Semgrep
Semgrep is a fast, open-source static analysis tool that lets you write custom rules in YAML to detect bugs, security vulnerabilities, and code patterns specific to your codebase. Its rule library covers OWASP Top 10 and common security issues across 30+ languages.
Snyk
Snyk scans your code, open-source dependencies, containers, and IaC for security vulnerabilities, providing fix recommendations directly in your PR workflow. Its AI-powered DeepCode capabilities detect custom security issues in application code beyond known CVEs.