Static analysis tool for finding bugs and enforcing code standards.
Semgrep is a fast, open-source static analysis engine that allows writing custom rules to detect bugs, security issues, and code smells. It supports many languages and integrates with CI/CD. It's used by developers and security engineers for code review and compliance.
Website
semgrep.com