[{"data":1,"prerenderedAt":658},["ShallowReactive",2],{"tool-semgrep-en":3},{"slug":4,"published":5,"minutes":6,"category":7,"tags":8,"keywords":14,"about":21,"sources":28,"cover":53,"og":54,"expertise":55,"locales":56,"lang":57,"title":60,"description":61,"coverAlt":62,"url":24,"pricing":63,"kind":64,"metaTitle":65,"takeaways":66,"faq":72,"toc":85,"blocks":110,"others":447},"semgrep","2026-08-14",10,"security",[9,10,11,12,13],"SAST","Static analysis","CI security","Rule authoring","AppSec",[4,15,16,17,18,19,20],"semgrep vs codeql","semgrep rules","semgrep pricing","semgrep pro engine","free sast tools","semgrep ci github actions",[22,25],{"name":23,"url":24},"Semgrep","https:\u002F\u002Fsemgrep.dev",{"name":26,"url":27},"Static application security testing","https:\u002F\u002Fen.wikipedia.org\u002Fwiki\u002FStatic_application_security_testing",[29,32,35,38,41,44,47,50],{"title":30,"url":31},"Semgrep pricing: Free, Teams and Enterprise","https:\u002F\u002Fsemgrep.dev\u002Fpricing\u002F",{"title":33,"url":34},"Semgrep Community Edition","https:\u002F\u002Fsemgrep.dev\u002Fproducts\u002Fcommunity-edition",{"title":36,"url":37},"Semgrep documentation: cross-file analysis","https:\u002F\u002Fdocs.semgrep.dev\u002Fsemgrep-code\u002Fsemgrep-pro-engine-intro\u002F",{"title":39,"url":40},"Semgrep documentation: usage and billing","https:\u002F\u002Fdocs.semgrep.dev\u002Fusage-and-billing\u002Foverview\u002F",{"title":42,"url":43},"Semgrep releases: v1.179.0","https:\u002F\u002Fgithub.com\u002Fsemgrep\u002Fsemgrep\u002Freleases",{"title":45,"url":46},"Semgrep Rules License v1.0","https:\u002F\u002Fsemgrep.dev\u002Flegal\u002Frules-license\u002F",{"title":48,"url":49},"Important updates to Semgrep OSS, 13 December 2024","https:\u002F\u002Fsemgrep.dev\u002Fblog\u002F2024\u002Fimportant-updates-to-semgrep-oss\u002F",{"title":51,"url":52},"OpenGrep repository","https:\u002F\u002Fgithub.com\u002Fopengrep\u002Fopengrep","\u002Fimages\u002Fblog\u002Fsemgrep\u002Fcover.webp","\u002Fimages\u002Fblog\u002Fsemgrep\u002Fog.jpg","ai-engineer",[57,58,59],"en","de","hu","Semgrep: static analysis that fits in a pull request","Semgrep parses 30-plus languages and matches YAML patterns in seconds, and the engine is free under LGPL-2.1. Cross-file analysis, the rulesets and the AI triage sit behind paid tiers.","Diagram of the Semgrep scan pipeline, from source files through parsing and rule matching to reported findings","Free · from $30 per seat","Static analysis with AI rules","Semgrep review: free SAST with a paid ceiling · Balázs Csorba",[67,68,69,70,71],"The Semgrep engine is LGPL-2.1 and scans 30-plus languages offline; cross-file analysis needs a proprietary binary and an account.","The free tier covers 10 contributors and 10 private repositories, and counts contributors from a rolling 90-day git log.","Since 13 December 2024 Semgrep-maintained rules carry the Semgrep Rules License v1.0, which forbids redistribution and service use; OpenGrep is the LGPL fork that answers it.","Cross-file analysis silently falls back to single-file after 5 GB of memory or three hours, so a large repository loses depth without failing.","AI Autofix costs 20 credits per finding against 20 monthly credits per Teams contributor, which makes autofix the most expensive action on the plan.",[73,76,79,82],{"q":74,"a":75},"Is Semgrep free to use in production?","The engine is free under LGPL-2.1 and the CLI runs without an account. The hosted free tier covers up to 10 contributors and 10 private repositories; beyond that Teams starts at $30 per contributor per month. The rules Semgrep maintains are free only for internal, non-competing use.",{"q":77,"a":78},"What is the difference between Community Edition and the Pro engine?","Community Edition analysis is intraprocedural, meaning it reasons inside a single function. The Pro engine adds cross-function analysis, which Semgrep Code runs by default, and optional cross-file analysis. It is a separate binary installed with