macOS
brew install sonar-scannerlocal Homebrew formula metadata
brew / rang 675
Consultez les chemins d'installation, exécutables, métadonnées et notes de sécurité de sonar-scanner pour les workflows d'agents IA.
installation
brew install sonar-scannerlocal Homebrew formula metadata
sudo apk add sonar-scannerAlpine Linux edge package indexes · sonar-scanner · Source: dl-cdn.alpinelinux.org
scoop install main/sonar-scannerScoop official bucket manifest trees · bucket/sonar-scanner.json · Source: api.github.com
aperçu
Launcher to analyze a project with SonarQube
historique
SonarScanner CLI is SonarSource's command-line scanner for running SonarQube Server and SonarQube Cloud code analysis when there is no build-system-specific scanner. It is a CI/CD staple because it turns a checked-out source tree plus `sonar-project.properties` into an analysis uploaded to a Sonar service.
The public GitHub repository is the official scanner CLI source tree, and its tags include older 2.x releases. Current SonarSource documentation presents a maintained release line from 4.x through 8.x, with the README stating that project configuration is read from `sonar-project.properties` or passed on the command line.
Notable documented release changes include the 4.3 release using the SonarScanner name in logs, the 4.4 release adding a supported Docker image, the 5.0 release embedding Java 17, the 6.0 release adding a new bootstrapping mechanism and JRE provisioning for SonarQube 10.6+ and SonarCloud, and the 8.0.1 release updating embedded JREs to Java 21.
The scanner is distributed as OS-specific downloads, a Docker image, a generic JVM zip, and package-manager formulae. Homebrew analytics show tens of thousands of yearly installs, which fits its role as a common CI dependency rather than a library used inside application code.
Users create `sonar-project.properties` in the project root, run `sonar-scanner`, and provide server/project credentials through scanner parameters, CI secrets, or environment configuration rather than a dedicated credentials file. SonarSource warns users to prefer dedicated Maven, Gradle, or .NET scanners for those build systems.
SonarScanner CLI matters to package maintainers because CI images and developer machines need a reproducible scanner binary with the right Java behavior. Changes such as embedded JRE updates, Docker distribution, and auto-provisioning affect whether a package works in minimal runners, corporate networks, and long-lived build pipelines.
posture de sécurité
narrow executable package without higher-risk signals.
risque vert · confiance faible · appliance
Avant une utilisation sans surveillance par un agent, vérifiez si l'outil lit des identifiants en clair, écrit un état distant, publie des artefacts ou lance des plugins.
local files
These source-backed paths show where this package keeps local settings or durable credentials. Automic Vault can use them as review targets for secret scanning, migration, and command approval.
Config paths the tool may read or write during local use.
sonar-project.properties${scanner.home}/conf/sonar-scanner.propertiesexécutables
| Commande | Type | Exposition | Note |
|---|---|---|---|
sonar-scanner | exécutable | exécutable indexé | Découvert depuis l'index local des exécutables. |
fraîcheur
Ces signaux séparent l'âge de génération de la page, l'activité du gestionnaire de paquets et la comparaison avec les versions amont. Un retard de version n'est signalé que lorsqu'une URL de preuve et des versions comparables sont présentes.
métadonnées d'installation
| Clé du paquet | brew:sonar-scanner |
|---|---|
| Version | 8.1.0.6389 |
| Gestionnaire de paquets | Homebrew |
| Page d'accueil | https://docs.sonarqube.org/latest/analysis/scan/sonarscanner/ |
| Dépôt | https://github.com/SonarSource/sonar-scanner-cli |
| Bouteille | non enregistré |
| Service | aucun déclaré |
correspondances dans les bases sources
Les correspondances proviennent d’index externes de gestionnaires de paquets et restent séparées des liens de paquets Automic Vault locaux.
sonar-scanner 8.1.0.6389-r0
Scanner CLI for SonarQube and SonarCloud
https://github.com/SonarSource/sonar-scanner-cli
sudo apk add sonar-scannermain/sonar-scanner
scoop install main/sonar-scannerpiste source
Cette page est servie par av-web depuis l'artéfact SQLite privé des paquets généré par scripts/generate-pkg-sqlite.py.
View the package source record on GitHub.