# Security reviews for your PRs

Greptile pairs static scanning with an AI security agent to catch vulnerabilities in every pull request.

[contact sales](/contact)

[get started](https://app.greptile.com/signup)

no credit card required • 14-day free trial

SECURITY CHECK

## How Greptile security review works

### Scan types

#### 01

Opengrep rule-based scanning

Pattern-matching rules that catch dangerous code constructs deterministically.

#### 02

SCA to identify CVEs

Software composition analysis that checks your dependencies against known vulnerability databases.

#### 03

AI to detect chained exploits

Non-deterministic analysis that understands context and catches issues static tools can't.

WHAT WE CATCH

## Examples

Security findings from recent pull requests.

### Authorization bypass

A stale DNS challenge could mark a domain verified after its ownership state changed.

[See PR](https://github.com/simstudioai/sim/pull/5909#discussion_r3642178929)

### Command injection

A malicious Git tag could run attacker commands in a package-publishing workflow.

[See PR](https://github.com/irinityhq/irin/pull/8#discussion_r3643084305)

### Filesystem and PATH attack

A PATH fallback could run an attacker-controlled gh binary during a PR check.

[See PR](https://github.com/IgorGanapolsky/ThumbGate/pull/3027#discussion_r3646805742)

### Denial of service

A malformed peer-presence message could disconnect collaboration and halt document sync.

[See PR](https://github.com/openooxml/betteroffice/pull/90#discussion_r3638639641)

### Security-gate bypass

An allowlisted command could satisfy the security gate before review verification ran.

[See PR](https://github.com/IgorGanapolsky/ThumbGate/pull/3030#discussion_r3647131953)

MORE FEATURES

## Explore other features at Greptile

Find out more about how teams are using Greptile

[See docs](https://www.greptile.com/docs/introduction)

### [Agent](/agent.md)

The code reviewer that catches real bugs

[Learn more](/agent.md)

### [TREX](/trex.md)

Test every code change

[Learn more](/trex.md)

### [Independence](/independence.md)

The independent code validator

[Learn more](/independence.md)

## Find security vulnerabilities before they ship

[View Pricing](/pricing.md)

[Start now](https://app.greptile.com/signup)