semgrep install-semgrep-pro after semgrep login.",{"q":80,"a":81},"How accurate is Semgrep?","No precision figure is published, so the honest answer is structural: matching happens against a syntax tree, so a finding is either an exact pattern match or a rule that was written too loosely. Most noise in practice comes from rules without metavariable constraints rather than from the engine.",{"q":83,"a":84},"Does Semgrep send my source code to the cloud?","Run locally or fully in your own CI and the source stays put; only scan metadata is sent to the service. AI features submit the file containing a finding to a model, and Managed Scans clone the repository for the scan and destroy the clone afterwards.",[86,89,92,95,98,101,104,107],{"id":87,"title":88},"what-it-is","What it is",{"id":90,"title":91},"how-it-works","How it works",{"id":93,"title":94},"getting-started","Getting started",{"id":96,"title":97},"pricing","Pricing and the rules licence",{"id":99,"title":100},"scaling-in-ci","Running it in CI",{"id":102,"title":103},"where-it-shingles","Where it shingles",{"id":105,"title":106},"verdict","Verdict",{"id":108,"title":109},"sources","Sources",[111,115,118,121,124,149,150,153,162,169,179,180,183,185,212,227,228,231,270,273,276,319,327,328,331,343,344,347,393,396,397,400,413,419,420],{"type":112,"content":113},"paragraph",[114],"Semgrep is a static analyser built around pattern matching: it parses source code into a syntax tree, then reports every place where a YAML rule's pattern matches that tree. The engine is open source under LGPL-2.1, runs on a laptop with no network connection, and finishes a typical repository in seconds. The position taken here is that it is the cheapest credible first SAST tool a small team can put into CI, and that the free tier is a well-built on-ramp rather than a finished product: the analysis that removes most of the noise, the rulesets it ships with and the AI triage all sit behind a login.",{"type":112,"content":116},[117],"It sits between the linters a team already runs and the heavyweight scanners that need a security engineer to feed them. In practice it competes with CodeQL for depth, with SonarQube for the pull-request gate and with Snyk Code for developer ergonomics; the open-source fork OpenGrep competes for the licence. What it replaces most often is a folder of half-maintained grep patterns.",{"type":119,"level":120,"id":87,"text":88},"heading",2,{"type":112,"content":122},[123],"A command-line scanner plus a hosted platform. The command line does the work: give it a target directory and one or more rulesets, and it returns findings carrying the rule id, severity, message and matched range. The platform, named Semgrep AppSec Platform, adds a dashboard, policy, pull-request comments, Supply Chain, Secrets detection and the AI features. Everything below the platform is the Community Edition.",{"type":125,"ordered":126,"items":127},"list",false,[128,130,132,138,140,142,144],[129],"Engine licence LGPL-2.1; latest release 1.179.0, published 1 October 2026",[131],"30-plus languages in Community Edition, 35-plus listed for Semgrep Code",[133,134],"3,000-plus community rules, plus registry rulesets by prefix such as ",{"tag":135,"children":136},"code",[137],"p\u002Fpython",[139],"Free tier: 10 contributors, 10 private repositories, 60 AI credits a month",[141],"Teams from $30 per contributor a month; Secrets is $15",[143],"Contributors counted from the git log over a rolling 90 days",[145,146],"Cross-file analysis needs a proprietary binary from ",{"tag":135,"children":147},[148],"semgrep install-semgrep-pro",{"type":119,"level":120,"id":90,"text":91},{"type":112,"content":151},[152],"Each language has a parser, mostly tree-sitter based, that turns the file into a syntax tree. A rule is a pattern over that tree written with metavariables such as $X and $F, plus optional constraints in patterns, pattern-not, metavariable-regex and taint mode. Matching is structural rather than textual: