# Semgrep — tools that shaped CodeVetter

> Canonical page: https://codevetter.com/inspiration/semgrep

Security and bug patterns can be written as reviewable code-shaped rules.

## What we admire

Semgrep’s rules demonstrate the power of describing a problem in a form close to the source being checked. That makes static findings easier to understand and audit.

## The principle that stayed

Static analysis is strongest with a selected rule pack and known scope. A generic scanner cannot turn every warning into a reproduced failure, and running more rules is not automatically better.

## Where CodeVetter stands

Our OSS decision parked Semgrep until specific rule packs justify its cost and packaging. CodeVetter’s current verification loop does not depend on Semgrep.

## Sources

- [Semgrep source repository](https://github.com/semgrep/semgrep) — the creator's own source
- [CodeVetter OSS integration decision](https://github.com/Codevetter/codevetter/blob/main/docs/architecture/decisions/oss-integration.md) — the CodeVetter project record

This is independent appreciation, not endorsement, partnership, code reuse, or feature parity.

## Public product links

- [CodeVetter](https://codevetter.com/)
- [Download](https://codevetter.com/download)
- [Documentation](https://codevetter.com/docs/)
- [Source](https://github.com/Codevetter/codevetter)
