Sign in
Categories
Your Saved List Become a Channel Partner Sell in AWS Marketplace Amazon Web Services Home Help

Reviews from AWS customer

0 AWS reviews
  • 5 star
    0
  • 4 star
    0
  • 3 star
    0
  • 2 star
    0
  • 1 star
    0

External reviews

32 reviews
from and

External reviews are not included in the AWS star rating for the product.


    Computer Software

An easy to use and fun to customize SAST tool

  • December 04, 2024
  • Review provided by G2

What do you like best about the product?
That the SAST engine returns a very small number of false positives. And the rules are fun to write. I also like the reachability analysis of the supply chain tool so you don't get overwhelmed by false positives
What do you dislike about the product?
There is no export report feature. Moreover it would be useful a toggle to tell the supply chain tool to report all the vulnerable dependencies, regardless of their reachability.
What problems is the product solving and how is that benefiting you?
Helping to build secure products by writing more secure code


    Computer & Network Security

Semgrep experience

  • December 04, 2024
  • Review provided by G2

What do you like best about the product?
The easy customisation, custom rule creation and fast feedback for devs
What do you dislike about the product?
More products like IaC scanning or DAST, I would love to have full capabilities to scan apps
What problems is the product solving and how is that benefiting you?
Shifting left vulnerabilities


    Henry Mwawai

Automated code reviews and good scalability with custom rule adaptability

  • September 23, 2024
  • Review provided by PeerSpot

What is our primary use case?

We use Semgrep to check custom user pipelines and test their claims for any vulnerabilities. We process the code by passing it through the testing process for any operability issues before sending feedback to the developers and providing the final product. This is part of the static testing analysis of code analysis.

How has it helped my organization?

Semgrep has supported our team in automating code reviews and allowed us to catch vulnerabilities before the final product stage. This has improved both our development cost and development speed.

What is most valuable?

The most valuable feature is the ability to write our custom rules. This adaptability allows us to cater specifically to our needs.

What needs improvement?

There should be more information on how to acquire the system, catering to beginners in application security, to make it more user-friendly.

For how long have I used the solution?

My experience with Semgrep is very recent since we started integrating it into our processes.

What do I think about the stability of the solution?

There haven't been any severe stability issues from my end.

What do I think about the scalability of the solution?

We have not faced any scalability issues. Since we are a team of only two users, Semgrep scales well for our current requirements.

How are customer service and support?

There was some difficulty in hearing the questions due to static noise, implying potential issues with communication or support on the call. However, rejoining the call resolved the problem.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

We did not switch from another product to Semgrep.

How was the initial setup?

The initial setup was straightforward, involving connecting the digital product to Semgrep. I am mainly involved in the usage aspect, and thus, I provided information from my perspective.

What about the implementation team?

We handled the setup internally within our team, and I particularly addressed it.

What was our ROI?

Semgrep has positively impacted our ROI by improving development speed and cost efficiency.

What other advice do I have?

I'd rate the solution eight out of ten.

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Other


    Shivam J.

Perfect code security analysis tool to check and eliminate vulnerabilities

  • February 20, 2024
  • Review provided by G2

What do you like best about the product?
The sast engine and the wholesome dashboard makes everything looks great and crisp
What do you dislike about the product?
I am not satisfied with the accuracy of the integration tools with it
What problems is the product solving and how is that benefiting you?
Making it easy to go shift left in security and in supply chain management security


    Abhineet S.

Just a right way to test and catch your code vulnerability

  • February 20, 2024
  • Review provided by G2

What do you like best about the product?
I like the SAST engine, it is powerful and capable alongwith less % of false positives. Apart from it, the pro and lot other built rules make it easy to integrate with any DevSecOps process.
What do you dislike about the product?
Currently the newer offering like SEMGREP AI and secrets manager does not add up perfectly
What problems is the product solving and how is that benefiting you?
It is catching the essential, critical and tainted in nature vulnerabilities in day to day code making it is good way to follow shift left practices.


    Computer Games

Simple yet powerful SAST & SCA

  • November 07, 2023
  • Review provided by G2

What do you like best about the product?
- Easy to integrate in CICD and custom workflows
- CLI configurations are simple
- Powerful scanning capabilities
- Supports many languages
- Reachability analysis is helpful
- Stable and reliable
What do you dislike about the product?
- Doesn't handle unicode chars properly at many places, if there are unicodes in your code then semgrep can crash
- No GUI for OSS version, they should atleast provide a basic GUI for OSS version
What problems is the product solving and how is that benefiting you?
Semgrep is helping us identify vulnerabilities at the early stages of the development by continously identifying the vulnerabilities in our codebase and highlighting the vulnerable OSS libraries being used.