whitespace, renamed variables and reordered statements do not hide a match, which is why the false-positive rate stays low enough for a pull-request gate.",{"type":154,"attrs":155,"inner":159,"caption":160},"diagram",{"viewBox":156,"role":157,"aria-labelledby":158},"0 0 720 300","img","sg-t sg-d","\u003Ctitle id=\"sg-t\">Semgrep: how a scan turns source into findings\u003C\u002Ftitle>\u003Cdesc id=\"sg-d\">Source files are parsed into a syntax tree, matched against rule patterns, and reported as findings. Rulesets from the registry and the optional Pro engine feed the matching step, and findings leave as terminal output, JSON or SARIF.\u003C\u002Fdesc>\u003Ctext x=\"20\" y=\"28\" class=\"d-title\">Semgrep: source in, findings out\u003C\u002Ftext>\u003Ctext x=\"700\" y=\"28\" text-anchor=\"end\" class=\"d-label\">semgrep.dev\u003C\u002Ftext>\u003Ctext x=\"20\" y=\"56\" class=\"d-label\">EVERY SCAN\u003C\u002Ftext>\u003Crect x=\"20\" y=\"70\" width=\"120\" height=\"64\" rx=\"10\" class=\"d-box\" \u002F>\u003Ctext x=\"80\" y=\"98\" text-anchor=\"middle\" class=\"d-text\">Source files\u003C\u002Ftext>\u003Ctext x=\"80\" y=\"119\" text-anchor=\"middle\" class=\"d-small\">src, git\u003C\u002Ftext>\u003Cpath d=\"M140 102 H152\" class=\"d-line\" \u002F>\u003Cpath d=\"M160 102 l-9 -5 v10 z\" class=\"d-head\" \u002F>\u003Crect x=\"160\" y=\"70\" width=\"120\" height=\"64\" rx=\"10\" class=\"d-box\" \u002F>\u003Ctext x=\"220\" y=\"98\" text-anchor=\"middle\" class=\"d-text\">Parser\u003C\u002Ftext>\u003Ctext x=\"220\" y=\"119\" text-anchor=\"middle\" class=\"d-small\">tree-sitter AST\u003C\u002Ftext>\u003Cpath d=\"M280 102 H292\" class=\"d-line\" \u002F>\u003Cpath d=\"M300 102 l-9 -5 v10 z\" class=\"d-head\" \u002F>\u003Crect x=\"300\" y=\"70\" width=\"120\" height=\"64\" rx=\"10\" class=\"d-sky\" \u002F>\u003Ctext x=\"360\" y=\"98\" text-anchor=\"middle\" class=\"d-text\">Rule match\u003C\u002Ftext>\u003Ctext x=\"360\" y=\"119\" text-anchor=\"middle\" class=\"d-small\">patterns, taint\u003C\u002Ftext>\u003Cpath d=\"M420 102 H432\" class=\"d-line\" \u002F>\u003Cpath d=\"M440 102 l-9 -5 v10 z\" class=\"d-head\" \u002F>\u003Crect x=\"440\" y=\"70\" width=\"120\" height=\"64\" rx=\"10\" class=\"d-sky\" \u002F>\u003Ctext x=\"500\" y=\"98\" text-anchor=\"middle\" class=\"d-text\">Findings\u003C\u002Ftext>\u003Ctext x=\"500\" y=\"119\" text-anchor=\"middle\" class=\"d-small\">id, severity\u003C\u002Ftext>\u003Cpath d=\"M560 102 H572\" class=\"d-line\" \u002F>\u003Cpath d=\"M580 102 l-9 -5 v10 z\" class=\"d-head\" \u002F>\u003Crect x=\"580\" y=\"70\" width=\"120\" height=\"64\" rx=\"10\" class=\"d-accent\" \u002F>\u003Ctext x=\"640\" y=\"98\" text-anchor=\"middle\" class=\"d-text\">Report\u003C\u002Ftext>\u003Ctext x=\"640\" y=\"119\" text-anchor=\"middle\" class=\"d-small\">json, SARIF\u003C\u002Ftext>\u003Ctext x=\"20\" y=\"172\" class=\"d-label\">WHAT FEEDS THE MATCH\u003C\u002Ftext>\u003Cpath d=\"M185 186 C185 158 350 168 356 152\" class=\"d-line\" \u002F>\u003Cpath d=\"M358 144 l-5 10 h10 z\" class=\"d-head\" \u002F>\u003Cpath d=\"M535 186 C535 158 380 168 372 152\" class=\"d-line\" \u002F>\u003Cpath d=\"M370 144 l-5 10 h10 z\" class=\"d-head\" \u002F>\u003Crect x=\"20\" y=\"186\" width=\"330\" height=\"64\" rx=\"10\" class=\"d-mint\" \u002F>\u003Ctext x=\"185\" y=\"214\" text-anchor=\"middle\" class=\"d-text\">Registry rulesets\u003C\u002Ftext>\u003Ctext x=\"185\" y=\"235\" text-anchor=\"middle\" class=\"d-small\">auto, p\u002Fpython\u003C\u002Ftext>\u003Crect x=\"370\" y=\"186\" width=\"330\" height=\"64\" rx=\"10\" class=\"d-gold\" \u002F>\u003Ctext x=\"535\" y=\"214\" text-anchor=\"middle\" class=\"d-text\">Pro engine\u003C\u002Ftext>\u003Ctext x=\"535\" y=\"235\" text-anchor=\"middle\" class=\"d-small\">cross-file, login\u003C\u002Ftext>",[161],"The rule decides what counts as a finding; the engine only decides where a pattern matches.",{"type":112,"content":163},[164,165,168],"Findings carry the rule id, severity and a message, and can