John Melton Profile picture
Christ-follower, Husband, Dad, Security Guy, Developer, Lead on AppSensor
Nov 20, 2020 17 tweets 4 min read
Thanksgiving in the US is upon us.

With that in mind, _easily_ my favorite new open-source tool of this year is semgrep. (github.com/returntocorp/s… and semgrep.dev).

Thread: A few thoughts on why ...

1/
Background: I'm in a fairly small group of people who have actually built a static analysis product. I believe in the technology. I also know the problems.

I think Semgrep made 2 fundamentally clever decisions:

2/