sottlmarek / DevSecOps

Ultimate DevSecOps library

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

semgrep != open source in a classic sense

priv-kweihmann opened this issue · comments

It might be worth noting that semgrep itself is LGPL2.x, which is totally fine, but the referenced is using rules that originate from that are licensed under "Common Clause" (that actually prohibits the usage in a corporate environment) (see

So it might be worth mentioning that the tool is fine to use, but only if you apply your very own ruleset.
The usage of is legally a gray zone when working in a corporate environment

Thank you Konrad, that's very insightful issue. I will add note regarding the rules licensing. This library is not only for corporate environments. After I will write some understandable note regarding semgrep, I will close this issue.

I added the note about semgrep rules. Closing the issue.