shellcheck-repl VS find-sec-bugs

Compare shellcheck-repl vs find-sec-bugs and see what are their differences.

shellcheck-repl

Validation of Shell Commands Before Evaluation (by HenrikBengtsson)

find-sec-bugs

The SpotBugs plugin for security audits of Java web applications and Android applications. (Also work with Kotlin, Groovy and Scala projects) (by find-sec-bugs)
InfluxDB - Power Real-Time Data Analytics at Scale
Get real-time insights from all types of time series data with InfluxDB. Ingest, query, and analyze billions of data points in real-time with unbounded cardinality.
www.influxdata.com
featured
SaaSHub - Software Alternatives and Reviews
SaaSHub helps you find the best software and product alternatives
www.saashub.com
featured
shellcheck-repl find-sec-bugs
4 8
15 2,209
- 0.7%
3.5 5.7
28 days ago 23 days ago
Shell Java
ISC License GNU Lesser General Public License v3.0 only
The number of mentions indicates the total number of mentions that we've tracked plus the number of user suggested alternatives.
Stars - the number of stars that a project has on GitHub. Growth - month over month growth in stars.
Activity is a relative number indicating how actively a project is being developed. Recent commits have higher weight than older ones.
For example, an activity of 9.0 indicates that a project is amongst the top 10% of the most actively developed projects that we are tracking.

shellcheck-repl

Posts with mentions or reviews of shellcheck-repl. We have used some of these posts to build our list of alternatives and similar projects. The last one was on 2022-10-27.
  • Shell Script Best Practices, from a decade of scripting things
    19 projects | news.ycombinator.com | 27 Oct 2022
    > "Use shellcheck."

    (Disclaimer: I'm one of the authors)

    After falling in love with ShellCheck several years ago, with the help of another person, I made the ShellCheck REPL tool for Bash:

      https://github.com/HenrikBengtsson/shellcheck-repl>
  • Bash Pitfalls
    5 projects | news.ycombinator.com | 16 Feb 2022
    Thank you, and thanks for the suggestion. Yes, it should be possible to keep the SC2154 check. I probably just disabled it as a quick fix when first started out. I'm tracking this in https://github.com/HenrikBengtsson/shellcheck-repl/issues/15.

    > You'd also want to take into account special variables like $RANDOM and $HOSTNAME, but that's pretty trivial.

    It seems like ShellCheck is already aware of these special Bash variable, e.g. 'echo $RANDOM' will not trigger SC2154 (or even SC2086 that otherwise asks you to quote variables).

  • ShellCheck: A static analysis tool for shell scripts
    12 projects | news.ycombinator.com | 18 Mar 2021
    shellcheck-repl: Validation of Shell Commands Before Evaluation

    https://github.com/HenrikBengtsson/shellcheck-repl

    This tool validates your commands at the Bash prompt using ShellCheck and refuses to evaluate them if there's a mistake. It ignores a set of rules that doesn't play well with oneliners.

    (Disclaimer: I'm one of the authors)

find-sec-bugs

Posts with mentions or reviews of find-sec-bugs. We have used some of these posts to build our list of alternatives and similar projects. The last one was on 2022-01-02.

What are some alternatives?

When comparing shellcheck-repl and find-sec-bugs you can also consider the following projects:

shellharden - The corrective bash syntax highlighter

Spotbugs - SpotBugs is FindBugs' successor. A tool for static analysis to look for bugs in Java code.

bats-core - Bash Automated Testing System

semgrep-rules - Semgrep rules registry

pure-bash-bible - 📖 A collection of pure bash alternatives to external processes.

snyk - Snyk CLI scans and monitors your projects for security vulnerabilities. [Moved to: https://github.com/snyk/cli]

ShellCheck - ShellCheck, a static analysis tool for shell scripts

semgrep - Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.

isort - A Python utility / library to sort imports.

static-analysis - ⚙️ A curated list of static analysis (SAST) tools and linters for all programming languages, config files, build tools, and more. The focus is on tools which improve code quality.

dmenu-scripts - Serious fun with dmenu

infer - A static analyzer for Java, C, C++, and Objective-C