pkg.sopackage field notes

brew / 順位 6212

vulture を Homebrew でインストール

vulture のインストール経路、実行ファイル、メタデータ、AI エージェント向けセキュリティノートを確認します。

インストール

追加のインストールコマンド

macOS

Homebrew確認済み · 100%
brew install vulture

provider-native install command

概要

パッケージ概要

Find dead Python code

コマンドとエイリアス

  • vulture

履歴

プロジェクトの歴史と使われ方

Vulture is a Python static-analysis command-line tool for finding unused code. It scans Python files, records defined and used names with the standard-library `ast` module, reports likely unused imports, variables, functions, methods, classes, properties, attributes, and also detects some unreachable code.

プロジェクトの歴史

Vulture has a longer history than its current GitHub repository suggests: PyPI records version 0.1 uploaded on March 17, 2012. The current GitHub repository was created in March 2017 under maintainer Jendrik Seipp, and the package metadata continues to identify him as the author/owner.

The project matured from a small dead-code finder into a production/stable Python quality tool. Its README emphasizes that Python's dynamic nature makes perfect static dead-code detection impossible, so Vulture reports confidence values and provides practical suppression mechanisms rather than pretending to be exact.

The 2.x series made Vulture fit modern Python project workflows: it supports `pyproject.toml` configuration, pre-commit integration, programmatic use, whitelists for false positives, common whitelists in the repository, and output syntax that complements Pyflakes.

採用の歴史

Vulture became a recognizable tool in Python maintenance circles because it addresses a recurring problem in large, long-lived codebases: unused helpers, stale imports, abandoned feature paths, and untested code that ordinary linting or test coverage may not make obvious.

By July 2026, GitHub repository metadata showed more than 4.6k stars, and PyPI listed Vulture 2.16 as the current release, uploaded on March 25, 2026. It also appears in editor and automation workflows through pre-commit hooks, a GitHub Action, and VS Code extension integrations.

使われ方

Typical usage is `vulture path_or_file`, optionally with directories, a generated whitelist, and a confidence threshold such as `--min-confidence 100`. The tool recommends scanning both a library and its test suite so code used only by tests is seen as used, and then rerunning after deletions because removing one chunk can reveal more dead code.

Vulture's confidence model is part of its identity. It treats unreachable code and unused function or method arguments as 100 percent, imports as 90 percent, and many attributes, classes, functions, methods, properties, and variables as 60 percent. Users tune results with whitelists, excludes, ignored names or decorators, `noqa` compatibility for selected Pyflakes codes, and `pyproject.toml` settings.

パッケージ好きにとっての重要性

For package nerds, Vulture is the small sharp tool between linting and coverage. It is simpler than a whole quality platform, depends mostly on Python's parser, and is valuable in cleanup branches, CI gates, and pre-commit checks where the goal is to find deletion candidates before they fossilize.

タイムライン

  • 2012: Vulture 0.1 was uploaded to PyPI on March 17, 2012.
  • 2017: The current GitHub repository was created on March 6, 2017.
  • 2021: Vulture 2.3 appeared as the example pre-commit hook revision in the README's integration documentation.
  • 2026: Vulture 2.16 was uploaded to PyPI on March 25, 2026.

Related projects

  • Vulture is related to Pyflakes, Flake8, Coverage.py, pre-commit, Ruff discussions around dead-code detection, editor extensions that wrap Vulture, and other Python dead-code tools such as uncalled and dead.

セキュリティ状態

リスクレベル: グリーン

narrow executable package without higher-risk signals.

リスク分類器

リスク グリーン · 信頼度 低 · appliance

理由

  • narrow executable package without higher-risk signals

信号

  • metadata:no-higher-risk-signals

インストール挙動

  • Homebrew bottle メタデータは記録されていません。

推奨レビュー

エージェントに無人実行させる前に、このツールが平文の認証情報を読むか、リモート状態を書き込むか、成果物を公開するか、プラグインを起動するかを確認してください。

local files

Configuration and credential file locations

These source-backed paths show where this package keeps local settings or durable credentials. Automic Vault can use them as review targets for secret scanning, migration, and command approval.

Configuration files

Config paths the tool may read or write during local use.

Unix
pyproject.toml

実行可能ファイル

インストールされる実行可能ファイル

コマンド種類公開範囲メモ
vulture実行可能ファイルインデックス済み実行可能ファイルローカル実行可能ファイルインデックスから検出されました。

鮮度

バージョンと鮮度

これらの信号は、ページ生成時期、パッケージマネージャの活動、上流リリース比較を分けて示します。バージョン遅れは、証拠 URL と比較可能なバージョンがある場合だけ警告されます。

ページ生成日2026-08-03
マネージャ版2.16
マネージャ更新日
ローカルデータ不明
上流利用不可
検出された最新未検出
  • OK鮮度警告は生成されていません。

インストールメタデータ

パッケージメタデータ

パッケージキーbrew:vulture
バージョン2.16
パッケージマネージャHomebrew
ホームページhttps://github.com/jendrikseipp/vulture
リポジトリhttps://github.com/jendrikseipp/vulture
Bottle未記録
サービス宣言なし

ソース経路

リポジトリデータから生成

このページは scripts/generate-pkg-sqlite.py が生成した非公開のパッケージ SQLite アーティファクトから av-web によって提供されます。

使用ソース

  • Geiger risk classifier
  • Nucleus package database
  • curated configuration and credential file locations
  • curated package history
  • pkgdb category and tag curation