Skip to main content

ScubaTrace

PyPI Docs Tests CodeQL License

ScubaTrace: Source-level code analysis toolkit for SAST, context engineering, and AI coding.


ScubaTrace is a code analysis toolkit that leverages tree-sitter, Joern and LSP (Language Server Protocol) to provide parsing, analysis, and context extraction capabilities for multiple programming languages.

Unlike most traditional static analysis tools that rely on compilation to extract Intermediate Representation (IR) for code analysis, ScubaTrace delivers analysis capabilities even when code repositories are incomplete or unable to compile. This resilience makes it particularly valuable for scenarios where traditional analysis approaches would fail, enabling developers and security researchers to gain insights from code that might otherwise be inaccessible to conventional static analysis methodologies.

Rather than being an end-to-end program analysis framework, ScubaTrace serves as a foundational toolkit that empowers developers to build solutions for IDE development, AI-powered coding tools, and SAST (Static Application Security Testing).

Features

  • Multi-Language Support
  • No Need To Compile
  • Statement-Based AST Abstraction
  • Call Graph
  • Control Flow Graph
  • Data/Control Dependency Graph
  • References Inference
  • CPG Based Multi-Granularity Slicing
  • Built on Tree-sitter and LSP

Install

pip install scubatrace

Supported Languages

ScubaTrace supports multiple programming languages, including:

Language Language Server Tree-sitter Parser Maturity
C/C++ clangd tree-sitter-cpp High
Java Eclipse JDT LS tree-sitter-java High
Python Pyright tree-sitter-python High
JavaScript typescript-language-server tree-sitter-javascript Medium
Go gopls tree-sitter-go Medium
Rust Rust Analyzer tree-sitter-rust Medium
Ruby Solargraph tree-sitter-ruby Low
Swift SourceKit-LSP tree-sitter-swift Low
C# OmniSharp tree-sitter-c-sharp Low
PHP phpactor tree-sitter-php Low

Usage

Initialize a ScubaTrace Project

import scubatrace

# Initialize a ScubaTrace Project
# language can be set to one of the following:
# scubatrace.language.[C, JAVA, PYTHON, JAVASCRIPT, GO, RUST, RUBY, PHP, CSHARP, SWIFT]
project = scubatrace.Project.create("path/to/your/codebase", language=scubatrace.language.C)

Retrieve Code Entities

# Get a file from the project
file = project.files["relative/path/to/your/file.c"]

# Get a function from the file
function = file.functions[0]
print(f"Function Name: {function.name}")
print(f"Source Code: {function.text}")

# Get the function's callers and print their names and callsites
callers = function.callers
for caller, callsites in callers.items():
    print(f"Caller: {caller.name}")
    for callsite in callsites:
        print(f"  Callsite: {callsite.text}")

# Get the first statement in file line
statement = file.statements_by_line(10)[0]

# Get the first variable in statement
variable = statement.variables[0]
print(f"Variable: {variable.name}")

# Get tree-sitter node in a file/function/statement
file_node = file.node
function_node = function.node
statement_node = statement.node

Perform Analysis

# Find the pre/post statements in control flow
pre_statements_in_control_flow = statement.pre_controls
post_statements_in_control_flow = statement.post_controls

# Find the pre/post data dependencies of a variable
pre_data_dependencies = variable.pre_data_dependents
post_data_dependencies = variable.post_data_dependents

# Find the definitions/references of a variable
definitions = variable.definitions
references = variable.references

# Perform slicing in a function based on specified lines
# Configure the slicing with control depth and data-dependent depth
criteria_lines = [10, 12, 18]
sliced_statements = function.slice_by_lines(
    lines=criteria_lines, control_depth=5, data_dependent_depth=8
)

ScubaTrace with Joern

# Initialize a ScubaTrace Project with Joern
project = scubatrace.Project.create(
    "path/to/your/codebase",
    language=scubatrace.language.C,
    joern_config=scubatrace.JoernConfig(
        enable_joern=True,
    ),
)

For more detailed information, refer to the Documentation.

Metadata

Release files for scubatrace 1.1.3

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for scubatrace 1.1.3
File Size Uploaded
scubatrace-1.1.3.tar.gz 69.4 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for scubatrace 1.1.3
File Interpreter ABI Platform
scubatrace-1.1.3-py3-none-any.whl Python 3 none any Details

Total release size: 158.5 kB

Release files / scubatrace-1.1.3.tar.gz

Download URL scubatrace-1.1.3.tar.gz
Size 69.4 kB
Tags Source
SHA-256 checksum
How to use checksums
528eabd633400fee533aba91b15b3cb2a79722a292e4a37e720b3dbf195d45a5
BLAKE2b-256 checksum
How to use checksums
30ebd0a3642081b5d5230d95caa622637d4405aeb031bf47a0e031d292decbdd
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.1.0 CPython/3.13.12

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Jun 7, 2026.

Transparency log

Release files / scubatrace-1.1.3-py3-none-any.whl

Download URL scubatrace-1.1.3-py3-none-any.whl
Size 89.1 kB
Tags Python 3
SHA-256 checksum
How to use checksums
57442e5e2ec3c390f993468f8f6028bb1dd59a79c9240b19d8054d1b6209f4f9
BLAKE2b-256 checksum
How to use checksums
9d615f7a291e6fd34f35f16ccf08928be920f56569a36c79f287f2acf9ffdb26
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.1.0 CPython/3.13.12

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Jun 7, 2026.

Transparency log

Release history Release notifications | RSS feed

This release

1.1.3 This release

2 release files

1.1.2

2 release files

1.1.1

2 release files

1.1.0

2 release files

1.0.6

2 release files

1.0.5

2 release files

1.0.4

2 release files

1.0.3

2 release files

1.0.2

2 release files

1.0.1

2 release files

1.0.0

2 release files

0.9.6

2 release files

0.9.5

2 release files

0.9.4

2 release files

0.9.3

2 release files

0.9.2

2 release files

0.9.1

2 release files

0.9.0

2 release files

0.8.1

2 release files

0.8.0

2 release files

0.7.2

2 release files

0.7.1

2 release files

0.7.0

2 release files

0.6.7

2 release files

0.6.6

2 release files

0.6.5

2 release files

0.6.4

2 release files

0.6.3

2 release files

0.6.2

2 release files

0.6.1

2 release files

0.6.0

2 release files

0.5.2

2 release files

0.5.1

2 release files

0.5.0

2 release files

0.4.1

2 release files

0.4.0

2 release files

0.3.0

2 release files

0.2.0

2 release files

0.1.0

2 release files

0.0.2

2 release files

0.0.1

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page