3 ms·
How does this compare/contrast with Semgrep?
by CrazyPyroLinux 5y ago
How does this compare/contrast with Semgrep?
- okundzich 5y agoSemgrep’s focus is on static analysis/search and is based on rules that developers need to write in a new DSL. Autofix is experimental and is one pattern replaced with another. https://semgrep.dev/docs/experiments/overview/ https://semgrep.dev/docs/experiments/overview/ OpenRewrite originated to do transformations of code, specifically to remove a Netflix proprietary logging library and replace it with in SLF4J. The predecessor of OpenRewrite was Gradle Lint (https://github.com/nebula-plugins/gradle-lint-plugin https://github.com/nebula-plugins/gradle-lint-plugin), commonly used to update Gradle build configuration. OpenRewrite added search after transformation and search can be very flexible (search for all usages of a particular package/any method, not just a specific method invocation). Instead of being DSL based, OpenRewrite provides a set of building blocks called recipes that can be combined together to create more powerful recipes. When building blocks are not enough, you can write a custom recipe in the same language as what you are managing. Java for Java and TypeScript for JavaScript/TypeScript (coming soon). For example, you can see JUnit 4 to 5 migration recipe contains a set of pre-built and custom recipes. https://docs.openrewrite.org/reference/recipes/java/testing/junit5/junit4to5migration https://docs.openrewrite.org/reference/recipes/java/testing/... You can see recipes in action on the Moderne product brief. https://moderne.io/product/ https://moderne.io/product/ https://www.youtube.com/watch?v=uR9EPALJKjI&t=1s https://www.youtube.com/watch?v=uR9EPALJKjI&t=1s