Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.
Rule-based scans of many languages from the CLI or in CI, with no server keeping findings across branches.
SonarSource's hosted static analysis service, formerly SonarCloud, that analyses code from connected repositories for bugs, code smells and vulnerabilities and reports on branches and pull requests. SonarSourceのクローズドな製品です。
| ツール | 置き換えの度合い | スター | ライセンス | 利用条件 | セルフホスト | 言語 | 最新リリース | 最終プッシュ |
|---|---|---|---|---|---|---|---|---|
| Semgrep | 部分的 | 17k | LGPL-2.1 | オープンソース | 可 | C | v1.179.0 | 2026-10-06 |
| SonarQube Community Build | 部分的 | 11k | LGPL-3.0 | オープンソース | 可 | Java | 26.9.0.129388 | 2026-10-05 |
| CodeChecker | 部分的 | 2.6k | Apache-2.0 | オープンソース | 可 | Python | v6.29.1 | 2026-10-03 |
| MegaLinter | 部分的 | 2.6k | AGPL-3.0 | オープンソース | 可 | Dockerfile | v10.1.0 | 2026-10-06 |
代替4件
Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.
Rule-based scans of many languages from the CLI or in CI, with no server keeping findings across branches.
Continuous Inspection
The same kind of analysis on a server you run, for the main branch only, without branch analysis or pull request decoration.
CodeChecker is an analyzer tooling, defect database and viewer extension for static and dynamic analyzer tools.
Stores, compares and triages the results of Clang, GCC and other analyzers on a server you run, mainly for C and C++.
🦙 MegaLinter analyzes 50 languages, 22 formats, 21 tooling formats, excessive copy-pastes, spelling mistakes and security issues in your repository sources with a GitHub Action, other CI tools or locally.
Runs many linters and analyzers in CI and reports on pull requests, with no server keeping history.