be suppressed per line with a ",{"tag":135,"children":166},[167],"nosemgrep"," comment or per rule with an ignore entry. Output goes to the terminal, to JSON or to SARIF, which is what most dashboards ingest.",{"type":112,"content":170},[171,172,175,176,178],"The boundary that matters is scope. Community Edition analysis is intraprocedural: it reasons inside a single function. Cross-function and cross-file analysis run on the Pro engine, a separate binary that only activates after ",{"tag":135,"children":173},[174],"semgrep login"," and ",{"tag":135,"children":177},[148],".",{"type":119,"level":120,"id":93,"text":94},{"type":112,"content":181},[182],"Install the CLI with pip, pipx, uv or brew; no account is needed to scan with community rules. A rule file is small enough to sit next to the code it protects.",{"type":135,"code":184},"# rules\u002Fno-pickle.yaml\nrules:\n  - id: avoid-pickle-load\n    languages: [python]\n    severity: WARNING\n    message: |\n      pickle.load executes whatever is in the stream. Only feed it\n      bytes that never left this machine; use json.loads otherwise.\n    pattern: pickle.load($STREAM)",{"type":112,"content":186},[187,188,191,192,195,196,199,200,203,204,207,208,211],"Then run ",{"tag":135,"children":189},[190],"semgrep scan --config rules\u002Fno-pickle.yaml src\u002F"," for one ruleset, ",{"tag":135,"children":193},[194],"semgrep scan --config p\u002Fpython src\u002F"," for a registry prefix, or ",{"tag":135,"children":197},[198],"semgrep --config auto"," to let the tool choose rulesets from the languages it detects. Add ",{"tag":135,"children":201},[202],"--json"," or ",{"tag":135,"children":205},[206],"--sarif"," for machine-readable output, and ",{"tag":135,"children":209},[210],"semgrep ci"," once a repository is connected to a deployment.",{"type":213,"variant":214,"title":215,"body":216},"callout","tip","Where the source code goes",[217,225],[218,219,203,222,178],"Run it locally or fully inside your own CI and the source never leaves the machine; only Semgrep metadata is sent to the service, according to the pricing FAQ. Metrics can be switched off with ",{"tag":135,"children":220},[221],"--metrics off",{"tag":135,"children":223},[224],"SEMGREP_SEND_METRICS=off",[226],"Two things do send code out: the AI features, which submit the file containing a finding, and Managed Scans, which clone the repository for the duration of the scan and destroy the clone afterwards.",{"type":119,"level":120,"id":96,"text":97},{"type":112,"content":229},[230],"The engine is free; the interesting money sits around it. The pricing page as of October 2026 lists three plans, and the free one is capped in a way that only becomes visible at the eleventh contributor.",{"type":232,"head":233,"rows":242},"table",[234,236,238,240],[235],"Plan",[237],"Price",[239],"Limits",[241],"What it unlocks",[243,252,261],[244,246,248,250],[245],"Free",[247],"$0",[249],"10 contributors, 10 private repositories",[251],"Code and Supply Chain, 60 AI credits a month",[253,255,257,259],[254],"Teams",[256],"From $30 per contributor a month",[258],"500 private repositories",[260],"SSO, role-based access, Secrets at $15, 20 AI credits each",[262,264,266,268],[263],"Enterprise",[265],"Custom",[267],"No limit on repositories or contributors",[269],"On-prem source control, custom CI, 50 AI credits, account manager",{"type":112,"content":271},[272],"Licence is a separate question from price. The engine stays LGPL-2.1, but since 13 December 2024 the rules Semgrep maintains ship under the Semgrep Rules License v1.0, which allows internal, non-competing use and forbids redistribution or offering the rules as a service. Consultants and companies using them internally are inside those terms; a vendor building a competing SAST product on them is not. That change is what produced OpenGrep, an LGPL-2.1 fork maintained by a consortium of security vendors including Aikido, Endor Labs, Jit and Orca Security.",{"type":112,"content":274},[275],"AI