Nightjar vs.
Semgrep
Pattern matching vs. semantic proof
Semgrep finds bugs by matching code patterns. It is fast and rule-based. Nightjar proves that code satisfies behavioural contracts — it is not pattern matching but semantic verification. Nightjar found real bugs in httpx, fastmcp, and litellm that no Semgrep rule covers.
Semgrep is a best-in-class static analysis tool for known pattern classes. Nightjar catches a different class of bugs: semantic contract violations, logic errors, and invariant breaks that have no matching pattern.
Nightjar strengths
- ·Catches semantic bugs with no pattern to match (e.g. falsy `exp=0` JWT bypass)
- ·Verifies behavioural contracts, not just syntax
- ·Generates formal proofs — not just warnings
- ·48 confirmed bugs found in popular Python packages
- ·No rule library required — specs are derived from code
Semgrep strengths
- ·Extremely fast on large codebases
- ·Thousands of community and proprietary rules
- ·Language-agnostic
- ·Low false-positive rate for known patterns
- ·First-class CI integration
Feature Comparison
See what Nightjar finds in your code
Free to try. AGPL open source.