pkg.soopen package index

brew / 排名 675

使用 Homebrew, apk, scoop 安装 sonar-scanner

查看 sonar-scanner 的安装路径、可执行文件、元数据以及面向 AI 代理工作流的安全说明。

安装

其他安装命令

macOS

Homebrew已验证 · 100%
brew install sonar-scanner

local Homebrew formula metadata

Linux

Alpine Linux apk已验证 · 92%
sudo apk add sonar-scanner

Alpine Linux edge package indexes · sonar-scanner · 来源: dl-cdn.alpinelinux.org

Windows

Scoop已验证 · 92%
scoop install main/sonar-scanner

Scoop official bucket manifest trees · bucket/sonar-scanner.json · 来源: api.github.com

概览

软件包摘要

Launcher to analyze a project with SonarQube

命令和别名

  • sonar-scanner

历史

项目历史与用法

SonarScanner CLI is SonarSource's command-line scanner for running SonarQube Server and SonarQube Cloud code analysis when there is no build-system-specific scanner. It is a CI/CD staple because it turns a checked-out source tree plus `sonar-project.properties` into an analysis uploaded to a Sonar service.

项目历史

The public GitHub repository is the official scanner CLI source tree, and its tags include older 2.x releases. Current SonarSource documentation presents a maintained release line from 4.x through 8.x, with the README stating that project configuration is read from `sonar-project.properties` or passed on the command line.

Notable documented release changes include the 4.3 release using the SonarScanner name in logs, the 4.4 release adding a supported Docker image, the 5.0 release embedding Java 17, the 6.0 release adding a new bootstrapping mechanism and JRE provisioning for SonarQube 10.6+ and SonarCloud, and the 8.0.1 release updating embedded JREs to Java 21.

采用历史

The scanner is distributed as OS-specific downloads, a Docker image, a generic JVM zip, and package-manager formulae. Homebrew analytics show tens of thousands of yearly installs, which fits its role as a common CI dependency rather than a library used inside application code.

使用方式

Users create `sonar-project.properties` in the project root, run `sonar-scanner`, and provide server/project credentials through scanner parameters, CI secrets, or environment configuration rather than a dedicated credentials file. SonarSource warns users to prefer dedicated Maven, Gradle, or .NET scanners for those build systems.

为什么软件包爱好者会关心

SonarScanner CLI matters to package maintainers because CI images and developer machines need a reproducible scanner binary with the right Java behavior. Changes such as embedded JRE updates, Docker distribution, and auto-provisioning affect whether a package works in minimal runners, corporate networks, and long-lived build pipelines.

时间线

  • 2019: SonarScanner CLI 4.3 documents use of the SonarScanner name in logs.
  • 2020: Version 4.4 adds a supported Docker image.
  • 2023: Version 5.0 updates the embedded JRE to Java 17.
  • 2024: Version 6.0 adds new bootstrapping and JRE provisioning.
  • 2025: Version 7.3 adds z/OS support for scanner execution.
  • 2025: Version 8.0.1 updates embedded JREs to Java 21.

Related projects

  • SonarQube Server and SonarQube Cloud receive the analysis results.
  • Dedicated SonarScanners exist for Maven, Gradle, and .NET and are recommended for those ecosystems.
  • The scanner is also distributed as the official `sonarsource/sonar-scanner-cli` Docker image.

安全态势

风险级别:绿色

narrow executable package without higher-risk signals.

风险分类器

绿色 风险 · 低 置信度 · appliance

原因

  • narrow executable package without higher-risk signals

信号

  • metadata:no-higher-risk-signals

安装行为

  • 未记录 Homebrew bottle 元数据。

建议审查

在无人值守的代理使用前,请检查该工具是否读取明文凭据、写入远程状态、发布制品或调用插件。

local files

Configuration and credential file locations

These source-backed paths show where this package keeps local settings or durable credentials. Automic Vault can use them as review targets for secret scanning, migration, and command approval.

Configuration files

Config paths the tool may read or write during local use.

Unix
sonar-project.properties${scanner.home}/conf/sonar-scanner.properties

可执行文件

已安装的可执行文件

命令类型暴露范围备注
sonar-scanner可执行文件已索引可执行文件从本地可执行文件索引发现。

新鲜度

版本和新鲜度

这些信号区分页生成时间、软件包管理器活动和上游发布比较。只有存在证据 URL 和可比较版本时,才会提示版本落后。

页面生成时间2026-08-03
管理器版本8.1.0.6389
管理器更新时间
本地数据未知
上游不可用
检测到的最新版本未检测到
  • OK没有生成新鲜度警告。

安装元数据

软件包元数据

软件包键brew:sonar-scanner
版本8.1.0.6389
软件包管理器Homebrew
主页https://docs.sonarqube.org/latest/analysis/scan/sonarscanner/
仓库https://github.com/SonarSource/sonar-scanner-cli
Bottle未记录
服务未声明

源数据库匹配

其他软件包管理器记录

匹配项来自外部软件包管理器索引,并与本地 Automic Vault 软件包链接分开显示。

apk95%

sonar-scanner 8.1.0.6389-r0

Scanner CLI for SonarQube and SonarCloud

https://github.com/SonarSource/sonar-scanner-cli

sudo apk add sonar-scanner
  • License: LGPL-3.0-or-later
  • Architecture: x86_64
  • Source Package: sonar-scanner
  • 1 依赖
  • 1 提供
  • normalized package name match
  • 匹配方式:Sonar Scanner
Alpine Linux edge package indexes · dl-cdn.alpinelinux.org · Alpine Linux edge package indexes: sonar-scanner from https://dl-cdn.alpinelinux.org/alpine/edge/community/x86_64/APKINDEX.tar.gz
Scoop95%

main/sonar-scanner

scoop install main/sonar-scanner
  • normalized package name match
  • 匹配方式:Sonar Scanner
Scoop official bucket manifest trees · api.github.com · Scoop official bucket manifest trees: bucket/sonar-scanner.json from https://api.github.com/repos/ScoopInstaller/Main/git/trees/master?recursive=1

来源线索

由仓库数据生成

此页面由 av-webscripts/generate-pkg-sqlite.py 生成的私有软件包 SQLite 工件提供。

使用的来源

  • Geiger risk classifier
  • cross-ecosystem install command graph
  • curated configuration and credential file locations
  • curated package history
  • external package-manager database matches
  • pkg.so package database
  • pkgdb category and tag curation