features are metered separately in credits, and the costs are published. Comments on a pull request are free, triage costs one credit per finding, and Autofix, which opens a pull request with a fix, costs twenty.",{"type":232,"head":277,"rows":284},[278,280,282],[279],"AI action",[281],"Credits",[283],"What it does",[285,292,299,306,313],[286,288,290],[287],"AI comments on a pull request",[289],"0",[291],"Guidance posted on the PR",[293,295,297],[294],"AI analysis of a finding",[296],"1 per finding",[298],"Triage, remediation guidance, component tagging",[300,302,304],[301],"AI Autofix",[303],"20 per finding",[305],"Opens a pull request that fixes the finding",[307,309,311],[308],"AI-powered detection scan",[310],"Variable",[312],"Depends on scan size and complexity",[314,316,317],[315],"Agentic Workflows run",[310],[318],"Multi-step analysis, more tokens than a detection scan",{"type":213,"variant":320,"title":321,"body":322},"warn","What the AI features send",[323,325],[324],"AI analysis submits the file containing the finding to a model. Entitlement credits expire at the end of the contract and do not roll over, so a quiet quarter is a quarter of budget lost.",[326],"Autofix at 20 credits per finding makes the credit pool the real rate limit: on the Teams plan a contributor gets 20 credits a month, so one Autofix spends the whole monthly allocation.",{"type":119,"level":120,"id":99,"text":100},{"type":112,"content":329},[330],"Semgrep is unusual in that the free tier is genuinely fast, and that changes what is worth gating on. The failure modes in large repositories are about depth and memory rather than about the scan itself.",{"type":125,"ordered":126,"items":332},[333,335,337,339,341],[334],"Diff-aware scans analyse only what a pull request touched; cross-file analysis runs on full scans and never on pull-request scans.",[336],"Cross-file analysis falls back to single-file once a scan passes 5 GB of memory or three hours, so a large repository quietly loses depth instead of failing the build.",[338],"Monorepo support splits a repository into parts on every plan; distributed scans across several machines start at Teams.",[340],"Join mode, the only facility in the open engine for joining matches across rules, is documented as experimental and not actively maintained.",[342],"Rules can be shared through the registry; private rules that keep sensitive rule logic inside the organisation need Teams or above.",{"type":119,"level":120,"id":102,"text":103},{"type":112,"content":345},[346],"The ceiling arrives sooner than the pricing page suggests. Community Edition only reasons inside one function, so a tainted value crossing a helper is invisible until somebody pays for the Pro engine, and type inference and constant propagation are the same story. The second limit is rule quality: generic patterns without a metavariable constraint produce enough noise that teams learn to ignore the tool, and writing tight rules is a skill a team has to acquire. The third is arithmetic: at $30 per contributor per month on a rolling 90-day count taken from git log, anyone who committed to a private repository in that window is billed, whether or not they are still on the project.",{"type":232,"head":348,"rows":356},[349,351,353,354],[350],"Tool",[352],"Analysis depth",[12],[355],"What it costs",[357,366,375,384],[358,360,362,364],[359],"Semgrep CE",[361],"Intraprocedural, one function at a time",[363],"YAML patterns a reviewer can read",[365],"Free engine, Semgrep-maintained rules for internal use only",[367,369,371,373],[368],"CodeQL",[370],"Whole-database dataflow across files",[372],"QL, a query language with a real learning curve",[374],"Free for public repositories, GitHub Code Security otherwise",[376,378,380,382],[377],"SonarQube",[379],"Quality plus baseline security; taint on paid tiers",[381],"Custom rules need a Java plugin",[383],"Community Build free, paid tiers per instance",[385,387,389,391],[386],"Snyk Code",[388],"Dataflow