Opengrep Open Source Project Launched
January 27, 2025

Endor Labs, Aikido Security, Arnica, Amplify, Kodem, Legit, Mobb and Orca Security have launched Opengrep to ensure static code analysis remains truly open, accessible and innovative for everyone:

A fork of Semgrep OSS, the new project is in response to recent changes by Semgrep that compromise its open source nature and limit access and innovation for the broader community.

The new project, Opengrep is built on three core principles:

1. True Open Source: All features and capabilities remain accessible to everyone, with no artificial restrictions or commercial gates.

2. Community Governance: Development priorities are set collectively, with contributions evaluated based on merit rather than commercial interests.

3. Foundation Management: A clear 12-month roadmap to transition to foundation oversight (like OWASP or Linux Foundation) ensures long-term stability.

By switching to Opengrep, developers get:

- Full access to all scanning capabilities without feature restrictions

- Backward compatibility with existing workflows and JSON/SARIF outputs

- Portable security rules that work across any environment

- Community-driven feature development

- Long-term stability through foundation governance

“Static code analysis is too important to be restricted,” said Varun Badhwar, CEO and co-founder of Endor Labs. “As one of the creators of Opengrep, Endor Labs is ensuring that security tooling remains open, innovative, and accessible to all. This isn't just about preserving existing capabilities—it's about building a future where security tools evolve through collaboration rather than commercial interests. By preserving and advancing open source security tooling, we can create a more secure future for software development—one where security capabilities are democratized, innovation is unrestricted, and the community's needs come first.”

Share this

Industry News

June 03, 2025

LambdaTest announced its partnership with Assembla, a cloud-based platform for version control and project management.

June 03, 2025

Salt Security unveiled Salt Illuminate, a platform that redefines how organizations adopt API security.

June 03, 2025

Workday announced a new unified, AI developer toolset to bring the power of Workday Illuminate directly into the hands of customer and partner developers, enabling them to easily customize and connect AI apps and agents on the Workday platform.

June 02, 2025

Pegasystems introduced Pega Agentic Process Fabric™, a service that orchestrates all AI agents and systems across an open agentic network for more reliable and accurate automation.

June 02, 2025

Fivetran announced that its Connector SDK now supports custom connectors for any data source.

June 02, 2025

Copado announced that Copado Robotic Testing is available in AWS Marketplace, a digital catalog with thousands of software listings from independent software vendors that make it easy to find, test, buy, and deploy software that runs on Amazon Web Services (AWS).

May 29, 2025

Sauce Labs announced the general availability of iOS 18 testing on its Virtual Device Cloud (VDC).

May 29, 2025

Infragistics announced the launch of Infragistics Ultimate 25.1, the company's flagship UX and UI product.

May 29, 2025

CIQ announced the creation of its Open Source Program Office (OSPO).

May 28, 2025

Check Point® Software Technologies Ltd.(link is external) announced the launch of its next generation Quantum(link is external) Smart-1 Management Appliances, delivering 2X increase in managed gateways and up to 70% higher log rate, with AI-powered security tools designed to meet the demands of hybrid enterprises.

May 28, 2025

Salesforce and Informatica have entered into an agreement for Salesforce to acquire Informatica.

May 28, 2025

Red Hat and Google Cloud announced an expanded collaboration to advance AI for enterprise applications by uniting Red Hat’s open source technologies with Google Cloud’s purpose-built infrastructure and Google’s family of open models, Gemma.

May 28, 2025

Mirantis announced Mirantis k0rdent Enterprise and Mirantis k0rdent Virtualization, unifying infrastructure for AI, containerized, and VM-based workloads through a Kubernetes-native model, streamlining operations for high-performance AI pipelines, modern microservices, and legacy applications alike.

May 28, 2025

Snyk launched the Snyk AI Trust Platform, an AI-native agentic platform specifically built to secure and govern software development in the AI Era.