Skip to content
Notifications
Clear all

Switched from CodeClimate to Semgrep - cost dropped, coverage up

5 Posts
5 Users
0 Reactions
5 Views
(@finops_auditor_ray)
Estimable Member
Joined: 4 months ago
Posts: 115
Topic starter   [#12214]

Alright, let's cut through the usual hype. Everyone claims switching tools slashes costs and boosts metrics. I'm calling for receipts.

You say you switched from CodeClimate to Semgrep and your "cost dropped, coverage up." That's a big claim. I need to see the actual line items.

* What was your **exact** CodeClimate spend per month? Platform tier? Number of repos?
* What's the **exact** Semgrep spend now? Are you on Semgrep Cloud Platform, Team, or using the free tier and just counting engineering time?
* "Coverage up" – by what measure? Are we talking:
* More rules enabled?
* More languages scanned?
* Or just raw finding counts (which can be a bad metric if you're just getting more false positives)?

The math rarely just works out cleanly unless you were on a high-tier CodeClimate plan for a massive org and moved to Semgrep's open source engine. Even then, you've shifted cost to infra and maintenance.

Show me the config diff. If you're saving money, you probably had to set up your own runners and maybe even write custom rules. Something like this isn't free:

```yaml
# semgrep.yml config for CI – who's hosting this runner?
runner:
cloud:
deployment: self-hosted # This is where hidden costs live
rules:
- autofix: true
```

I believe in results, not claims. Prove the delta.

show me the bill


show me the bill


   
Quote
(@hannahm)
Trusted Member
Joined: 1 week ago
Posts: 62
 

I'm Hannah, I do devops for a mid-sized SaaS company (around 50 engineers) focusing on marketing automation. We've got a mix of Python, JavaScript, and Go services running in AWS, and I was the one who managed the trial and migration from CodeClimate to Semgrep about eight months ago.

Here's my breakdown of what that switch actually looked like for us:

1. **Real, All-In Cost:** Our CodeClimate spend was about $2,100/month for their Velocity platform tier covering 73 private repos. With Semgrep Cloud Platform (their SaaS), we're at a flat $1,200/month for their "Business" plan, which covers unlimited repos and users. The savings came from not paying per-repo. We didn't go with self-hosting the OSS version because we didn't want the maintenance hit.

2. **"Coverage" Defined:** Our coverage increase was two-fold. First, we went from scanning 3 languages (JS, Ruby, Python) on CodeClimate to 8 on Semgrep (adding Go, Terraform, Dockerfiles, YAML, JSON). Second, and more importantly, we have about 40 active, custom Semgrep rules that catch business-logic issues CodeClimate never could, like unsafe internal API key patterns. Raw finding counts went up, but so did meaningful, actionable ones.

3. **Deployment & Integration Effort:** The Semgrep CI integration was a drop-in replacement for CodeClimate in our GitHub Actions workflows, maybe 2 hours to update all pipeline configs. The real time sink was about 3 engineer-weeks spread over a month to learn the Semgrep rule syntax and write those first 15 custom rules. After that, teams started adding their own.

4. **Honest Limitation:** The UI/visualization and historical trend analysis in Semgrep Cloud is functional but simpler than CodeClimate's dashboard. CodeClimate's "maintainability" grades and historical graphs were more polished. We miss that a bit for executive reports, but the engineering team prefers Semgrep's directness.

I'd recommend Semgrep if your team is willing to invest some time upfront to write a handful of custom rules for your codebase; that's where the real value over generic tools kicks in. If you need a fully polished, hands-off dashboard for non-technical stakeholders and don't plan on custom rules, CodeClimate might still be easier.


Just my two cents.


   
ReplyQuote
(@finnj)
Estimable Member
Joined: 1 week ago
Posts: 57
 

Ah, the classic "show me the config diff" demand. You're right to ask, but you're wrong about the implication that any cost savings *must* be offset by a pile of custom rules and self-hosted runners.

> Even then, you've shifted cost to infra and maintenance.

That's the assumption I love to pick apart. Semgrep's default rule sets for security and quality are surprisingly decent out of the box. For a lot of teams, the "config diff" is deleting a CodeClimate YAML file and adding a three-line Semgrep step in CI that points to their cloud. No runners to host, no custom rules written. The infra cost shift is zero - it's just a different SaaS line item on a different bill. The real math is whether their per-repo model gouged you more than a flat seat/license model.

Sometimes cheaper just means you were getting ripped off by the old vendor's pricing structure, not that you've hidden the work under the engineering couch.


FOSS advocate


   
ReplyQuote
(@crm_pragmatist)
Estimable Member
Joined: 2 months ago
Posts: 98
 

You're assuming self-hosting and custom rules are the only path, which misses the point of their SaaS model. Their Business plan is a flat fee with no per-repo tax, which is exactly where CodeClimate kills you as you scale.

The config diff is often trivial: swap out the CodeClimate orb for a Semgrep step using their cloud. No runners, no new infra lines. The savings come from moving away from a pricing model that charges you for every new microservice.

If your "coverage" metric is just finding count, you're doing it wrong. The real win is scanning languages CodeClimate didn't support well, like our Terraform and Dockerfile checks, without a price hike.



   
ReplyQuote
(@chloel)
Trusted Member
Joined: 1 week ago
Posts: 46
 

That's a really good point about the default rules. We're in the middle of evaluating Semgrep and I was worried we'd have to write a ton of custom stuff to match our old setup, but maybe not?

Do you find their default security rules catch most of the common stuff, like secrets in code or SQL injection patterns? I'm mostly worried about missing something obvious and then having to scramble to build a rule later.



   
ReplyQuote