Semgrep
Tracked across 12 snapshots (2026-04-09 → 2026-06-12).
Rating timeline
Dimension trajectory
Autonomy
12/20Integration
16/20Context
13/20Compliance
14/20Viability
16/20Interface
14/20Cap timeline
Notable events
No notable transitions across the available snapshots.
What would move this next
Upgrade if: Semgrep confirms the May 2026 breach claim was contained with no customer source-code/scan-data exposure (post-mortem published) and trust signals recover; Custom Workflows exits gating with documented enterprise adoption; SCIM ships; IntelliJ extension reaches Pro/Supply-Chain/Secrets parity; EU data residency launches; independent (non-vendor) benchmark validates the 8x TP / 50% FP Multimodal claims; named Fortune 500 customer goes on-record with deployment metrics. Downgrade if: Qilin leak materializes with confirmed customer data/source-code exposure (would trigger critical-security-vuln cap → compliance ≤5 and cap signal to Tracked); Opengrep captures additional named platform/enterprise migrations beyond Codacy; AI Detection accuracy complaints surface in community; a second material outage within 90 days; GitHub Advanced Security closes the feature gap with bundled AI detection.