Automic VaultAutomic Vault

brew

staticcheck を Homebrew, apk, dnf, MacPorts, pacman, scoop でインストール

staticcheck のインストール経路、実行ファイル、メタデータ、AI エージェント向けセキュリティノートを確認します。

インストール

追加のインストールコマンド

macOS

Homebrew確認済み · 100%
brew install staticcheck

local Homebrew formula metadata

MacPorts確認済み · 94%
sudo port install staticcheck

MacPorts ports tree · devel/staticcheck/Portfile · ソース: api.github.com

Windows

Scoop確認済み · 92%
scoop install main/staticcheck

Scoop official bucket manifest trees · bucket/staticcheck.json · ソース: api.github.com

概要

パッケージ概要

State of the art linter for the Go programming language

コマンドとエイリアス

  • staticcheck

履歴

プロジェクトの歴史と使われ方

Staticcheck is a Go static-analysis command-line tool and one of the best-known third-party linters in the Go ecosystem. It is packaged as the `staticcheck` executable and is commonly installed with Go tooling or system package managers for local development and CI.

プロジェクトの歴史

The upstream project lives in Dominik Honnef's `go-tools` repository, which was created in January 2017. The official README describes Staticcheck as an advanced Go linter that finds bugs and performance issues, offers simplifications, and enforces style rules.

Staticcheck publishes release notes on staticcheck.dev. The release-note index records releases from 2017.2 through the 2026 series, showing a long-running tool with versioned compatibility work alongside Go's release cadence.

採用の歴史

The input package metadata lists Staticcheck in Homebrew, Alpine, Fedora, MacPorts, Arch, and Scoop. The official documentation also recommends installing released versions with `go install honnef.co/go/tools/cmd/staticcheck@latest` on modern Go versions or using prebuilt binaries from GitHub releases.

Staticcheck's package-manager footprint reflects its role as a standard quality gate for Go projects. It is useful as a standalone CLI, as a CI check, and as a linter that complements the Go compiler and `go vet`.

使われ方

Typical usage is to run `staticcheck` against Go packages or wire it into CI. The tool can analyze code targeting Go versions up to the latest release, while the project recommends using tagged releases instead of master for stable builds.

パッケージ好きにとっての重要性

Package nerds care about Staticcheck because it is a canonical example of a language ecosystem tool that lives outside the core toolchain but is widely treated as infrastructure. Its version tags, prebuilt binaries, and `go install` path make it straightforward to pin in reproducible builds.

For package managers, Staticcheck is high-value despite being a single executable: it is heavily used by Go developers, has stable release notes, and represents the broader `honnef.co/go/tools` analyzer collection.

タイムライン

  • 2017: `dominikh/go-tools` repository created.
  • 2017: Staticcheck 2017.2 release published.
  • 2019: Staticcheck 2019.2 release notes described major performance and memory improvements.
  • 2026: Staticcheck 2026.1 and 2026.2 release candidates appeared in official releases.

Related projects

  • The same repository contains related tools such as `structlayout`, `structlayout-optimize`, and `structlayout-pretty`, and libraries used to implement the tools.

セキュリティ状態

リスクレベル: yellow

generalized runtime or code generation signal.

リスク分類器

リスク yellow · 信頼度 中 · runtime

理由

  • generalized runtime or code generation signal

信号

  • text:programming language

インストール挙動

  • formula メタデータに Homebrew post-install フックは記録されていません。
  • Homebrew bottle メタデータは 6 個のプラットフォームターゲットで利用できます。
  • 1 件の実行時依存関係とともにインストールされます。

推奨レビュー

エージェントに無人実行させる前に、このツールが平文の認証情報を読むか、リモート状態を書き込むか、成果物を公開するか、プラグインを起動するかを確認してください。

local files

Configuration and credential file locations

These source-backed paths show where this package keeps local settings or durable credentials. Automic Vault can use them as review targets for secret scanning, migration, and command approval.

Configuration files

Config paths the tool may read or write during local use.