in a hosted engine",[390],"Vendor-maintained rules, little to write yourself",[392],"Paid, priced per developer",{"type":112,"content":394},[395],"The opinionated version: for a team of eight, depth matters less than being read. A ruleset a developer understands and can extend in YAML will be acted on; a whole-database query language nobody has time to learn will not. The moment the threat model is dataflow across a service boundary, Semgrep CE cannot answer the question, and the $30 tier is the cheap option next to migrating the rules to QL.",{"type":119,"level":120,"id":105,"text":106},{"type":112,"content":398},[399],"Take it as the default first scanner, with the eyes open about where the paid ceiling sits.",{"type":125,"ordered":401,"items":402},true,[403,405,407,409,411],[404],"Use the free Community Edition when the goal is a working security gate in CI within a week and nobody on the team writes query languages.",[406],"Pay for Teams when single-function analysis produces findings developers argue with, and when SSO, a dashboard and private rules have become requirements rather than wishes.",[408],"Do not treat $30 as the price: it is $30 per contributor per month on a 90-day rolling count, and unlimited repositories, on-prem source control and custom CI integrations live in Enterprise.",[410],"Choose CodeQL when the question is how data reaches a sink across a compiled codebase, and SonarQube when the gate is about maintainability as much as security.",[412],"If the rules have to be redistributed or served to third parties, the engine without the Semgrep-maintained rulesets, or OpenGrep, is the only arrangement that needs no conversation with the vendor.",{"type":213,"variant":414,"title":415,"body":416},"note","The claim to argue with",[417],[418],"That free static analysis is good enough for most teams is defensible. That it stays enough is not: single-function analysis was a reasonable trade when Semgrep was a pattern search, and it is the reason teams pay. Anyone adopting the free tier should write down, on the day of adoption, what finding would justify the upgrade, otherwise the upgrade gets decided by an incident instead of by a plan.",{"type":119,"level":120,"id":108,"text":109},{"type":125,"ordered":401,"items":421},[422,426,429,432,435,438,441,444],[423],{"tag":424,"href":31,"children":425},"a",[30],[427],{"tag":424,"href":34,"children":428},[33],[430],{"tag":424,"href":37,"children":431},[36],[433],{"tag":424,"href":40,"children":434},[39],[436],{"tag":424,"href":43,"children":437},[42],[439],{"tag":424,"href":46,"children":440},[45],[442],{"tag":424,"href":49,"children":443},[48],[445],{"tag":424,"href":52,"children":446},[51],[448,510,567,624],{"slug":449,"published":450,"minutes":6,"category":7,"tags":451,"keywords":456,"about":464,"sources":474,"cover":502,"og":503,"expertise":55,"locales":504,"lang":57,"title":505,"description":506,"coverAlt":507,"url":508,"pricing":509,"kind":453},"guardrails-ai","2026-09-29",[452,453,454,455],"Guardrails","Output validation","LLM reliability","Python",[457,458,459,460,461,462,463],"guardrails ai","guardrails ai validators","llm output validation python","guardrails vs nemo guardrails","guardrails on_fail actions","llm guardrails framework","pii validation llm output",[465,468,471],{"name":466,"url":467},"NVIDIA","https:\u002F\u002Fen.wikipedia.org\u002Fwiki\u002FNVIDIA",{"name":469,"url":470},"Apache License","https:\u002F\u002Fen.wikipedia.org\u002Fwiki\u002FApache_License",{"name":472,"url":473},"Large language model","https:\u002F\u002Fen.wikipedia.org\u002Fwiki\u002FLarge_language_model",[475,478,481,484,487,490,493,496,499],{"title":476,"url":477},"Guardrails AI on GitHub: README, news and FAQ","https:\u002F\u002Fgithub.com\u002Fguardrails-ai\u002Fguardrails",{"title":479,"url":480},"guardrails-ai 0.11.0 on PyPI","https:\u002F\u002Fpypi.org\u002Fproject\u002Fguardrails-ai\u002F",{"title":482,"url":483},"Guardrails Hub: 65 