pkg.soopen package index

brew / 順位 675

sonar-scanner を Homebrew, apk, scoop でインストール

sonar-scanner のインストール経路、実行ファイル、メタデータ、AI エージェント向けセキュリティノートを確認します。

インストール

追加のインストールコマンド

macOS

Homebrew確認済み · 100%
brew install sonar-scanner

local Homebrew formula metadata

Windows

Scoop確認済み · 92%
scoop install main/sonar-scanner

Scoop official bucket manifest trees · bucket/sonar-scanner.json · ソース: api.github.com

概要

パッケージ概要

Launcher to analyze a project with SonarQube

コマンドとエイリアス

  • sonar-scanner

履歴

プロジェクトの歴史と使われ方

SonarScanner CLI is SonarSource's command-line scanner for running SonarQube Server and SonarQube Cloud code analysis when there is no build-system-specific scanner. It is a CI/CD staple because it turns a checked-out source tree plus `sonar-project.properties` into an analysis uploaded to a Sonar service.

プロジェクトの歴史

The public GitHub repository is the official scanner CLI source tree, and its tags include older 2.x releases. Current SonarSource documentation presents a maintained release line from 4.x through 8.x, with the README stating that project configuration is read from `sonar-project.properties` or passed on the command line.

Notable documented release changes include the 4.3 release using the SonarScanner name in logs, the 4.4 release adding a supported Docker image, the 5.0 release embedding Java 17, the 6.0 release adding a new bootstrapping mechanism and JRE provisioning for SonarQube 10.6+ and SonarCloud, and the 8.0.1 release updating embedded JREs to Java 21.

採用の歴史

The scanner is distributed as OS-specific downloads, a Docker image, a generic JVM zip, and package-manager formulae. Homebrew analytics show tens of thousands of yearly installs, which fits its role as a common CI dependency rather than a library used inside application code.

使われ方

Users create `sonar-project.properties` in the project root, run `sonar-scanner`, and provide server/project credentials through scanner parameters, CI secrets, or environment configuration rather than a dedicated credentials file. SonarSource warns users to prefer dedicated Maven, Gradle, or .NET scanners for those build systems.

パッケージ好きにとっての重要性

SonarScanner CLI matters to package maintainers because CI images and developer machines need a reproducible scanner binary with the right Java behavior. Changes such as embedded JRE updates, Docker distribution, and auto-provisioning affect whether a package works in minimal runners, corporate networks, and long-lived build pipelines.

タイムライン

  • 2019: SonarScanner CLI 4.3 documents use of the SonarScanner name in logs.
  • 2020: Version 4.4 adds a supported Docker image.
  • 2023: Version 5.0 updates the embedded JRE to Java 17.
  • 2024: Version 6.0 adds new bootstrapping and JRE provisioning.
  • 2025: Version 7.3 adds z/OS support for scanner execution.
  • 2025: Version 8.0.1 updates embedded JREs to Java 21.

Related projects

  • SonarQube Server and SonarQube Cloud receive the analysis results.
  • Dedicated SonarScanners exist for Maven, Gradle, and .NET and are recommended for those ecosystems.
  • The scanner is also distributed as the official `sonarsource/sonar-scanner-cli` Docker image.

セキュリティ状態

リスクレベル: グリーン

narrow executable package without higher-risk signals.

リスク分類器

リスク グリーン · 信頼度 低 · appliance

理由

  • narrow executable package without higher-risk signals

信号

  • metadata:no-higher-risk-signals

インストール挙動

  • Homebrew bottle メタデータは記録されていません。

推奨レビュー

エージェントに無人実行させる前に、このツールが平文の認証情報を読むか、リモート状態を書き込むか、成果物を公開するか、プラグインを起動するかを確認してください。

local files

Configuration and credential file locations

These source-backed paths show where this package keeps local settings or durable credentials. Automic Vault can use them as review targets for secret scanning, migration, and command approval.

Configuration files

Config paths the tool may read or write during local use.

Unix
sonar-project.properties${scanner.home}/conf/sonar-scanner.properties

実行可能ファイル

インストールされる実行可能ファイル

コマンド種類公開範囲メモ
sonar-scanner実行可能ファイルインデックス済み実行可能ファイルローカル実行可能ファイルインデックスから検出されました。

鮮度

バージョンと鮮度

これらの信号は、ページ生成時期、パッケージマネージャの活動、上流リリース比較を分けて示します。バージョン遅れは、証拠 URL と比較可能なバージョンがある場合だけ警告されます。

ページ生成日2026-08-03
マネージャ版8.1.0.6389
マネージャ更新日
ローカルデータ不明
上流利用不可
検出された最新未検出
  • OK鮮度警告は生成されていません。

インストールメタデータ

パッケージメタデータ

パッケージキーbrew:sonar-scanner
バージョン8.1.0.6389
パッケージマネージャHomebrew
ホームページhttps://docs.sonarqube.org/latest/analysis/scan/sonarscanner/
リポジトリhttps://github.com/SonarSource/sonar-scanner-cli
Bottle未記録
サービス宣言なし

ソースデータベース一致

他のパッケージマネージャ記録

一致は外部パッケージマネージャインデックスから取得され、ローカルの Automic Vault パッケージリンクとは分けて表示されます。

apk95%

sonar-scanner 8.1.0.6389-r0

Scanner CLI for SonarQube and SonarCloud

https://github.com/SonarSource/sonar-scanner-cli

sudo apk add sonar-scanner
  • License: LGPL-3.0-or-later
  • Architecture: x86_64
  • Source Package: sonar-scanner
  • 1 依存関係
  • 1 提供
  • normalized package name match
  • 一致条件: Sonar Scanner
Alpine Linux edge package indexes · dl-cdn.alpinelinux.org · Alpine Linux edge package indexes: sonar-scanner from https://dl-cdn.alpinelinux.org/alpine/edge/community/x86_64/APKINDEX.tar.gz
Scoop95%

main/sonar-scanner

scoop install main/sonar-scanner
  • normalized package name match
  • 一致条件: Sonar Scanner
Scoop official bucket manifest trees · api.github.com · Scoop official bucket manifest trees: bucket/sonar-scanner.json from https://api.github.com/repos/ScoopInstaller/Main/git/trees/master?recursive=1

ソース経路

リポジトリデータから生成

このページは scripts/generate-pkg-sqlite.py が生成した非公開のパッケージ SQLite アーティファクトから av-web によって提供されます。

使用ソース

  • Geiger risk classifier
  • cross-ecosystem install command graph
  • curated configuration and credential file locations
  • curated package history
  • external package-manager database matches
  • pkg.so package database
  • pkgdb category and tag curation