Unix
staticcheck.conf
Windows
staticcheck.conf

実行可能ファイル

インストールされる実行可能ファイル

コマンド種類公開範囲メモ
staticcheckcliグローバル実行可能ファイル

鮮度

バージョンと鮮度

これらの信号は、ページ生成時期、パッケージマネージャの活動、上流リリース比較を分けて示します。バージョン遅れは、証拠 URL と比較可能なバージョンがある場合だけ警告されます。

ページ生成日2026-07-25
マネージャ版2026.1
マネージャ更新日2026-07-08
ローカルデータOK
上流最新
検出された最新2026.1

https://github.com/dominikh/go-tools

  • OK鮮度警告は生成されていません。

インストールメタデータ

パッケージメタデータ

パッケージキーbrew:staticcheck
バージョン2026.1
パッケージマネージャHomebrew
パッケージマネージャページhttps://formulae.brew.sh/formula/staticcheck
ホームページhttps://staticcheck.dev/
リポジトリhttps://github.com/dominikh/go-tools
上流ドキュメントhttps://staticcheck.dev/docs
ライセンスMIT
ソースアーカイブhttps://github.com/dominikh/go-tools/archive/refs/tags/2026.1.tar.gz
最終更新2026-07-08T03:14:15Z
Pulseupdated
依存関係go
Bottle利用可能 (対象 arm64_linux, arm64_sequoia, arm64_sonoma, arm64_tahoe, sonoma, x86_64_linux)
Homebrew post-install未定義
サービス宣言なし

レジストリ情報

ソースデータベース詳細

Source DatabaseHomebrew formula API
Taphomebrew/core
Full Namestaticcheck
Version Scheme0
Revision5
Head VersionHEAD
Bottle Stable Root URLhttps://ghcr.io/v2/homebrew/core
Deprecatedno
Disabledno
Keg Onlyno
URL Keys
  • head
  • stable

ソースデータベース一致

他のパッケージマネージャ記録

一致は外部パッケージマネージャインデックスから取得され、ローカルの Automic Vault パッケージリンクとは分けて表示されます。

apk95%

staticcheck 2026.1-r3

advanced Go linter

https://github.com/dominikh/go-tools

sudo apk add staticcheck
  • License: MIT
  • Architecture: x86_64
  • Source Package: staticcheck
  • 1 依存関係
  • 1 提供
  • normalized package name match
  • 一致条件: Staticcheck
Alpine Linux edge package indexes · dl-cdn.alpinelinux.org · Alpine Linux edge package indexes: staticcheck from https://dl-cdn.alpinelinux.org/alpine/edge/community/x86_64/APKINDEX.tar.gz
dnf95%

staticcheck 2026.1-1.fc45

The advanced Go linter

https://github.com/dominikh/go-tools

sudo dnf install staticcheck
  • License: BSD-3-Clause AND MIT
  • Category: Unspecified
  • Architecture: x86_64
  • Source Package: staticcheck
  • 3 依存関係
  • 2 提供
  • normalized package name match
  • 一致条件: Staticcheck
Fedora Rawhide package metadata · dl.fedoraproject.org · Fedora Rawhide package metadata: staticcheck from https://dl.fedoraproject.org/pub/fedora/linux/development/rawhide/Everything/x86_64/os/repodata/e5ca8ce900cd68f5419e1c39ae517343100b306336cbaeb70a3c153121d95094-primary.xml.zst
pacman95%

staticcheck 2026.1-3

The advanced Go linter

https://staticcheck.io

sudo pacman -S staticcheck
  • License: MIT
  • Architecture: x86_64
  • 1 依存関係
  • normalized package name match
  • 一致条件: Staticcheck
Arch Linux sync databases · geo.mirror.pkgbuild.com · Arch Linux sync databases: staticcheck from https://geo.mirror.pkgbuild.com/extra/os/x86_64/extra.db.tar.gz
MacPorts95%

staticcheck

sudo port install staticcheck
  • normalized package name match
  • 一致条件: Staticcheck
MacPorts ports tree · api.github.com · MacPorts ports tree: devel/staticcheck/Portfile from https://api.github.com/repos/macports/macports-ports/git/trees/master?recursive=1
Scoop95%

main/staticcheck

scoop install main/staticcheck
  • normalized package name match
  • 一致条件: Staticcheck
Scoop official bucket manifest trees · api.github.com · Scoop official bucket manifest trees: bucket/staticcheck.json from https://api.github.com/repos/ScoopInstaller/Main/git/trees/master?recursive=1

ソース経路

リポジトリデータから生成

このページは scripts/generate-pkg-sqlite.py が生成した非公開のパッケージ SQLite アーティファクトから av-web によって提供されます。

使用ソース

  • Geiger risk classifier
  • Nucleus package database
  • av.db category and tag curation
  • cross-ecosystem install command graph
  • curated configuration and credential file locations
  • curated package history
  • external package-manager database matches
  • package relationship graph
  • package version freshness
  • package-page enrichment