ShellCheck: A static analysis tool for shell scripts
github.com
github.com
Lessons learned from writing ShellCheck - https://news.ycombinator.com/item?id=22279585 - Feb 2020 (46 comments)
Shellcheck: a static analysis tool for shell scripts - https://news.ycombinator.com/item?id=9001931 - Feb 2015 (46 comments)
ShellCheck: a static analysis and linting tool for sh/bash scripts - https://news.ycombinator.com/item?id=8777705 - Dec 2014 (20 comments)
ShellCheck – Online shell script analyzer - https://news.ycombinator.com/item?id=8182745 - Aug 2014 (14 comments)
It was a while ago and seemed a bit gimmicky, but i really enjoyed the ability to see what could be done about an error by opening a web page (without having to manually dig through StackOverflow or other sites).
Now, if we'd get a development framework that'd couple documentation like that, with user generated comments (like PHP has, for example see the bottom of https://www.php.net/manual/en/function.strcmp.php ), then i think the developer experience would improve a bunch!
Who knows, maybe even allow users to contribute possible fixes and allow those as autocomplete solutions and you've just improved on what tools like Codota do a whole bunch!
See https://github.com/find-sec-bugs/find-sec-bugs/blob/master/f...
I agree that it’s really handy, especially when implementing the check in a CI pipeline with lots of developers.
Each rule has its own url. Tool therefore easily gives you a link.
One thing which might be worth considering is adding this to your personal ~/.shellcheckrc to make it more pedantic:
enable=all
What people don't always expect is the immense portability that POSIX-compliant Shell offers you. This thing runs on pretty much everything.
Then again, I've learnt more than once that you start with "I'm just capturing a few commands in a script" and the next thing you see is a mess of special characters, crude syntax and nasty error handling. Don't be like me...
What I love python for is scraping web pages and dealing with JSON or xml it rocks for that.
All shells take the -n option to perform a basic syntax check.
Debian has a script for checking scripts for bashisms:
https://manpages.debian.org/checkbashisms
bashate is a automated style checker for bash (similar to pep8 for python):
https://opendev.org/openstack/bashate
lintshell is an early prototype of a shell linter based on the Morbig trustworthy static parser for POSIX shell, based on the Why3 platform for deductive program verification.
https://www.irif.fr/~treinen/colis/ https://github.com/colis-anr/morbig https://github.com/colis-anr/lintshell
Shellharden helps rewrite scripts for ShellCheck compliance:
https://github.com/anordal/shellharden/
shfmt is gofmt for shell:
ShellScriptFormatter is another formatter:
https://github.com/osalvador/ShellScriptFormatter
Some of these tools and other tools can be automatically run by check-all-the-things:
Click on the site link[1] in parenthesis to the right of the title, you will see.
[1]: https://news.ycombinator.com/from?site=github.com/koalaman
It's like in this xkcd. It's always new to somebody.
One of these tests is to run shellcheck against all of the scripts in the repo. We don't allow any modifications to scripts without shellcheck giving them the green light now. The quality of our tests has increased dramatically since this was instituted - it's a really great tool.
For someone who’s not used to them they might feel annoying (e.g. why should I wrap every $() in quotes?! Ugh) but once you accept them your code will be a million times better and safer.
I can credit Resharper for a large part of my proficiency in C# for example.
https://github.com/HenrikBengtsson/shellcheck-repl
This tool validates your commands at the Bash prompt using ShellCheck and refuses to evaluate them if there's a mistake. It ignores a set of rules that doesn't play well with oneliners.
(Disclaimer: I'm one of the authors)
There is also a LSP at : https://github.com/bash-lsp/bash-language-server
shellcheck will show you many more mistakes that are much more painful your example and also very common.
Deno is definitively an interesting language, but Shell scripting is the gateway to bootstrap so many of your beloved programming languages. If your environment allows it always prefer a proper programming language over shell scripting. Shell scripts are meant for Unix operating system operations, setting few variables, combining certain data-sources, doing filesystem operations, ...
I do think it would be nice if shellcheck was more opinionated, or if it was possible to create rulesets that have stronger opinions. For example, I would personally like to enforce the use of double bracket conditionals in my scripts, but I know that others prefer the single bracket variety.
If it was
#!/usr/bin/env sh
then shellheck would report SC3010: In POSIX sh, [[ ]] is undefined.
.