pkg.soopen package index

brew / rang 675

Installer sonar-scanner avec Homebrew, apk, scoop

Consultez les chemins d'installation, exécutables, métadonnées et notes de sécurité de sonar-scanner pour les workflows d'agents IA.

installation

Commandes d'installation supplémentaires

macOS

Homebrewvérifié · 100%
brew install sonar-scanner

local Homebrew formula metadata

Linux

Alpine Linux apkvérifié · 92%
sudo apk add sonar-scanner

Alpine Linux edge package indexes · sonar-scanner · Source: dl-cdn.alpinelinux.org

Windows

Scoopvérifié · 92%
scoop install main/sonar-scanner

Scoop official bucket manifest trees · bucket/sonar-scanner.json · Source: api.github.com

aperçu

Résumé du paquet

Launcher to analyze a project with SonarQube

Commandes et alias

  • sonar-scanner

historique

Historique du projet et usages

SonarScanner CLI is SonarSource's command-line scanner for running SonarQube Server and SonarQube Cloud code analysis when there is no build-system-specific scanner. It is a CI/CD staple because it turns a checked-out source tree plus `sonar-project.properties` into an analysis uploaded to a Sonar service.

Historique du projet

The public GitHub repository is the official scanner CLI source tree, and its tags include older 2.x releases. Current SonarSource documentation presents a maintained release line from 4.x through 8.x, with the README stating that project configuration is read from `sonar-project.properties` or passed on the command line.

Notable documented release changes include the 4.3 release using the SonarScanner name in logs, the 4.4 release adding a supported Docker image, the 5.0 release embedding Java 17, the 6.0 release adding a new bootstrapping mechanism and JRE provisioning for SonarQube 10.6+ and SonarCloud, and the 8.0.1 release updating embedded JREs to Java 21.

Historique d'adoption

The scanner is distributed as OS-specific downloads, a Docker image, a generic JVM zip, and package-manager formulae. Homebrew analytics show tens of thousands of yearly installs, which fits its role as a common CI dependency rather than a library used inside application code.

Modes d'utilisation

Users create `sonar-project.properties` in the project root, run `sonar-scanner`, and provide server/project credentials through scanner parameters, CI secrets, or environment configuration rather than a dedicated credentials file. SonarSource warns users to prefer dedicated Maven, Gradle, or .NET scanners for those build systems.

Pourquoi les passionnés de paquets s'y intéressent

SonarScanner CLI matters to package maintainers because CI images and developer machines need a reproducible scanner binary with the right Java behavior. Changes such as embedded JRE updates, Docker distribution, and auto-provisioning affect whether a package works in minimal runners, corporate networks, and long-lived build pipelines.

Chronologie

  • 2019: SonarScanner CLI 4.3 documents use of the SonarScanner name in logs.
  • 2020: Version 4.4 adds a supported Docker image.
  • 2023: Version 5.0 updates the embedded JRE to Java 17.
  • 2024: Version 6.0 adds new bootstrapping and JRE provisioning.
  • 2025: Version 7.3 adds z/OS support for scanner execution.
  • 2025: Version 8.0.1 updates embedded JREs to Java 21.

Related projects

  • SonarQube Server and SonarQube Cloud receive the analysis results.
  • Dedicated SonarScanners exist for Maven, Gradle, and .NET and are recommended for those ecosystems.
  • The scanner is also distributed as the official `sonarsource/sonar-scanner-cli` Docker image.

posture de sécurité

Niveau de risque : vert

narrow executable package without higher-risk signals.

Classificateur de risque

risque vert · confiance faible · appliance

Pourquoi

  • narrow executable package without higher-risk signals

Signaux

  • metadata:no-higher-risk-signals

Comportement d'installation

  • Aucune métadonnée de bottle Homebrew n’a été enregistrée.

Revue recommandée

Avant une utilisation sans surveillance par un agent, vérifiez si l'outil lit des identifiants en clair, écrit un état distant, publie des artefacts ou lance des plugins.

local files

Configuration and credential file locations

These source-backed paths show where this package keeps local settings or durable credentials. Automic Vault can use them as review targets for secret scanning, migration, and command approval.

Configuration files

Config paths the tool may read or write during local use.

Unix
sonar-project.properties${scanner.home}/conf/sonar-scanner.properties

exécutables

Exécutables installés

CommandeTypeExpositionNote
sonar-scannerexécutableexécutable indexéDécouvert depuis l'index local des exécutables.

fraîcheur

Version et fraîcheur

Ces signaux séparent l'âge de génération de la page, l'activité du gestionnaire de paquets et la comparaison avec les versions amont. Un retard de version n'est signalé que lorsqu'une URL de preuve et des versions comparables sont présentes.

page générée2026-08-03
version du gestionnaire8.1.0.6389
gestionnaire mis à jour
données localesinconnu
amontnon disponible
dernière version détectéenon détecté
  • OKAucun avertissement de fraîcheur n'a été généré.

métadonnées d'installation

Métadonnées du paquet

Clé du paquetbrew:sonar-scanner
Version8.1.0.6389
Gestionnaire de paquetsHomebrew
Page d'accueilhttps://docs.sonarqube.org/latest/analysis/scan/sonarscanner/
Dépôthttps://github.com/SonarSource/sonar-scanner-cli
Bouteillenon enregistré
Serviceaucun déclaré

correspondances dans les bases sources

Autres enregistrements de gestionnaires de paquets

Les correspondances proviennent d’index externes de gestionnaires de paquets et restent séparées des liens de paquets Automic Vault locaux.

apk95%

sonar-scanner 8.1.0.6389-r0

Scanner CLI for SonarQube and SonarCloud

https://github.com/SonarSource/sonar-scanner-cli

sudo apk add sonar-scanner
  • License: LGPL-3.0-or-later
  • Architecture: x86_64
  • Source Package: sonar-scanner
  • 1 Dépendances
  • 1 fournit
  • normalized package name match
  • Correspondance par : Sonar Scanner
Alpine Linux edge package indexes · dl-cdn.alpinelinux.org · Alpine Linux edge package indexes: sonar-scanner from https://dl-cdn.alpinelinux.org/alpine/edge/community/x86_64/APKINDEX.tar.gz
Scoop95%

main/sonar-scanner

scoop install main/sonar-scanner
  • normalized package name match
  • Correspondance par : Sonar Scanner
Scoop official bucket manifest trees · api.github.com · Scoop official bucket manifest trees: bucket/sonar-scanner.json from https://api.github.com/repos/ScoopInstaller/Main/git/trees/master?recursive=1

piste source

Généré depuis les données du dépôt

Cette page est servie par av-web depuis l'artéfact SQLite privé des paquets généré par scripts/generate-pkg-sqlite.py.

Sources utilisées

  • Geiger risk classifier
  • cross-ecosystem install command graph
  • curated configuration and credential file locations
  • curated package history
  • external package-manager database matches
  • pkg.so package database
  • pkgdb category and tag curation