pkg.soopen package index

brew / rank 3867

Install joern with Homebrew

Open-source code analysis platform based on code property graphs. Version 4.0.590 via Homebrew; verified 2026-07-28.

install

Additional install commands

macOS

Homebrewverified · 100%
brew install joern

local Homebrew formula metadata

overview

Package summary

Open-source code analysis platform based on code property graphs

Commands and aliases

  • abap2cpg
  • c2cpg.sh
  • csharpsrc2cpg
  • ghidra2cpg
  • gosrc2cpg
  • javasrc2cpg
  • jimple2cpg
  • joern
  • joern-cpg2scpg
  • joern-export
  • joern-flow
  • joern-parse
  • joern-scan
  • joern-slice
  • joern-vectors
  • jssrc2cpg.sh
  • kotlin2cpg
  • php2cpg
  • pysrc2cpg
  • rubysrc2cpg
  • rust2cpg
  • schema-extender.sh
  • swiftsrc2cpg.sh

history

Project history and usage

Joern is an open-source code analysis platform built around code property graphs, a graph representation that lets security researchers query syntax, control flow, and data flow through a Scala-based domain-specific language. Its Homebrew formula packages a large CLI surface, including language frontends and helper commands for parsing, scanning, slicing, exporting, and vectorizing code.

Project history

The code property graph idea was introduced in vulnerability-research work on C system code and the Linux kernel. Joern grew from that research lineage into a practical tool for creating and querying CPGs, with later research from 2014 to 2016 extending the representation and 2017 onward work at ShiftLeft turning the format into a broader static-analysis foundation.

The public joernio/joern repository was created in 2019 and the project documentation records several architectural shifts: older Joern versions used general-purpose graph databases and Gremlin, later versions moved to OverflowDB, Joern v2 changed the implementation line from Scala 2 to Scala 3, and Joern v4 moved from OverflowDB to flatgraph.

Adoption history

Joern's adoption is strongest in security research and static-analysis workflows where importing incomplete or build-hostile code is valuable. The documentation lists mature or partially mature frontends for C/C++, Java, JavaScript, Python, binary analysis through Ghidra, JVM bytecode, Kotlin, PHP, Go, Ruby, Swift, and C#.

Homebrew distribution makes Joern convenient on macOS and Linux while preserving its JVM/Scala toolchain shape through OpenJDK and sbt-related packaging.

How it is used

A typical Joern workflow parses source, bytecode, or binaries into a CPG, stores the graph in Joern's graph database, and then uses CPGQL or bundled commands such as joern-scan, joern-slice, and joern-export to inspect code patterns and vulnerability-relevant flows.

Why package nerds care

Joern matters to package nerds because it turns a research-heavy static-analysis stack into a single installable CLI formula with many frontends. It also shows the unusual packaging profile of modern security tooling: JVM runtime, Scala build tooling, external parsers, and a fast-moving release stream tied to graph storage changes.

Timeline

  • 2014: Code property graphs were introduced for vulnerability discovery in C system code.
  • 2014-2016: Research extended the CPG concept for interprocedural analysis, data-flow learning, dominator-tree integration, and dynamic-language analysis.
  • 2017: The CPG became a foundation for static-analysis products at ShiftLeft.
  • 2019: The joernio/joern GitHub repository was created.
  • 2023: Joern v2 marked the Scala 2 to Scala 3 transition.
  • 2026: Joern v4 documented the move from OverflowDB to flatgraph.

Related projects

  • Related projects and concepts include the Code Property Graph specification, Ocular and Qwiet AI, OverflowDB, flatgraph, Ghidra frontends, and the older Gremlin/property-graph ecosystem that influenced early Joern storage and querying.

security posture

No protected-tool coverage found yet

No matching local secret-handling manifest was found for joern. Nucleus package metadata is still published here so future coverage has a stable package URL.

Install behavior

  • No Homebrew bottle metadata was recorded.

Recommended review

Before unattended agent use, check whether the tool reads plaintext credentials, writes remote state, publishes artifacts, or shells out to plugins.

executables

Installed executables

CommandKindExposureNote
abap2cpgexecutableindexed executableDiscovered from the local executable index.
c2cpg.shexecutableindexed executableDiscovered from the local executable index.
csharpsrc2cpgexecutableindexed executableDiscovered from the local executable index.
ghidra2cpgexecutableindexed executableDiscovered from the local executable index.
gosrc2cpgexecutableindexed executableDiscovered from the local executable index.
javasrc2cpgexecutableindexed executableDiscovered from the local executable index.
jimple2cpgexecutableindexed executableDiscovered from the local executable index.
joernexecutableindexed executableDiscovered from the local executable index.
joern-cpg2scpgexecutableindexed executableDiscovered from the local executable index.
joern-exportexecutableindexed executableDiscovered from the local executable index.
joern-flowexecutableindexed executableDiscovered from the local executable index.
joern-parseexecutableindexed executableDiscovered from the local executable index.
joern-scanexecutableindexed executableDiscovered from the local executable index.
joern-sliceexecutableindexed executableDiscovered from the local executable index.
joern-vectorsexecutableindexed executableDiscovered from the local executable index.
jssrc2cpg.shexecutableindexed executableDiscovered from the local executable index.
kotlin2cpgexecutableindexed executableDiscovered from the local executable index.
php2cpgexecutableindexed executableDiscovered from the local executable index.
pysrc2cpgexecutableindexed executableDiscovered from the local executable index.
rubysrc2cpgexecutableindexed executableDiscovered from the local executable index.
rust2cpgexecutableindexed executableDiscovered from the local executable index.
schema-extender.shexecutableindexed executableDiscovered from the local executable index.
swiftsrc2cpg.shexecutableindexed executableDiscovered from the local executable index.

freshness

Version and freshness

These signals separate page generation age, package-manager activity, and upstream release comparison. Version lag is warned only when an evidence URL and comparable versions are present.

page generated2026-08-03
manager version4.0.590
manager updated2026-07-28
local dataunknown
upstreamnot available
latest detectednot detected
  • okNo freshness warnings were generated.

install metadata

Package metadata

Package keybrew:joern
Version4.0.590
Package managerHomebrew
Homepagehttps://joern.io/
Repositoryhttps://github.com/joernio/joern
Last updated2026-07-28T10:31:06Z
Pulseupdated
Bottlenot recorded
Servicenone declared

source trail

Generated from repository data

This page is generated by av-web from the private package SQLite artifact built by scripts/generate-pkg-sqlite.py.

Used sources

  • Geiger risk classifier
  • cross-ecosystem install command graph
  • curated package history
  • pkg.so package database
  • pkgdb category and tag curation