# Install staticcheck with Homebrew

State of the art linter for the Go programming language. Version 2026.1 via Homebrew; verified 2026-07-26.

## Install

```sh
sudo av install brew:staticcheck
```

Additional install commands:

### macOS

- Homebrew (100%):

```sh
brew install staticcheck
```

  Evidence: provider-native install command

## Package facts

- **Package key:** brew:staticcheck
- **Package manager:** Homebrew
- **Version:** 2026.1
- **Source summary:** State of the art linter for the Go programming language
- **Homepage:** <https://staticcheck.dev/>
- **Repository:** <https://github.com/dominikh/go-tools>
- **Last updated:** 2026-07-26T04:03:46+02:00
- **Generated:** 2026-08-03T00:40:33+00:00

## Executables

- staticcheck (alias)

## Install behavior

- Bottle: not available

## Freshness

- Page generated: 2026-08-03
- Package-manager version: 2026.1
## Project history and usage

Staticcheck is a Go static-analysis command-line tool and one of the best-known third-party linters in the Go ecosystem. It is packaged as the `staticcheck` executable and is commonly installed with Go tooling or system package managers for local development and CI.

### Project history

The upstream project lives in Dominik Honnef's `go-tools` repository, which was created in January 2017. The official README describes Staticcheck as an advanced Go linter that finds bugs and performance issues, offers simplifications, and enforces style rules.

Staticcheck publishes release notes on staticcheck.dev. The release-note index records releases from 2017.2 through the 2026 series, showing a long-running tool with versioned compatibility work alongside Go's release cadence.

### Adoption history

The input package metadata lists Staticcheck in Homebrew, Alpine, Fedora, MacPorts, Arch, and Scoop. The official documentation also recommends installing released versions with `go install honnef.co/go/tools/cmd/staticcheck@latest` on modern Go versions or using prebuilt binaries from GitHub releases.

Staticcheck's package-manager footprint reflects its role as a standard quality gate for Go projects. It is useful as a standalone CLI, as a CI check, and as a linter that complements the Go compiler and `go vet`.

### How it is used

Typical usage is to run `staticcheck` against Go packages or wire it into CI. The tool can analyze code targeting Go versions up to the latest release, while the project recommends using tagged releases instead of master for stable builds.

### Why package nerds care

Package nerds care about Staticcheck because it is a canonical example of a language ecosystem tool that lives outside the core toolchain but is widely treated as infrastructure. Its version tags, prebuilt binaries, and `go install` path make it straightforward to pin in reproducible builds.

For package managers, Staticcheck is high-value despite being a single executable: it is heavily used by Go developers, has stable release notes, and represents the broader `honnef.co/go/tools` analyzer collection.

### Timeline

- 2017: `dominikh/go-tools` repository created.
- 2017: Staticcheck 2017.2 release published.
- 2019: Staticcheck 2019.2 release notes described major performance and memory improvements.
- 2026: Staticcheck 2026.1 and 2026.2 release candidates appeared in official releases.

### Related projects

- The same repository contains related tools such as `structlayout`, `structlayout-optimize`, and `structlayout-pretty`, and libraries used to implement the tools.

### Sources

- <https://github.com/dominikh/go-tools>
- <https://raw.githubusercontent.com/dominikh/go-tools/master/README.md>
- <https://staticcheck.dev/changes/>
- <https://staticcheck.dev/docs/getting-started/>
- input.source_facts.package-manager


## Security Notes

generalized runtime or code generation signal.

- **Geiger risk:** yellow / medium
- generalized runtime or code generation signal


## Configuration and credential file locations

These source-backed paths show where this package keeps local settings or durable credentials. Automic Vault can use them as review targets for secret scanning, migration, and command approval.


## Configuration files

- Unix: staticcheck.conf
- Windows: staticcheck.conf

## Combined YAML source

View the package source record on GitHub. [combined/staticcheck.yml](https://github.com/automic-vault/db/blob/main/combined/staticcheck.yml)


## Sources

- Nucleus package database
- Geiger risk classifier
- curated configuration and credential file locations
- curated package history
- pkgdb category and tag curation
