ãµã€ããŒã»ãã¥ãªãã£
Semgrep ã©ã€ã»ã³ã¹è«äºã®äžã§ã®ãªãŒãã³ãœãŒã¹ã®ä»£æ¿

2025幎XNUMXæãã»ãã¥ãªãã£ã³ãã¥ããã£ã¯ãã©ã€ãã«äŒæ¥ãå£çµã㊠ãªãŒãã³ã°ã¬ããâéçã¢ããªã±ãŒã·ã§ã³ã»ãã¥ãªãã£ãã¹ãããŒã«ã§ããSemgrepã®ãã©ãŒã¯ããã€ãŠã¯ã³ãã¥ããã£äž»å°ã®ãªãŒãã³ãœãŒã¹ç²Ÿç¥ã§ç§°è³ãããŠããŸãããã ã»ã ã°ã¬ãã 2024幎XNUMXæã«ã©ã€ã»ã³ã¹ã¢ãã«ã倿Žããéã«è«äºãå·»ãèµ·ãã£ããã©ã€ã»ã³ã¹ã®å€æŽã«ãããå¯çš¿ãããã«ãŒã«ã®åçšè£œåã§ã®äœ¿çšãå¶éãããäž»èŠãªæ©èœãææåãããããšã«ãªã£ãã
Semgrep ã¯ãè€æ°ã®ããã°ã©ãã³ã°èšèªã«ãããè匱æ§ãæ€åºã§ãããããäžçäžã®éçºè ã«ãšã£ãŠæ¬ ãããªãããŒã«ãšãªã£ããããããåç€Ÿã®æ±ºå®ã¯ãçŸä»£ã®ãµã€ããŒã»ãã¥ãªãã£ã«ãšã£ãŠæ¥µããŠéèŠãªåéã«ãããã€ãããŒã·ã§ã³ãé»å®³ããæããããã
è«äºã®çã£åªäžãDevSecOpsã®ã¹ã¿ãŒãã¢ããDeepSourceãç«ã¡äžãã ã°ããã¹ã¿ãŒã¯ãã³ãŒã ã»ãã¥ãªãã£çšã®æ°ãããªãŒãã³ ãœãŒã¹ ããŒã«ãããã§ããGlobstar ã¯ããã®ããŒã«ãããããŒãããæ§ç¯ããMIT ã©ã€ã»ã³ã¹ã®äžã§ãªãªãŒã¹ããã³ãŒããžã®ç¡å¶éã®åçšã¢ã¯ã»ã¹ãšå®å šãªäžè¬å ¬éãæäŸããããšãç®æããŠãããšèªã£ãŠããŸãã
ãGlobstarãéããŠãã»ãã¥ãªãã£ããŒã ã®ããŒãºã念é ã«èšèšãããã«ã¹ã¿ã éçåæãžã®æ°ããã¢ãããŒããæäŸããŠããŸããããã¯ãè åšæ€åºã®ããã«éçºãã瀟å ãã¬ãŒã ã¯ãŒã¯ããçãŸããŸãããã ãµã³ã±ãã»ãµãŠã©ããå ±ååµèšè å Œæé«çµå¶è²¬ä»»è ïŒCEOïŒ ãã£ãŒããœãŒã¹ã¯ç§ã«ããèªã£ãããSemgrep ã¯ãã§ã«æèœãªäººæã®æã«æž¡ã£ãŠãããç§ãã¡ã®ç®æšã¯ç¬èªã®éãé²ãããšã§ãããç§ãã¡ã¯èªåãã¡ãã代ããã®äººæã§ã¯ãªãããã®åéã«æ°ããèŠç¹ããããã代æ¿äººæã ãšèããŠããŸããã
å瀟ã¯ç·é¡7.7äžãã«ã®è³éã調éããŠãããçŸåšã¯Y-Combinatorã®æè³å®¶ããæ¯æŽãåããŠããã
Go ããã°ã©ãã³ã°èšèªã䜿çšããŠéçºãããTree-sitter ãšçµ±åããã Globstar ã¯ã20 ãè¶ ããããã°ã©ãã³ã°èšèªããµããŒãããŠããŸãããã®ããŒã«ãããã«ã¯ãã«ã¹ã¿ã ã»ãã¥ãªã㣠ãã§ãã«ãŒãäœæããããã®çŽæç㪠YAML ã€ã³ã¿ãŒãã§ã€ã¹ãšãè€éãªãã¡ã€ã«éåæã®ããã®é«åºŠãª Go ã€ã³ã¿ãŒãã§ã€ã¹ãåãã£ãŠããŸãã
