Skip to main content
https://img.shields.io/pypi/v/scan-build.svg https://img.shields.io/pypi/l/scan-build.svg https://img.shields.io/pypi/dm/scan-build.svg https://img.shields.io/pypi/pyversions/scan-build.svg

clanganalyzer

clanganalyzer runs the Clang static analyzer against a project using its compilation database, and generates a report of the potential bugs it finds. It lets you analyze an existing code base without modifying the build.

How to use

A typical workflow with a CMake project:

$ cmake -B build -DCMAKE_EXPORT_COMPILE_COMMANDS=ON
$ clanganalyzer --cdb build/compile_commands.json --output report

This runs the analyzer against every entry of the compilation database and writes an HTML report into a subdirectory of the output directory. By default the compilation database is read from compile_commands.json in the current directory, and reports are written under the system temp directory.

Some commonly used options:

  • --output <path> — where to put the analyzer reports.

  • --status-bugs — exit with a non-zero status if potential bugs were found; useful in CI.

  • --exclude <directory> — skip files in the given directory (e.g. third-party code); can be repeated.

  • --plist, --plist-html — emit machine-readable plist output instead of (or along with) HTML.

Use --help for the full list of options. The tool is also installed under the alias analyze-build, the name it had in earlier releases.

How to install

The package is published on PyPI as scan-build for historical reasons (see History). Install it with pip:

$ pip install scan-build

Or as a standalone tool with uv:

$ uv tool install scan-build

Prerequisites and limitations

To run the analysis you need:

  1. clang, to compile the sources and to run the static analyzer.

  2. A compilation database (compile_commands.json) for your project. CMake can generate one with -DCMAKE_EXPORT_COMPILE_COMMANDS=ON; for other build systems, use Bear.

The tool itself requires a Python interpreter (version 3.10 or later). It has been tested on FreeBSD, GNU/Linux, macOS and Windows.

Unlike earlier versions, this package does not intercept build commands: if your build system cannot export a compilation database, create one with Bear before running the analysis.

Problem reports

If you find a bug in the program or in this documentation, or would like to propose an improvement, please use the project’s issue tracker. Please describe the bug and where you found it. If you have a suggestion how to fix it, include that as well. Patches are also welcome.

Development

To set up a development environment:

$ git clone https://github.com/rizsotto/scan-build.git
$ cd scan-build
$ uv sync

To run tests:

$ uv run pytest tests/unit
$ uv run lit -v tests/functional

To run formatting, linting and type checking:

$ uv run ruff check .
$ uv run ruff format .
$ uv run ty check clanganalyzer

History

This project started as a Python rewrite of the scan-build Perl scripts shipped with Clang. An earlier version was contributed to the Clang repository as scan-build-py, and this project has been published on PyPI under the name scan-build ever since — which is why the package name and the command name differ.

Up to version 2.x the package also provided intercept-build, a tool to capture compiler calls and produce a compilation database. That functionality was removed in version 3.0: the Bear project now covers all targeted platforms (including Windows, which was the original reason for the Python implementation), so this package focuses solely on running the analyzer.

License

The project is licensed under the MIT License. See LICENSE.txt for details.

Release files for scan-build 3.1.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for scan-build 3.1.0
File Size Uploaded
scan_build-3.1.0.tar.gz 45.6 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for scan-build 3.1.0
File Interpreter ABI Platform
scan_build-3.1.0-py3-none-any.whl Python 3 none any Details

Total release size: 78.9 kB

Release files / scan_build-3.1.0.tar.gz

Download URL scan_build-3.1.0.tar.gz
Size 45.6 kB
Tags Source
SHA-256 checksum
How to use checksums
dc98511d2c3acf306a11f0b3b580e04c13a936449da73576c8f623ae514d6bb6
BLAKE2b-256 checksum
How to use checksums
461776f65ac070aa9fbdf6c1982dc02395f03aac887dd1924aff12336b396f58
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Aug 10, 2026.

Transparency log

Release files / scan_build-3.1.0-py3-none-any.whl

Download URL scan_build-3.1.0-py3-none-any.whl
Size 33.3 kB
Tags Python 3
SHA-256 checksum
How to use checksums
4a8910d1efffa67c23ca4fd677b2046544f03928aa0c328f8e86ec83beacec0b
BLAKE2b-256 checksum
How to use checksums
3d73ab7bb361313d112e99f0bdf72798205790f33b2fd85aa352ea02746c9206
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Aug 10, 2026.

Transparency log

Release history Release notifications | RSS feed

This release

3.1.0 This release

2 release files

3.0.0

2 release files

2.0.20

2 release files

2.0.19

1 release file

2.0.18

1 release file

2.0.17

1 release file

2.0.16

1 release file

2.0.15

1 release file

2.0.14

1 release file

2.0.13

1 release file

2.0.12

1 release file

2.0.11

1 release file

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page