5 ms·
All the engine functionality is FOSS https://semgrep.dev/docs/experiments/r2c-internal-project-depends-on/ https://semgrep.dev/docs/experiments/r2c-internal-pro
by ievans 4y ago
All the engine functionality is FOSS https://semgrep.dev/docs/experiments/r2c-internal-project-depends-on/ https://semgrep.dev/docs/experiments/r2c-internal-project-de... (code at https://github.com/returntocorp/semgrep); https://github.com/returntocorp/semgrep); but the rules are currently private (may change in the future).
As with all other Semgrep scanning, the analysis is done locally and offline -- which is a major contrast to most other vendors. See #12 on our development philosophy for more details: https://semgrep.dev/docs/contributing/semgrep-philosophy/ https://semgrep.dev/docs/contributing/semgrep-philosophy/
Relevant part of the changelog is a good idea--others have also come out with statistical approaches based on upgrades others made (eg dependabot has a compatibility score which is based on "when we made PRs for this on other repos, what % of the time did tests pass vs fail")
- snowstormsun 4y agoAh okay, thanks for the information.