pkg.soopen package index

brew / rank 11399

Install rats with Homebrew, dnf, MacPorts

Rough auditing tool for security. Version 2.4 via Homebrew; verified from local package data. Also installable with dnf: sudo dnf install rats.

install

Additional install commands

macOS

Homebrewverified · 100%
brew install rats

local Homebrew formula metadata

MacPortsverified · 94%
sudo port install rats

MacPorts ports tree · security/rats/Portfile · source: api.github.com

overview

Package summary

Rough auditing tool for security

Commands and aliases

  • rats

history

Project history and usage

RATS, the Rough Auditing Tool for Security, is a command-line static analysis scanner for finding common security-sensitive programming patterns in source code.

Project history

The official README says RATS was developed, maintained, and distributed by Secure Software, Inc. The 2.4 source archive describes it as a scanner for C, C++, Perl, PHP, Python, and Ruby source that flags issues such as buffer overflows and TOCTOU race conditions.

Adoption history

RATS circulated as a small Unix security-auditing utility through source archives and package managers. Homebrew, Debian-derived manpage packaging, Fedora, MacPorts, and other Unix package collections carried it as a lightweight source-code auditing tool.

How it is used

Users run rats against files or directories and can select vulnerability databases with -d, force a language with -l, choose warning levels, recurse through directories, and emit text, XML, or HTML reports.

Why package nerds care

Package maintainers care about RATS because it is an old-style security CLI: small C code, autoconf build, XML vulnerability databases, and a package surface that exposes static-analysis behavior without a large framework.

Timeline

  • 2001: The bundled manpage date records RATS documentation in September 2001.
  • 2.4: Homebrew packages the Google Code archive release as the stable version.

Related projects

  • The README notes Expat as a build/runtime requirement and credits Ben Laurie for OpenSSL-specific database contributions.

Sources

  • Google Code Archive: official rough-auditing-tool-for-security project and source download.
  • Homebrew formula metadata for rats stable 2.4.
  • RATS 2.4 README and rats.1 from the official Google Code archive tarball.

security posture

Risk level: green

narrow executable package without higher-risk signals.

Risk classifier

green risk · low confidence · appliance

Why

  • narrow executable package without higher-risk signals

Signals

  • metadata:no-higher-risk-signals

Install behavior

  • No Homebrew bottle metadata was recorded.

Recommended review

Before unattended agent use, check whether the tool reads plaintext credentials, writes remote state, publishes artifacts, or shells out to plugins.

executables

Installed executables

CommandKindExposureNote
ratsexecutableindexed executableDiscovered from the local executable index.

freshness

Version and freshness

These signals separate page generation age, package-manager activity, and upstream release comparison. Version lag is warned only when an evidence URL and comparable versions are present.

page generated2026-08-03
manager version2.4
manager updated
local dataunknown
upstreamnot available
latest detectednot detected
  • okNo freshness warnings were generated.

install metadata

Package metadata

Package keybrew:rats
Version2.4
Package managerHomebrew
Homepagehttps://security.web.cern.ch/security/recommendations/en/codetools/rats.shtml
Bottlenot recorded
Servicenone declared

source database matches

Other package-manager records

Matches are pulled from external package-manager indexes and kept separate from local Automic Vault package links.

dnf95%

rats 2.4-32.fc45

Rough Auditing Tool for Security

https://code.google.com/p/rough-auditing-tool-for-security/

sudo dnf install rats
  • License: GPL-2.0-only
  • Category: Unspecified
  • Architecture: x86_64
  • Source Package: rats
  • 3 dependencies
  • 1 provides
  • normalized package name match
  • Matched by: Rats
Fedora Rawhide package metadata · dl.fedoraproject.org · Fedora Rawhide package metadata: rats from https://dl.fedoraproject.org/pub/fedora/linux/development/rawhide/Everything/x86_64/os/repodata/07190dc5ae9f35ae73866675fed6d95fe6e8d9fe22c9d7cdf85862cb2ed24a4c-primary.xml.zst
MacPorts95%

rats

sudo port install rats
  • normalized package name match
  • Matched by: Rats
MacPorts ports tree · api.github.com · MacPorts ports tree: security/rats/Portfile from https://api.github.com/repos/macports/macports-ports/git/trees/master?recursive=1

source trail

Generated from repository data

This page is generated by av-web from the private package SQLite artifact built by scripts/generate-pkg-sqlite.py.

Used sources

  • Geiger risk classifier
  • cross-ecosystem install command graph
  • curated package history
  • external package-manager database matches
  • pkg.so package database
  • pkgdb category and tag curation