Automic VaultAutomic Vault

brew

staticcheck mit Homebrew, apk, dnf, MacPorts, pacman, scoop installieren

Prüfe Installationswege, Executables, Metadaten und Sicherheitshinweise für staticcheck in AI-Agent-Workflows.

Installation

Weitere Installationsbefehle

macOS

Homebrewverifiziert · 100%
brew install staticcheck

local Homebrew formula metadata

MacPortsverifiziert · 94%
sudo port install staticcheck

MacPorts ports tree · devel/staticcheck/Portfile · Quelle: api.github.com

Windows

Scoopverifiziert · 92%
scoop install main/staticcheck

Scoop official bucket manifest trees · bucket/staticcheck.json · Quelle: api.github.com

Überblick

Paketzusammenfassung

State of the art linter for the Go programming language

Befehle und Aliase

  • staticcheck

Verlauf

Projektgeschichte und Nutzung

Staticcheck is a Go static-analysis command-line tool and one of the best-known third-party linters in the Go ecosystem. It is packaged as the `staticcheck` executable and is commonly installed with Go tooling or system package managers for local development and CI.

Projektgeschichte

The upstream project lives in Dominik Honnef's `go-tools` repository, which was created in January 2017. The official README describes Staticcheck as an advanced Go linter that finds bugs and performance issues, offers simplifications, and enforces style rules.

Staticcheck publishes release notes on staticcheck.dev. The release-note index records releases from 2017.2 through the 2026 series, showing a long-running tool with versioned compatibility work alongside Go's release cadence.

Adoptionsgeschichte

The input package metadata lists Staticcheck in Homebrew, Alpine, Fedora, MacPorts, Arch, and Scoop. The official documentation also recommends installing released versions with `go install honnef.co/go/tools/cmd/staticcheck@latest` on modern Go versions or using prebuilt binaries from GitHub releases.

Staticcheck's package-manager footprint reflects its role as a standard quality gate for Go projects. It is useful as a standalone CLI, as a CI check, and as a linter that complements the Go compiler and `go vet`.

Wie es verwendet wird

Typical usage is to run `staticcheck` against Go packages or wire it into CI. The tool can analyze code targeting Go versions up to the latest release, while the project recommends using tagged releases instead of master for stable builds.

Warum Paket-Nerds sich dafür interessieren

Package nerds care about Staticcheck because it is a canonical example of a language ecosystem tool that lives outside the core toolchain but is widely treated as infrastructure. Its version tags, prebuilt binaries, and `go install` path make it straightforward to pin in reproducible builds.

For package managers, Staticcheck is high-value despite being a single executable: it is heavily used by Go developers, has stable release notes, and represents the broader `honnef.co/go/tools` analyzer collection.

Zeitleiste

  • 2017: `dominikh/go-tools` repository created.
  • 2017: Staticcheck 2017.2 release published.
  • 2019: Staticcheck 2019.2 release notes described major performance and memory improvements.
  • 2026: Staticcheck 2026.1 and 2026.2 release candidates appeared in official releases.

Related projects

  • The same repository contains related tools such as `structlayout`, `structlayout-optimize`, and `structlayout-pretty`, and libraries used to implement the tools.

Sicherheitslage

Risikostufe: yellow

generalized runtime or code generation signal.

Risikoklassifikator

yellow Risiko · mittel Konfidenz · runtime

Warum

  • generalized runtime or code generation signal

Signale

  • text:programming language

Installationsverhalten

  • In den Formelmetadaten ist kein Homebrew-Post-install-Hook erfasst.
  • Homebrew-Bottle-Metadaten sind für 6 Plattformziele verfügbar.
  • Installiert mit 1 Laufzeitabhängigkeiten.

Empfohlene Prüfung

Prüfe vor unbeaufsichtigter Agent-Nutzung, ob das Tool Klartext-Credentials liest, Remote-Zustand schreibt, Artefakte veröffentlicht oder Plugins ausführt.

local files

Configuration and credential file locations

These source-backed paths show where this package keeps local settings or durable credentials. Automic Vault can use them as review targets for secret scanning, migration, and command approval.

Configuration files

Config paths the tool may read or write during local use.

Unix
staticcheck.conf
Windows
staticcheck.conf

Executables

Installierte Executables

BefehlArtSichtbarkeitHinweis
staticcheckcliglobales Executable

Aktualität

Version und Aktualität

Diese Signale trennen das Alter der Seitengenerierung, Aktivität des Paketmanagers und Upstream-Release-Vergleich. Versionsrückstand wird nur gemeldet, wenn eine Evidenz-URL und vergleichbare Versionen vorhanden sind.

