ShellCheck 0.11.0
A static analysis tool for shell scripts that finds quoting bugs, unsafe patterns, and portability problems, with an explanation and a wiki page for every warning it emits.
Download TAR.XZ Project website ↗Download Mirrors
ShellCheck reads a shell script and tells you what is wrong with it. For anyone writing shell, it is the single highest value tool available, and running it over an existing script is genuinely educational.
shellcheck myscript.sh
What it catches
Unquoted expansions, which is the single largest source of shell bugs. A variable holding a filename with a space becomes two arguments, silently.
rm $file # SC2086: Double quote to prevent globbing and word splitting
rm "$file" # correct
Missing double dash, so a file named -rf is not interpreted as a flag.
Useless use of cat, subshell variable scoping, unreachable code, [ versus [[ differences, and portability problems when a script declares #!/bin/sh and uses bash features.
Every warning has a code like SC2086 and a wiki page explaining the reasoning, which is why it teaches rather than just complains.
In a pre-commit hook
# .pre-commit-config.yaml
repos:
- repo: https://github.com/koalaman/shellcheck-precommit
rev: v0.11.0
hooks:
- id: shellcheck
Or directly:
find . -name '*.sh' -exec shellcheck {} +
shellcheck -S error myscript.sh # errors only
shellcheck -f gcc myscript.sh # editor-parseable output
Silencing a warning
Occasionally the tool is wrong for your specific case:
# shellcheck disable=SC2086
command $intentionally_unquoted
Put the directive immediately above the line, and add a comment explaining why, because a bare disable is indistinguishable from someone silencing a real bug.
Editor integration
Most editors have a plugin, which is where it delivers most value: the warning appears as you type rather than after you have written the whole script.
Our bash quoting guide covers the class of bug it primarily catches, and our error handling guide covers the options it will recommend.
Installing
sudo apt install shellcheck # Debian and Ubuntu
sudo dnf install ShellCheck # Fedora
sudo pacman -S shellcheck # Arch
Verify Your Download
Release archives on GitHub are published with checksums.