ããããžã§ã¯ããåå²ãããšãå€ãã®å Žåãç°ãªãè»éããã©ããŸãããæ¢åã®è£œåã®äžã«æ§ç¯ãããšããå¶çŽããããšãã€ãããŒã·ã§ã³ãå¶éãããå¯èœæ§ããããŸãããšãµã³ã±ããæ°ã¯èªããŸãããç§ãã¡ã¯ãã«ã¹ã¿ã ã³ãŒã ãã§ãã«ãŒã®äœæããã»ã¹ãç°¡çŽ åããã·ã¹ãã ãäœæããŸãããã
ããžãã¹äžã®å¿ èŠæ§ãšãªãŒãã³ãœãŒã¹ã®ä¿å
13幎2024æXNUMXæ¥ãSemgrepã¯ã©ã€ã»ã³ã¹ã¢ãã«ãå·æ°ããæäŸãããã«ãŒã«ã第äžè ãèš±å¯ãªãç«¶ååçšè£œåã§äœ¿çšããããšãå¶éããŸãããããã«ãå瀟ã¯ãªãŒãã³ãœãŒã¹çããSemgrep CEãïŒã³ãã¥ããã£ãšãã£ã·ã§ã³ïŒã«ãªãã©ã³ãããŸãããSemgrepã¯ãã©ã€ã»ã³ã¹ã®å€æŽã¯ç¥ç財ç£ãä¿è·ããæç¶å¯èœãªåçã確ä¿ããããã«äžå¯æ¬ ã§ãããšäž»åŒµããŠããŸããå瀟ã¯ãåçšå©çšãå¶éããããšã§ãç¡èš±å¯ã®åããã±ãŒãžåãæå¶ããé·æçãªã€ãããŒã·ã§ã³ããµããŒããããšäž»åŒµããŠããŸãã
ããšã³ãžãã¢ãåé¡ã解決ããããã«ã³ãŒããæžããšããéçè§£æã¯å®è¡ããã«ã³ãŒãã調ã¹ãéçºããã»ã¹ã®æ©ã段éã§ãã¿ãŒã³ãšæœåšçãªåé¡ãç¹å®ããŸããSemgrep ã¯ãã®åéã§å°æ¬ãããŠããäŒæ¥ã§ãããç§ã¯åœŒããé«ãè©äŸ¡ããŠããŸãããšãµã³ã±ããæ°ã¯èªããŸãããããããåçšãŠãŒã¶ãŒåãã®ã©ã€ã»ã³ã¹ã®å€æŽã¯ãããåºç¯ãªçŸå®ãåæ ããŠããŸããã€ãŸããVC ã®æ¯æŽãåããäŒæ¥ã¯ããªãŒãã³ãœãŒã¹ã®ååãšæç¶å¯èœãªããžãã¹ ã¢ãã«ã®ãã©ã³ã¹ãåããªããã°ãªããªããšããããšã§ããã
圌ã¯ããã®å€æŽããšã³ããŠãŒã¶ãŒã«çŽæ¥åœ±é¿ãäžããããšã¯ãªãã£ããã®ã®ããªãŒãã³ãœãŒã¹ã¯å®å šã«å¶éã®ãªããŸãŸã«ããŠããã¹ããããããšãé·æçãªåç¶ã確ä¿ããããã«é²åãããã¹ãããšããç¶ç¶çãªè°è«ãåŒãèµ·ãããŠãããšææããŠããã
2025幎10æãAikido SecurityãArnicaãAmplify SecurityãEndor LabsãJitãKodemãLegit SecurityãMobbãOrca Securityãå«ãXNUMXã®DevSecäŒæ¥ãã³ã³ãœãŒã·ã¢ã ãçµæããOpengrepãç«ã¡äžããŸãããäŒçµ±çã«æ¿ããç«¶äºçžæã§ãããã®æ°ããã³ã³ãœãŒã·ã¢ã ã¯ã忥çå©çãåªå ããŠæ©èœãå¶éãããšããSemgrepã®æ±ºå®ã«çŽæ¥ç°è°ãå±ããäºå®ã§ãã ããã°æçš¿Endor Labs ã¯ãéçã³ãŒãåæã¯ãå¶éããã«ã¯éèŠãããããšè¿°ã¹ãŠããŸãã