    Dhaval D.

Free and open-source static code analysis tool

  • June 27, 2023
  • Review provided by G2

What do you like best about the product?
-Installation is pretty straightforward
-Supports almost all programming languages
-Scans are relatively faster than other static code analysis tool
-In certain cases, I have noticed results/findings from Semgrep were more accurate
What do you dislike about the product?
-There were quite a few false positives as well
-Other tools such as Sonarqube has more features and provides thorough reports
-Troubleshooting can be difficult
What problems is the product solving and how is that benefiting you?
In my case, I use Semgrep to find initial bugs in my code and it works almost perfectly in almost all cases and pass on the report to tester to debug more and fix the same issues.


    Stéphane S.

Amazing quality product and affordable for SMBs with great support team and community !

  • May 29, 2023
  • Review provided by G2

What do you like best about the product?
Semgrep helped us in no time narrowing down important vulnerabilities and focusing on what matters thanks to Semgrep Supply Chain.

It is the product with the best ROI I would recommend to add to your SSDLC. it fast, extendable and customizable, with a handy CLI.
What do you dislike about the product?
Less advanced Bitbucket / Jira integration compared to GitHub but catching up fast!
What problems is the product solving and how is that benefiting you?
Making sure we maintain cybersecurity compliance and ensure safety of the data we process. Semgrep Supply Chain ensure we are focusing the most important security issues first.


    Financial Services

A Highly Customizable SAST

  • March 24, 2023
  • Review provided by G2

What do you like best about the product?
Semgrep is an easy-to-use and highly customizable static code analysis tool. Its intuitive interface and flexible rules library make running scans on any codebase effortless, big or small. With its active community of contributors and open-source nature, Semgrep is an essential tool for developers looking to enhance code quality and security quickly and efficiently.
What do you dislike about the product?
I have not encountered any major issues while using the product so far. During onboarding, I experienced some minor UI issues, but they did not significantly impact my overall experience.
What problems is the product solving and how is that benefiting you?
It helps identify potential issues before they become major problems, saving time and resources in the long run. By finding and fixing issues early on in the development process, developers can improve the overall quality of the codebase and reduce the likelihood of future problems.


    Kiko E.

A Seamless Static Analysis Tool

  • February 22, 2023
  • Review provided by G2

What do you like best about the product?
One of the things that I love most about Semgrep is how easy it is to use. As a static analysis tool, it has a reputation for being intimidating or difficult to integrate into existing workflows. But with Semgrep, developers don't have to worry about that at all. It seamlessly integrates with many popular code editors, version control systems, and continuous integration tools. This means that it's a breeze to set up and start using to detect potential security vulnerabilities, performance issues, and other code quality problems.

But what's really cool about Semgrep is how it feels like a tool that's designed with developers in mind. The pre-built rules are incredibly comprehensive and cover a wide range of potential issues. But if you need to customize them for your project, it's easy to do so. And if you ever get stuck, the community is always there to help you out.

All in all, Semgrep is a powerful tool that can help developers improve the quality of their code. But more importantly, it feels like a tool that was designed to make our lives easier. And who doesn't love that?
What do you dislike about the product?
As with any tool, Semgrep has some potential downsides to consider. Here are a few:

Learning curve: While Semgrep is generally considered to be user-friendly and easy to use, there is still a learning curve to using any new tool. Some developers may need to spend some time getting familiar with Semgrep's syntax and how to write and modify rules.

False positives/negatives: Like any static analysis tool, Semgrep can generate false positives (i.e., flagging code as problematic when it's not) or false negatives (i.e., failing to flag problematic code). This can be frustrating and may require some additional time and effort to sort out.

Resource-intensive: Depending on the size of your codebase, running Semgrep can be resource-intensive and may slow down your development process. It's important to consider this when integrating Semgrep into your workflow and ensure that your hardware and infrastructure can handle it.

Overall, these potential downsides are relatively minor compared to the benefits that Semgrep can provide. However, it's important to consider these factors when deciding whether or not Semgrep is the right tool for your project.
What problems is the product solving and how is that benefiting you?
The problem that Semgrep is solving is that it can be difficult for developers to manually review code for potential issues. With codebases that are constantly growing and changing, it can be easy to miss potential issues or introduce new ones. Semgrep automates this process and enables developers to quickly identify and address potential issues before they become larger problems.