Nightjar vs.

Semgrep

Pattern matching vs. semantic proof

Semgrep finds bugs by matching code patterns. It is fast and rule-based. Nightjar proves that code satisfies behavioural contracts — it is not pattern matching but semantic verification. Nightjar found real bugs in httpx, fastmcp, and litellm that no Semgrep rule covers.

Semgrep is a best-in-class static analysis tool for known pattern classes. Nightjar catches a different class of bugs: semantic contract violations, logic errors, and invariant breaks that have no matching pattern.

Nightjar strengths
  • ·Catches semantic bugs with no pattern to match (e.g. falsy `exp=0` JWT bypass)
  • ·Verifies behavioural contracts, not just syntax
  • ·Generates formal proofs — not just warnings
  • ·48 confirmed bugs found in popular Python packages
  • ·No rule library required — specs are derived from code
Semgrep strengths
  • ·Extremely fast on large codebases
  • ·Thousands of community and proprietary rules
  • ·Language-agnostic
  • ·Low false-positive rate for known patterns
  • ·First-class CI integration

Feature Comparison

FeatureNightjarSemgrep
Detection
Known vulnerability patternsYESYES
Logic / semantic errorsYESNO
Contract violationsYESNO
Formal proof generationYESNO
Scale
Monorepo scalecomingYES
Real-time in editorNOYES

See what Nightjar finds in your code

Free to try. AGPL open source.

Get started →
← All comparisons