ãã ããOpengrep ããŸã£ããæ°ãããœãªã¥ãŒã·ã§ã³ãæäŸããã®ã§ã¯ãªããåã«ã¬ã¬ã·ãŒ ã³ãŒããåããã±ãŒãžåããŠããã ããªã®ãã©ããã¯ãŸã æããã§ã¯ãããŸããã
ãªãŒãã³ãœãŒã¹ã®ä»£æ¿åã®å°é
DeepSource ã¯ãéçºè ã®éã§ãåŸæ¥ã®å¶çŽãåŒãç¶ããªãããŒã«ã«å¯ŸããããŒãºãé«ãŸã£ãŠããããšãèªèããŸãããããšã³ã¿ãŒãã©ã€ãºã®ã客æ§ã¯ãè€æ°ã®ããŒã«ã䜿ãåããããšãæãã§ããŸãããè€æ°ã®ããŒã«ã䜿ãåãããšçµ±åã®èª²é¡ãçãããªãŒã«ã€ã³ã¯ã³ ãœãªã¥ãŒã·ã§ã³ã®éèŠãé«ãŸããŸãããš Sanket æ°ã¯èª¬æããŸãããéçåæã¯ãã³ãŒã ã¢ãŒããã¯ãã£ãçè§£ããäžã§éèŠãªåœ¹å²ãæãããŸãããã®ãããåœç€Ÿã¯çµ±åãã©ãããã©ãŒã ãšããŠäœçœ®ã¥ããŠããŸããã
ããããDeepSource ã® Globstar ã ãã§ã¯ãããŸãããSemgrep ã®ã©ã€ã»ã³ã¹è«äºãåããŠãéçã³ãŒãåæã®ä»£æ¿ææ®µãããã€ã泚ç®ãéããŠããŸããããšãã°ãSonarQube ã¯ãéçã³ãŒãåæãçµ±åãµããŒããã¡ããªãã¯è¿œè·¡çšã®ç¡æ Community Edition ãšææçã®äž¡æ¹ãæäŸããã³ãŒãåæãã©ãããã©ãŒã ã§ããåæ§ã«ãShellCheck ãã·ã§ã« ã¹ã¯ãªããã®åæã«ç¹åããä»£æ¿ææ®µã§ãéçºè ãåŸã§å€§ããªãã°ãéå¹çæ§ã«ã€ãªããå¯èœæ§ã®ããã¹ã¯ãªãã ãšã©ãŒãèŠã€ããã®ã«åœ¹ç«ã¡ãŸããç°ãªãã·ã§ã«ç°å¢éã§ç§»æ€ã§ããªãå¯èœæ§ã®ããã³ãã³ããæ§æã«ãã©ã°ãä»ããŸããã³ãã³ãã©ã€ã³ããå®è¡ã§ããCI/CD ãã€ãã©ã€ã³ã«ç°¡åã«çµ±åã§ãããªã©ã䜿ãããããããShellCheck ã¯ãŸããŸã人æ°ã®éžæè¢ã«ãªã£ãŠããŸãã
Opengrep ã¯ã¬ã¬ã·ãŒ ããŒã«ã®ãªãŒãã³ ã«ãŒããç¶æããããšããŠããŸãããSonarQubeãGlobstarãShellCheck ãªã©ã®ä»ã®ä»£æ¿ææ®µããæ¬æ°ã§å é²çãªãœãªã¥ãŒã·ã§ã³ãæäŸããŠããŸãããªãŒãã³ ãœãŒã¹ã®è°è«ãé²ãã«ã€ããéçºè ãäŒæ¥ã¯ãã³ãŒãåæã®ããæ¹ãåå®çŸ©ããå¯èœæ§ã®ããéèŠãªéžæã«çŽé¢ããŠããŸãã