Semgrep. In December 2024, Semgrep rebranded its widely used OSS static application security testing (SAST) tool to Semgrep Community Edition. The shift also moved crucial features and community rules behind its paid SaaS platform.
The lab, along with more than cybersecurity firms, has responded with Opengrep with a fully open-source fork of Semgrep to protect the integrity of community-centric security research.
Endor Labs Criticizes Semgrep: Here’s Why
In a statement, Endor Labs slammed Semgrep’s new licensing model for disrupting the open-source ecosystem and restricting collaboration.
“The rebranding from “Semgrep OSS” to “Semgrep Community Edition” signals a shift away from open source principles,” Endor Labs wrote in a blog post. The company affirmed that open-source security tools should remain free, transparent, and independent of vendor control. “Essential features like tracking ignores, fingerprinting, and meta-variables have moved behind the SaaS platform,” it added.
By leading the development of Opengrep, Endor Labs aims to provide developers with a truly open SAST tool. It retains all essential features without locking features behind a paywall.
Endor Labs and its partners launched Opengrep to keep security research open and accessible. Unlike Semgrep’s new model, Opengrep ensures that key scanning features, metadata, and rule contributions remain free.
It enables developers to use security rules across different platforms without being tied to a specific vendor. The firm is calling it a “special moment” where security companies have come together to support a truly open-source SAST ecosystem. Now, with Semgrep’s shift, Endor Labs thinks Opengrep will become the go-to-open-source alternative for developers around the globe.
Source: https://www.endorlabs.com/learn/how-to-discover-open-source-ai-models-in-your-code
Latest Stories:
L&T to Build Uzbekistan’s First AI-Driven Sustainable Data Centre