Having recently completed a significant application security uplift for a client migrating to AWS EKS, the selection of a static application security testing (SAST) tool was a critical path item. We evaluated Semgrep alongside established tools like SonarQube, CodeQL, and various linters. My perspective is grounded in operational integration into CI/CD pipelines, runtime cost, and the actionable nature of findings.
The primary differentiator for Semgrep is its **approachability and speed**. Unlike CodeQL, which requires building a database of your codebase and can be resource-intensive, Semgrep operates on a parse-and-search principle. This makes it exceptionally fast, suitable for pre-commit hooks or rapid CI feedback. For a developer-centric shift-left strategy, this is a significant advantage.
However, this comes with trade-offs. Let's break down the comparison across several key dimensions:
* **Analysis Depth vs. Speed:**
* **Semgrep:** Uses pattern matching on ASTs. It excels at finding known bad patterns, insecure configurations (Dockerfiles, Kubernetes YAML), and enforcing code standards. Its rules are easier to write, allowing teams to quickly codify custom security patterns.
* **SonarQube / CodeQL:** Employ deeper data-flow analysis (taint tracking). They can uncover complex vulnerabilities where user input flows through several functions before reaching a sensitive sink. This is more powerful but computationally expensive.
* **Customization and Rules:**
* Semgrep's rule syntax is YAML-based and relatively intuitive. Creating a rule to flag a problematic AWS SDK pattern is trivial.
```yaml
rules:
- id: avoid-s3-presigned-url-timeout
patterns:
- pattern: |
s3.generate_presigned_url(..., ExpiresIn=$EXPIRES)
- metavariable-regex:
metavariable: $EXPIRES
regex: '^(3[6-9]|[4-9][0-9]|[1-9][0-9][0-9]+)$'
message: Presigned URL expiry exceeds 1 hour. Consider shorter durations for sensitive operations.
severity: WARNING
languages: [python]
```
* CodeQL's learning curve is steeper, requiring understanding of its query language and code abstraction models.
* **Integration and Operational Overhead:**
* **Semgrep:** The CLI tool is a single binary. Integrating it into a GitHub Actions workflow or a Kubernetes-based CI runner is straightforward. Its free tier is generous for open source and small teams.
* **SonarQube:** Requires managing a server (or SaaS subscription), which introduces operational overhead—scaling, updates, and maintenance. The total cost of ownership is higher.
* **Linters (ESLint, etc.):** Fantastic for code quality but often lack the security-centric rules out-of-the-box. They are complementary; we run Semgrep *after* standard linters.
**Conclusion for Infrastructure & Cloud Context:** For platform engineering and cloud infrastructure, Semgrep is particularly compelling. Its ability to natively scan Terraform, CloudFormation, Docker, and Kubernetes manifests for security misconfigurations (e.g., publicly accessible S3 buckets, privileged containers) in the same sweep as application code unifies the review process. For deep, inter-procedural application vulnerability discovery, a combination might be optimal: Semgrep for fast, broad-spectrum scanning and CodeQL for targeted, critical-path analysis on specific components. The choice ultimately hinges on whether your primary need is developer-friendly, high-velocity feedback or maximum-depth, exhaustive security analysis for compliance-heavy environments.
I'm a security lead at a mid-sized fintech running a mix of microservices on EKS. We run Semgrep in CI and have used SonarQube and CodeQL in previous roles.
**Developer Speed:** Semgrep runs in <2 minutes on our ~500k line monorepo during CI. CodeQL database creation alone often took 15+ minutes. For pre-commit or rapid CI feedback, this is a game changer.
**Custom Rule Creation:** A security engineer on my team wrote and deployed a custom rule for a risky API pattern in under an hour using Semgrep's pattern syntax. Doing the equivalent in CodeQL required a deeper dive into their QL language.
**Language/CVE Coverage:** Semgrep shines for Terraform, Docker, and YAML. For deep, inter-procedural Java/C# vulnerabilities (think data flow taint), CodeQL still found more complex issues in my last comparison.
**Cost/Complexity:** Semgrep's free tier is generous. We use their Team tier at ~$35/developer/year. The hidden cost with CodeQL/SonarQube was the pipeline time and developer patience waiting for scans.
My pick is Semgrep for any team prioritizing developer adoption, speed, and securing config files. I'd only recommend CodeQL first if you're in a regulated industry (like banking) and your main need is the deepest possible code flow analysis for a few critical languages. Tell us your top two languages and whether pre-commit speed is a dealbreaker.