validators","https:\u002F\u002Fwww.guardrailsai.com\u002Fhub",{"title":485,"url":486},"Guardrails documentation: error remediation and on-fail actions","https:\u002F\u002Fwww.guardrailsai.com\u002Fdocs\u002Fconcepts\u002Ferror_remediation",{"title":488,"url":489},"Guardrails documentation: use on-fail actions","https:\u002F\u002Fwww.guardrailsai.com\u002Fguardrails\u002Fdocs\u002Fhow-to-guides\u002Fuse_on_fail_actions",{"title":491,"url":492},"Migration issue 1560: moving off hosted remote inferencing","https:\u002F\u002Fgithub.com\u002Fguardrails-ai\u002Fguardrails\u002Fissues\u002F1560",{"title":494,"url":495},"NVIDIA NeMo Guardrails on GitHub","https:\u002F\u002Fgithub.com\u002FNVIDIA-NeMo\u002FGuardrails",{"title":497,"url":498},"NVIDIA NeMo Guardrails documentation","https:\u002F\u002Fdocs.nvidia.com\u002Fnemo\u002Fguardrails\u002Flatest\u002Findex.html",{"title":500,"url":501},"OpenAI API pricing, including moderation","https:\u002F\u002Fdevelopers.openai.com\u002Fapi\u002Fdocs\u002Fpricing","\u002Fimages\u002Fblog\u002Fguardrails-ai\u002Fcover.webp","\u002Fimages\u002Fblog\u002Fguardrails-ai\u002Fog.jpg",[57,58,59],"Guardrails AI: validating what the model returns","A review of Guardrails AI: 65 hub validators, eight on-fail actions, the August 2026 shutdown of hosted inferencing, and when NeMo Guardrails fits better.","Guardrails AI cover artwork with validator pipeline labels","https:\u002F\u002Fwww.guardrailsai.com","Apache-2.0",{"slug":511,"published":512,"minutes":513,"category":7,"tags":514,"keywords":518,"about":527,"sources":533,"cover":558,"og":559,"expertise":55,"locales":560,"lang":57,"title":561,"description":562,"coverAlt":563,"url":564,"pricing":565,"kind":566},"lakera-guard","2026-08-04",9,[515,452,516,517],"Prompt injection","LLM security","Content moderation",[519,520,521,522,523,524,525,526],"lakera guard","lakera guard review","prompt injection filter","prompt injection detection","llm guardrails comparison","pint benchmark","check point ai guardrails","lakera pricing",[528,530],{"name":515,"url":529},"https:\u002F\u002Fen.wikipedia.org\u002Fwiki\u002FPrompt_injection",{"name":531,"url":532},"Check Point","https:\u002F\u002Fwww.checkpoint.com\u002F",[534,537,540,543,546,549,552,555],{"title":535,"url":536},"Lakera documentation: Guard API","https:\u002F\u002Fdocs.lakera.ai\u002Fdocs\u002Fapi\u002Fguard",{"title":538,"url":539},"Guard API endpoint reference","https:\u002F\u002Fdocs.lakera.ai\u002Fapi-reference\u002Flakera-api\u002Fguard\u002Fscreen-content",{"title":541,"url":542},"Lakera documentation: projects","https:\u002F\u002Fdocs.lakera.ai\u002Fdocs\u002Fprojects",{"title":544,"url":545},"Lakera documentation: self-hosting","https:\u002F\u002Fdocs.lakera.ai\u002Fdocs\u002Fselfhosting",{"title":547,"url":548},"Lakera platform pricing","https:\u002F\u002Fplatform.lakera.ai\u002Fpricing",{"title":550,"url":551},"PINT benchmark on GitHub","https:\u002F\u002Fgithub.com\u002Flakeraai\u002Fpint-benchmark",{"title":553,"url":554},"Lakera homepage","https:\u002F\u002Fwww.lakera.ai\u002F",{"title":556,"url":557},"Check Point press release on the Lakera acquisition","https:\u002F\u002Fwww.checkpoint.com\u002Fpress-releases\u002Fcheck-point-acquires-lakera-to-deliver-end-to-end-ai-security-for-enterprises\u002F","\u002Fimages\u002Fblog\u002Flakera-guard\u002Fcover.webp","\u002Fimages\u002Fblog\u002Flakera-guard\u002Fog.jpg",[57,58,59],"Lakera Guard: prompt injection filtering at the request boundary","A review of Lakera Guard: one endpoint before the model, the PINT benchmark behind its scores, and why the free tier stops at 10,000 requests a month.","Cover art for the Lakera Guard review: a filter screen in front of a language model","https:\u002F\u002Fwww.lakera.ai","Free tier · from $20 per month","Prompt injection filter",{"slug":568,"published":569,"minutes":6,"category":7,"tags":570,"keywords":575,"about":582,"sources":589,"cover":617,"og":618,"expertise":55,"locales":619,"lang":57,"title":620,"description":621,"coverAlt":622,"url":592,"pricing":509,"kind":623},"detect-secrets","2026-08-03",[571,572,573,574],"Secret