Automic VaultAutomic Vault

brew

Install rats with Homebrew, dnf, MacPorts

Rough auditing tool for security. Version 2.4 via Homebrew; verified from local package data. Also installable with dnf: sudo dnf install rats.

install

Additional install commands

macOS

Homebrewverified · 100%
brew install rats

local Homebrew formula metadata

MacPortsverified · 94%
sudo port install rats

MacPorts ports tree · security/rats/Portfile · source: api.github.com

overview

Package summary

Rough auditing tool for security

Commands and aliases

  • rats

history

Project history and usage

RATS, the Rough Auditing Tool for Security, is a command-line static analysis scanner for finding common security-sensitive programming patterns in source code.

Project history

The official README says RATS was developed, maintained, and distributed by Secure Software, Inc. The 2.4 source archive describes it as a scanner for C, C++, Perl, PHP, Python, and Ruby source that flags issues such as buffer overflows and TOCTOU race conditions.

Adoption history

RATS circulated as a small Unix security-auditing utility through source archives and package managers. Homebrew, Debian-derived manpage packaging, Fedora, MacPorts, and other Unix package collections carried it as a lightweight source-code auditing tool.

How it is used

Users run rats against files or directories and can select vulnerability databases with -d, force a language with -l, choose warning levels, recurse through directories, and emit text, XML, or HTML reports.

Why package nerds care

Package maintainers care about RATS because it is an old-style security CLI: small C code, autoconf build, XML vulnerability databases, and a package surface that exposes static-analysis behavior without a large framework.

Timeline

  • 2001: The bundled manpage date records RATS documentation in September 2001.
  • 2.4: Homebrew packages the Google Code archive release as the stable version.

Related projects

  • The README notes Expat as a build/runtime requirement and credits Ben Laurie for OpenSSL-specific database contributions.

Sources

  • Google Code Archive: official rough-auditing-tool-for-security project and source download.
  • Homebrew formula metadata for rats stable 2.4.
  • RATS 2.4 README and rats.1 from the official Google Code archive tarball.

security posture

Risk level: green

narrow executable package without higher-risk signals.

Risk classifier

green risk · low confidence · appliance

Why

  • narrow executable package without higher-risk signals

Signals

  • metadata:no-higher-risk-signals

Install behavior

  • No Homebrew post-install hook is recorded in formula metadata.
  • Homebrew bottle metadata is available for 13 platform targets.

Recommended review

Before unattended agent use, check whether the tool reads plaintext credentials, writes remote state, publishes artifacts, or shells out to plugins.

executables

Installed executables

CommandKindExposureNote
ratscliglobal executable

freshness

Version and freshness

These signals separate page generation age, package-manager activity, and upstream release comparison. Version lag is warned only when an evidence URL and comparable versions are present.

page generated2026-07-25
manager version2.4
manager updated
local dataok
upstreamnot checked
latest detectednot detected

https://security.web.cern.ch/security/recommendations/en/codetools/rats.shtml

install metadata

Package metadata

Package keybrew:rats
Version2.4
Package managerHomebrew
Package manager pagehttps://formulae.brew.sh/formula/rats
Homepagehttps://security.web.cern.ch/security/recommendations/en/codetools/rats.shtml
Repositoryhttps://code.google.com/archive/p/rough-auditing-tool-for-security/source/default/source
Upstream docshttps://security.web.cern.ch/security/recommendations/en/codetools/rats.shtml
LicenseGPL-2.0-or-later
Source archivehttps://storage.googleapis.com/google-code-archive-downloads/v2/code.google.com/rough-auditing-tool-for-security/rats-2.4.tgz
Uses from macOSexpat
Bottleavailable (on arm64_big_sur, arm64_linux, arm64_monterey, arm64_sequoia, arm64_sonoma, arm64_tahoe, arm64_ventura, big_sur, catalina, monterey, sonoma, ventura, x86_64_linux)
Homebrew post-installnot defined
Servicenone declared

registry facts

Source database details

Source DatabaseHomebrew formula API
Taphomebrew/core
Full Namerats
Version Scheme0
Revision0
Bottle Stable Root URLhttps://ghcr.io/v2/homebrew/core
Deprecatedno
Disabledno
Keg Onlyno
URL Keys
  • stable

source database matches

Other package-manager records

Matches are pulled from external package-manager indexes and kept separate from local Automic Vault package links.

dnf95%

rats 2.4-31.fc44

Rough Auditing Tool for Security

https://code.google.com/p/rough-auditing-tool-for-security/

sudo dnf install rats
  • License: GPL-2.0-only
  • Category: Unspecified
  • Architecture: x86_64
  • Source Package: rats
  • 3 dependencies
  • 1 provides
  • normalized package name match
  • Matched by: Rats
Fedora Rawhide package metadata · dl.fedoraproject.org · Fedora Rawhide package metadata: rats from https://dl.fedoraproject.org/pub/fedora/linux/development/rawhide/Everything/x86_64/os/repodata/e5ca8ce900cd68f5419e1c39ae517343100b306336cbaeb70a3c153121d95094-primary.xml.zst
MacPorts95%

rats

sudo port install rats
  • normalized package name match
  • Matched by: Rats
MacPorts ports tree · api.github.com · MacPorts ports tree: security/rats/Portfile from https://api.github.com/repos/macports/macports-ports/git/trees/master?recursive=1

source trail

Generated from repository data

This page is generated by av-web from the private package SQLite artifact built by scripts/generate-pkg-sqlite.py.

Used sources

  • Geiger risk classifier
  • Nucleus package database
  • av.db category and tag curation
  • cross-ecosystem install command graph
  • curated package history
  • external package-manager database matches
  • package relationship graph
  • package version freshness
  • package-page enrichment