pkg.soopen package index

brew / rank 6082

Install datadog-static-analyzer with Homebrew

Static analysis tool for code quality and security. Version 0.9.0 via Homebrew; verified 2026-07-24.

install

Additional install commands

macOS

Homebrewverified · 100%
brew install datadog-static-analyzer

local Homebrew formula metadata

overview

Package summary

Static analysis tool for code quality and security

Commands and aliases

  • datadog-static-analyzer
  • datadog-static-analyzer-git-hook

history

Project history and usage

Datadog Static Analyzer is the command-line static analysis engine for Datadog Static Code Analysis.

Project history

The public Datadog repository was created in July 2023 and published an initial 0.0.1 release that same month. Its README positions the analyzer as the engine behind Datadog's SAST product and documents direct CLI, Docker, CI/CD, and IDE usage.

Adoption history

Adoption follows Datadog's Code Security product rather than a standalone community plugin model: the official docs describe scans in CI/CD pipelines or hosted scanning, pull-request feedback, IDE integrations, and Datadog result views.

How it is used

Users run `datadog-static-analyzer` against a directory and emit CSV or SARIF-style reports, optionally selecting rules through a `code-security.datadog.yaml` file at the repository root.

Why package nerds care

For package managers, the analyzer is notable because it packages a vendor SAST engine as a local binary that can run outside the Datadog UI while still feeding Datadog-oriented code-security workflows.

Timeline

  • 2023: Public repository created and 0.0.1 initial release published.
  • 2026: 0.8.x releases show continuing binary distribution through GitHub releases.

Related projects

  • Official integrations include a GitHub Action, a CircleCI orb, Datadog IDE plugins, and the broader Datadog Code Security product.

security posture

Risk level: green

narrow executable package without higher-risk signals.

Risk classifier

green risk · low confidence · appliance

Why

  • narrow executable package without higher-risk signals

Signals

  • metadata:no-higher-risk-signals

Install behavior

  • No Homebrew bottle metadata was recorded.

Recommended review

Before unattended agent use, check whether the tool reads plaintext credentials, writes remote state, publishes artifacts, or shells out to plugins.

local files

Configuration and credential file locations

These source-backed paths show where this package keeps local settings or durable credentials. Automic Vault can use them as review targets for secret scanning, migration, and command approval.

Configuration files

Config paths the tool may read or write during local use.

Unix
code-security.datadog.yamlstatic-analysis.datadog.yml

executables

Installed executables

CommandKindExposureNote
datadog-static-analyzerexecutableindexed executableDiscovered from the local executable index.
datadog-static-analyzer-git-hookexecutableindexed executableDiscovered from the local executable index.

freshness

Version and freshness

These signals separate page generation age, package-manager activity, and upstream release comparison. Version lag is warned only when an evidence URL and comparable versions are present.

page generated2026-08-03
manager version0.9.0
manager updated2026-07-24
local dataunknown
upstreamnot available
latest detectednot detected
  • okNo freshness warnings were generated.

install metadata

Package metadata

Package keybrew:datadog-static-analyzer
Version0.9.0
Package managerHomebrew
Homepagehttps://docs.datadoghq.com/security/code_security/static_analysis/
Repositoryhttps://github.com/DataDog/datadog-static-analyzer
Last updated2026-07-24T15:06:54Z
Pulseupdated
Bottlenot recorded
Servicenone declared

source trail

Generated from repository data

This page is generated by av-web from the private package SQLite artifact built by scripts/generate-pkg-sqlite.py.

Used sources

  • Geiger risk classifier
  • cross-ecosystem install command graph
  • curated configuration and credential file locations
  • curated package history
  • pkg.so package database
  • pkgdb category and tag curation