"I just want to re-iterate that there's almost zero time between thinking ‘I should find code that looks like this’ and having a check that finds code that looks like that."
"Any security team trying to get static analysis working in a DevOps world should check out Semgrep. Having fast code scans without tons of false positives through a CI/CD-native tool is a game changer."