scan-build
Run the Clang static analyzer on projects with a compilation database.
Decision gist · record as of 2026-08-14
Yes. This is a mature, actively maintained tool (release 4 days old, 396 GitHub stars) with zero known vulnerabilities, no Python dependencies, and permissive MIT licensing. Install it if you need to run Clang static analysis on C/C++ projects with a compilation database. The only real prerequisite is having clang and a compilation database available—if your build system doesn't generate one natively, use Bear first.AI-flagged interpretation of the facts on this page — verify before relying
Before you install
- Requires clang to be installed and a compilation database (compile_commands.json) for your project; Python 3.10 or later.
- Low friction: pure Python wheel with no runtime dependencies.
- Actively maintained with a release 4 days old.
License · maintenance · safety
MIT (permissive) — MIT license (permissive): you can use, modify, and distribute this package freely with minimal restrictions, making it safe for both open-source and commercial projects.
last release 2026-08-10 (4 days) · last repo commit 2026-08-10 · 396 stars
0 known vulnerabilities (OSV.dev, 2026-08-14) · 151,137 downloads/mo, #10,943 on PyPI
Alternatives
Verify before relying
$ pip install scan-build
$ cmake -B build -DCMAKE_EXPORT_COMPILE_COMMANDS=ON
$ clanganalyzer --cdb build/compile_commands.json --output report- Whether the tool's analysis accuracy and coverage match or exceed the original Perl scan-build implementation.
- Performance characteristics when analyzing large codebases with many compilation database entries.
What it is and what it does
scan-build is a Python-based wrapper around the Clang static analyzer that automates analysis of C/C++ projects. It reads a compilation database (a JSON file describing how each source file should be compiled), runs the Clang analyzer against each entry, and produces reports of potential bugs in HTML or machine-readable plist format. The tool works with any build system that can generate a compilation database—CMake does this natively with a flag, and other build systems can use the Bear tool to capture compiler invocations.
The package requires clang to be installed separately and Python 3.10 or later. It has no Python dependencies, making installation straightforward. Unlike earlier versions, it no longer intercepts build commands; it purely analyzes existing compilation databases. This design simplifies the tool and shifts database generation to dedicated tools like Bear, which now support all major platforms including Windows.
Use it for
- Integrate static analysis into CI/CD pipelines with --status-bugs to fail builds when potential bugs are detected.
- Analyze third-party or legacy C/C++ codebases without modifying their build configuration.
- Generate HTML reports of code defects for code review and quality tracking across releases.
- Exclude specific directories (e.g., vendor code) from analysis using --exclude flags.
- Export machine-readable plist output for automated tooling and defect tracking systems.
Worth the install?
AI-flagged interpretation of the facts on this page. Verify before relying on it.
Yes.
This is a mature, actively maintained tool (release 4 days old, 396 GitHub stars) with zero known vulnerabilities, no Python dependencies, and permissive MIT licensing. Install it if you need to run Clang static analysis on C/C++ projects with a compilation database. The only real prerequisite is having clang and a compilation database available—if your build system doesn't generate one natively, use Bear first.
Install
scan-build on PyPI
Before you install
Low friction: pure Python wheel with no runtime dependencies. Actively maintained with a release 4 days old. Requires clang and a compilation database to function, but the tool itself installs cleanly.
Requires clang to be installed and a compilation database (compile_commands.json) for your project; Python 3.10 or later.
License in practice
MIT license (permissive): you can use, modify, and distribute this package freely with minimal restrictions, making it safe for both open-source and commercial projects.
Quickstart
$ pip install scan-build
$ cmake -B build -DCMAKE_EXPORT_COMPILE_COMMANDS=ON
$ clanganalyzer --cdb build/compile_commands.json --output report
Verify before relying
- Whether the tool's analysis accuracy and coverage match or exceed the original Perl scan-build implementation.
- Performance characteristics when analyzing large codebases with many compilation database entries.
Package facts
| License | MIT permissive |
| Python support | Supports the current Python release >=3.10 |
| Install friction | Low. Pure-Python wheel |
| Runtime dependencies | None |
| Maintenance | Actively maintained 4 days since the last release |
| Last repo commit | |
| First released | |
| Downloads | 151,137 / month, #10,943 on PyPI 30-day window, as of 2026-08-14 |
| Known vulnerabilities | None known OSV.dev, checked 2026-08-14 |
| Classifiers | Development Status :: 5 - Production/StableEnvironment :: ConsoleIntended Audience :: DevelopersOperating System :: MacOS :: MacOS XOperating System :: Microsoft :: WindowsOperating System :: POSIXProgramming Language :: CProgramming Language :: Python :: 3Programming Language :: Python :: 3.10Programming Language :: Python :: 3.11Programming Language :: Python :: 3.12Programming Language :: Python :: 3.13Programming Language :: Python :: 3.14Topic :: Software Development :: CompilersTopic :: Software Development :: Quality AssuranceTyping :: Typed |
Evidence: scan_build-3.1.0-py3-none-any.whl
Tags
Let your AI agent find packages like this
Example. Real query, live index.
You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.
wish › “clang static analyzer”
- scan-buildRuns the Clang static analyzer on C/C++ projects using a compilation…
- clangProvides Python bindings to libclang, allowing you to…
- libclangProvides Python bindings to Clang's C API, bundled with prebuilt…
Give your agent the search over MCP, or paste the wish link into any chat.
More Quality Assurance packages
Coverage.py measures which lines of Python code are executed during test runs, reporting coverage percentages and identifying untested code paths.
Install it if you want to measure test completeness or enforce coverage thresholds in your project.
Ruff is a Python linter and code formatter written in Rust that combines linting, formatting, and code fixing into a single tool, replacing Flake8, Black, isort, and related utilities.
Pexpect spawns and controls interactive console applications by sending input and matching output patterns, automating tasks that would otherwise require manual interaction.
Black reformats Python source code to a consistent style by parsing entire files and rewriting them according to an opinionated, deterministic set of rules, eliminating manual formatting decisions.
pytest-xdist distributes pytest tests across multiple CPU cores or machines to speed up test execution, with the simplest usage being `pytest -n auto` to spawn workers equal to available CPUs.
Install it if your test suite takes long enough that parallelization would save meaningful time.
Validates AWS CloudFormation templates in YAML or JSON format against resource provider schemas and best practices, checking property values and configuration correctness.
Install it if you work with CloudFormation templates.
See also compiledb · sccache · flawfinder · lizard · clang · clangd-tidy · lit · meson · chialisp-builder · slither-analyzer