# 使用 Homebrew, apk, dnf, MacPorts, pacman, scoop 安装 staticcheck

查看 staticcheck 的安装路径、可执行文件、元数据以及面向 AI 代理工作流的安全说明。

## 安装

```sh
sudo av install brew:staticcheck
```

其他安装命令:

### macOS

- Homebrew (100%):

```sh
brew install staticcheck
```

  证据: local Homebrew formula metadata

- MacPorts (94%):

```sh
sudo port install staticcheck
```

  证据: MacPorts ports tree: devel/staticcheck/Portfile from https://api.github.com/repos/macports/macports-ports/git/trees/master?recursive=1

### Linux

- apk (92%):

```sh
sudo apk add staticcheck
```

  证据: Alpine Linux edge package indexes: staticcheck from https://dl-cdn.alpinelinux.org/alpine/edge/community/x86_64/APKINDEX.tar.gz

- dnf (92%):

```sh
sudo dnf install staticcheck
```

  证据: Fedora Rawhide package metadata: staticcheck from https://dl.fedoraproject.org/pub/fedora/linux/development/rawhide/Everything/x86_64/os/repodata/07190dc5ae9f35ae73866675fed6d95fe6e8d9fe22c9d7cdf85862cb2ed24a4c-primary.xml.zst

- pacman (92%):

```sh
sudo pacman -S staticcheck
```

  证据: Arch Linux sync databases: staticcheck from https://geo.mirror.pkgbuild.com/extra/os/x86_64/extra.db.tar.gz

### Windows

- Scoop (92%):

```sh
scoop install main/staticcheck
```

  证据: Scoop official bucket manifest trees: bucket/staticcheck.json from https://api.github.com/repos/ScoopInstaller/Main/git/trees/master?recursive=1

## 软件包事实

- **软件包键:** brew:staticcheck
- **软件包管理器:** Homebrew
- **版本:** 2026.1
- **来源摘要:** State of the art linter for the Go programming language
- **主页:** <https://staticcheck.dev/>
- **仓库:** <https://github.com/dominikh/go-tools>
- **最后更新:** 2026-07-26T04:03:46+02:00
- **已生成:** 2026-08-03T19:37:03+00:00

## 可执行文件

- staticcheck (别名)

## 安装行为

- Bottle: 不可用

## 版本和新鲜度

- 页面生成时间: 2026-08-03
- 管理器版本: 2026.1
## 项目历史与用法

Staticcheck is a Go static-analysis command-line tool and one of the best-known third-party linters in the Go ecosystem. It is packaged as the `staticcheck` executable and is commonly installed with Go tooling or system package managers for local development and CI.

### 项目历史

The upstream project lives in Dominik Honnef's `go-tools` repository, which was created in January 2017. The official README describes Staticcheck as an advanced Go linter that finds bugs and performance issues, offers simplifications, and enforces style rules.

Staticcheck publishes release notes on staticcheck.dev. The release-note index records releases from 2017.2 through the 2026 series, showing a long-running tool with versioned compatibility work alongside Go's release cadence.

### 采用历史

The input package metadata lists Staticcheck in Homebrew, Alpine, Fedora, MacPorts, Arch, and Scoop. The official documentation also recommends installing released versions with `go install honnef.co/go/tools/cmd/staticcheck@latest` on modern Go versions or using prebuilt binaries from GitHub releases.

Staticcheck's package-manager footprint reflects its role as a standard quality gate for Go projects. It is useful as a standalone CLI, as a CI check, and as a linter that complements the Go compiler and `go vet`.

### 使用方式

Typical usage is to run `staticcheck` against Go packages or wire it into CI. The tool can analyze code targeting Go versions up to the latest release, while the project recommends using tagged releases instead of master for stable builds.

### 为什么软件包爱好者会关心

Package nerds care about Staticcheck because it is a canonical example of a language ecosystem tool that lives outside the core toolchain but is widely treated as infrastructure. Its version tags, prebuilt binaries, and `go install` path make it straightforward to pin in reproducible builds.

For package managers, Staticcheck is high-value despite being a single executable: it is heavily used by Go developers, has stable release notes, and represents the broader `honnef.co/go/tools` analyzer collection.

### 时间线

- 2017: `dominikh/go-tools` repository created.
- 2017: Staticcheck 2017.2 release published.
- 2019: Staticcheck 2019.2 release notes described major performance and memory improvements.
- 2026: Staticcheck 2026.1 and 2026.2 release candidates appeared in official releases.

### Related projects

- The same repository contains related tools such as `structlayout`, `structlayout-optimize`, and `structlayout-pretty`, and libraries used to implement the tools.

### 来源

- <https://github.com/dominikh/go-tools>
- <https://raw.githubusercontent.com/dominikh/go-tools/master/README.md>
- <https://staticcheck.dev/changes/>
- <https://staticcheck.dev/docs/getting-started/>
- input.source_facts.package-manager


## 安全说明

generalized runtime or code generation signal.

- **Geiger 风险:** yellow / 中
- generalized runtime or code generation signal


## Configuration and credential file locations

These source-backed paths show where this package keeps local settings or durable credentials. Automic Vault can use them as review targets for secret scanning, migration, and command approval.


## Configuration files

- Unix: staticcheck.conf
- Windows: staticcheck.conf
## 其他软件包管理器记录

- apk - staticcheck - 2026.1-r4: normalized package name match | Alpine Linux edge package indexes: staticcheck from https://dl-cdn.alpinelinux.org/alpine/edge/community/x86_64/APKINDEX.tar.gz | advanced Go linter | https://github.com/dominikh/go-tools
- dnf - staticcheck - 2026.1-1.fc45: normalized package name match | Fedora Rawhide package metadata: staticcheck from https://dl.fedoraproject.org/pub/fedora/linux/development/rawhide/Everything/x86_64/os/repodata/07190dc5ae9f35ae73866675fed6d95fe6e8d9fe22c9d7cdf85862cb2ed24a4c-primary.xml.zst | The advanced Go linter | https://github.com/dominikh/go-tools
- pacman - staticcheck - 2026.1-3: normalized package name match | Arch Linux sync databases: staticcheck from https://geo.mirror.pkgbuild.com/extra/os/x86_64/extra.db.tar.gz | The advanced Go linter | https://staticcheck.io
- MacPorts - staticcheck: normalized package name match | MacPorts ports tree: devel/staticcheck/Portfile from https://api.github.com/repos/macports/macports-ports/git/trees/master?recursive=1
- Scoop - main/staticcheck: normalized package name match | Scoop official bucket manifest trees: bucket/staticcheck.json from https://api.github.com/repos/ScoopInstaller/Main/git/trees/master?recursive=1


## Combined YAML source

View the package source record on GitHub. [combined/staticcheck.yml](https://github.com/mxcl/pkgdb/blob/main/combined/staticcheck.yml)


## 来源

- pkg.so package database
- Geiger risk classifier
- curated configuration and credential file locations
- curated package history
- pkgdb category and tag curation
- external package-manager database matches
- cross-ecosystem install command graph