scanning","Pre-commit","Git","DevSecOps",[568,576,577,578,579,580,581],"detect-secrets vs gitleaks","detect-secrets baseline","secret scanning tools comparison","gitleaks vs trufflehog","rotate leaked api keys","pre-commit secret hook",[583,586,588],{"name":584,"url":585},"Yelp","https:\u002F\u002Fen.wikipedia.org\u002Fwiki\u002FYelp",{"name":573,"url":587},"https:\u002F\u002Fen.wikipedia.org\u002Fwiki\u002FGit",{"name":469,"url":470},[590,593,596,599,602,605,608,611,614],{"title":591,"url":592},"Yelp\u002Fdetect-secrets: README and usage","https:\u002F\u002Fgithub.com\u002FYelp\u002Fdetect-secrets",{"title":594,"url":595},"Yelp\u002Fdetect-secrets: CHANGELOG (v1.5.0, 6 May 2024)","https:\u002F\u002Fgithub.com\u002FYelp\u002Fdetect-secrets\u002Fblob\u002Fmaster\u002FCHANGELOG.md",{"title":597,"url":598},"Yelp\u002Fdetect-secrets: plugin and verification documentation","https:\u002F\u002Fgithub.com\u002FYelp\u002Fdetect-secrets\u002Fblob\u002Fmaster\u002Fdocs\u002Fplugins.md",{"title":600,"url":601},"detect-secrets 1.5.0 on PyPI","https:\u002F\u002Fpypi.org\u002Fproject\u002Fdetect-secrets\u002F",{"title":603,"url":604},"Yelp\u002Fdetect-secrets: releases","https:\u002F\u002Fgithub.com\u002FYelp\u002Fdetect-secrets\u002Freleases",{"title":606,"url":607},"Gitleaks README (MIT, Go)","https:\u002F\u002Fgithub.com\u002Fgitleaks\u002Fgitleaks",{"title":609,"url":610},"TruffleHog README (AGPL-3.0, credential verification)","https:\u002F\u002Fgithub.com\u002Ftrufflesecurity\u002Ftrufflehog",{"title":612,"url":613},"GitHub Docs: About secret scanning","https:\u002F\u002Fdocs.github.com\u002Fen\u002Fcode-security\u002Fsecret-scanning\u002Fintroduction\u002Fabout-secret-scanning",{"title":615,"url":616},"betterleaks\u002Fbetterleaks","https:\u002F\u002Fgithub.com\u002Fbetterleaks\u002Fbetterleaks","\u002Fimages\u002Fblog\u002Fdetect-secrets\u002Fcover.webp","\u002Fimages\u002Fblog\u002Fdetect-secrets\u002Fog.jpg",[57,58,59],"detect-secrets: secret scanning with a committed baseline","What detect-secrets does, how its committed baseline differs from gitleaks and TruffleHog, why verification calls matter in CI, and where the tool stops.","Diagram: files pass through transformers, plugins, filters and verification into a JSON baseline, which then feeds the pre-commit gate and the audit session.","Secret detection",{"slug":625,"published":626,"minutes":513,"category":7,"tags":627,"keywords":629,"about":634,"sources":639,"cover":651,"og":652,"expertise":55,"locales":653,"lang":57,"title":654,"description":655,"coverAlt":656,"url":637,"pricing":509,"kind":657},"rebuff","2026-06-22",[515,516,452,628],"Canary tokens",[625,522,630,631,632,633],"rebuff python sdk","llm prompt injection guardrail","canary token leak detection","rebuff alternative",[635,638],{"name":636,"url":637},"Rebuff","https:\u002F\u002Fgithub.com\u002Fprotectai\u002Frebuff",{"name":472,"url":473},[640,642,645,648],{"title":641,"url":637},"Rebuff repository, archived 16 May 2025",{"title":643,"url":644},"Rebuff 0.1.1 on PyPI, released 20 January 2024","https:\u002F\u002Fpypi.org\u002Fproject\u002Frebuff\u002F",{"title":646,"url":647},"LangChain: Rebuff, detecting prompt injection attacks","https:\u002F\u002Fwww.langchain.com\u002Fblog\u002Frebuff",{"title":649,"url":650},"LLM Guard repository, archived 9 July 2026","https:\u002F\u002Fgithub.com\u002Fprotectai\u002Fllm-guard","\u002Fimages\u002Fblog\u002Frebuff\u002Fcover.webp","\u002Fimages\u002Fblog\u002Frebuff\u002Fog.jpg",[57,58,59],"Rebuff: four layers of prompt injection detection, now archived","Rebuff scored prompts with heuristics, an LLM, a vector store of past attacks and canary tokens. The repository was archived in May 2025 and the last release dates from January 2024.","Diagram of the Rebuff detection path, from incoming prompt through heuristics, LLM check and vector search to a verdict","Prompt injection detection",1791383548801]