Seite generiert2026-07-25
Manager-Version2026.1
Manager aktualisiert2026-07-08
lokale DatenOK
Upstreamaktuell
neueste erkannte Version2026.1

https://github.com/dominikh/go-tools

  • OKEs wurden keine Aktualitätswarnungen generiert.

Installationsmetadaten

Paketmetadaten

Paketschlüsselbrew:staticcheck
Version2026.1
PaketmanagerHomebrew
Paketmanager-Seitehttps://formulae.brew.sh/formula/staticcheck
Homepagehttps://staticcheck.dev/
Repositoryhttps://github.com/dominikh/go-tools
Upstream-Dokumentationhttps://staticcheck.dev/docs
LizenzMIT
Quellarchivhttps://github.com/dominikh/go-tools/archive/refs/tags/2026.1.tar.gz
Zuletzt aktualisiert2026-07-08T03:14:15Z
Pulseupdated
Abhängigkeitengo
Bottleverfügbar (auf arm64_linux, arm64_sequoia, arm64_sonoma, arm64_tahoe, sonoma, x86_64_linux)
Homebrew post-installnicht definiert
Dienstkeiner deklariert

Registry-Fakten

Details aus der Quelldatenbank

Source DatabaseHomebrew formula API
Taphomebrew/core
Full Namestaticcheck
Version Scheme0
Revision5
Head VersionHEAD
Bottle Stable Root URLhttps://ghcr.io/v2/homebrew/core
Deprecatedno
Disabledno
Keg Onlyno
URL Keys
  • head
  • stable

Source-Datenbank-Treffer

Andere Paketmanager-Einträge

Treffer stammen aus externen Paketmanager-Indizes und bleiben von lokalen Automic-Vault-Paketlinks getrennt.

apk95%

staticcheck 2026.1-r3

advanced Go linter

https://github.com/dominikh/go-tools

sudo apk add staticcheck
  • License: MIT
  • Architecture: x86_64
  • Source Package: staticcheck
  • 1 Abhängigkeiten
  • 1 stellt bereit
  • normalized package name match
  • Abgeglichen nach: Staticcheck
Alpine Linux edge package indexes · dl-cdn.alpinelinux.org · Alpine Linux edge package indexes: staticcheck from https://dl-cdn.alpinelinux.org/alpine/edge/community/x86_64/APKINDEX.tar.gz
dnf95%

staticcheck 2026.1-1.fc45

The advanced Go linter

https://github.com/dominikh/go-tools

sudo dnf install staticcheck
  • License: BSD-3-Clause AND MIT
  • Category: Unspecified
  • Architecture: x86_64
  • Source Package: staticcheck
  • 3 Abhängigkeiten
  • 2 stellt bereit
  • normalized package name match
  • Abgeglichen nach: Staticcheck
Fedora Rawhide package metadata · dl.fedoraproject.org · Fedora Rawhide package metadata: staticcheck from https://dl.fedoraproject.org/pub/fedora/linux/development/rawhide/Everything/x86_64/os/repodata/e5ca8ce900cd68f5419e1c39ae517343100b306336cbaeb70a3c153121d95094-primary.xml.zst
pacman95%

staticcheck 2026.1-3

The advanced Go linter

https://staticcheck.io

sudo pacman -S staticcheck
  • License: MIT
  • Architecture: x86_64
  • 1 Abhängigkeiten
  • normalized package name match
  • Abgeglichen nach: Staticcheck
Arch Linux sync databases · geo.mirror.pkgbuild.com · Arch Linux sync databases: staticcheck from https://geo.mirror.pkgbuild.com/extra/os/x86_64/extra.db.tar.gz
MacPorts95%

staticcheck

sudo port install staticcheck
  • normalized package name match
  • Abgeglichen nach: Staticcheck
MacPorts ports tree · api.github.com · MacPorts ports tree: devel/staticcheck/Portfile from https://api.github.com/repos/macports/macports-ports/git/trees/master?recursive=1
Scoop95%

main/staticcheck

scoop install main/staticcheck
  • normalized package name match
  • Abgeglichen nach: Staticcheck
Scoop official bucket manifest trees · api.github.com · Scoop official bucket manifest trees: bucket/staticcheck.json from https://api.github.com/repos/ScoopInstaller/Main/git/trees/master?recursive=1

Quellspur

Aus Repository-Daten generiert

Diese Seite wird von av-web aus dem privaten Paket-SQLite-Artefakt bereitgestellt, das scripts/generate-pkg-sqlite.py erstellt.

Verwendete Quellen

  • Geiger risk classifier
  • Nucleus package database
  • av.db category and tag curation
  • cross-ecosystem install command graph
  • curated configuration and credential file locations
  • curated package history
  • external package-manager database matches
  • package relationship graph
  • package version freshness
  • package-page enrichment