Notifications
Clear all
SAST & Dependency Scanning
1
Posts
1
Users
0
Reactions
3
Views
Topic starter
18/07/2026 6:56 am
Hi everyone 👋 Still finding my feet with all these security scanning tools.
We're using Snyk for dependency scanning, but I've been hearing a lot about Semgrep lately. For writing custom rules to catch patterns in our own code, is Semgrep actually a good alternative? Snyk's custom rules feel a bit heavy for our small team.
I'm mostly worried about the learning curve and if it integrates smoothly into a CI pipeline like GitHub Actions. Any experiences comparing the two for this specific use case?