static analysis of C/C++ code
Go to file
amai2012 e0be3f6f1b
CI: Build GUI on ubuntu (#2626)
2020-05-03 10:10:39 +02:00
.github/workflows CI: Build GUI on ubuntu (#2626) 2020-05-03 10:10:39 +02:00
Cppcheck.xcodeproj
addons misra.py: Fix 5.1 and 5.2 FP for c99 (#2625) 2020-04-28 07:18:54 +02:00
cfg wxwidgets.cfg: Fixed false positive because Cppcheck cfg is not able to handle overloaded functions 2020-05-01 20:12:42 +02:00
cli ExprEngine: Document how it works 2020-04-30 12:18:49 +02:00
cmake some sanitizer build fixes and cleanups (#2621) 2020-04-24 21:17:06 +02:00
cve-test-suite
democlient
externals cleaned up setting of compiler options and a few more things in CMake (#2599) 2020-04-22 11:04:19 +02:00
gui GUI: When clearing results, remove files in build dir 2020-04-29 18:10:01 +02:00
htmlreport htmlreport: Fix source view with leading empty lines 2020-01-21 09:13:55 +01:00
lib Add bug hunting test case for CVE-2019-7156 2020-05-02 22:22:31 +02:00
man Manual; In bug hunting chapter focus on GUI usage better 2020-04-29 22:27:34 +02:00
oss-fuzz CMake correction to "fixed OSS-Fuzz builds and added CMake targets" (28cd5d7) (#2613) 2020-04-19 17:46:07 +02:00
platforms
rules Format rules files as well 2019-09-26 19:58:39 +02:00
samples Try to fix Travis 2019-08-20 22:00:50 +02:00
snap
test Add bug hunting test case for CVE-2019-16168 2020-05-03 08:49:24 +02:00
tools cleaned up setting of compiler options and a few more things in CMake (#2599) 2020-04-22 11:04:19 +02:00
win_installer Set version 2019-12-21 11:49:01 +01:00
.astylerc
.clang-tidy fixes for Clang and clang-tidy 10 (#2588) 2020-04-04 11:44:59 +02:00
.codacy.yml
.gitignore some cleanups (#2601) 2020-04-09 09:23:31 +02:00
.mailmap
.travis.yml Travis: Remove TestExprEngine for now, that does not work well 2020-05-01 15:22:04 +02:00
.travis_llvmcheck_suppressions
.travis_suppressions Check that virtual function non-narrow access modifier in derived class (#2229) 2020-01-01 16:09:43 +01:00
AUTHORS AUTHORS: added felwolff 2020-04-28 07:43:37 +02:00
CMakeLists.txt cleaned up setting of compiler options and a few more things in CMake (#2599) 2020-04-22 11:04:19 +02:00
COPYING
Makefile Run dmake 2020-04-19 11:17:59 +02:00
appveyor.yml compiling; you can put z3 files in externals/z3 2020-02-11 17:42:40 +01:00
benchmarks.txt
build-pcre.txt
build.bat
console_common.pri
cppcheck-errors.rng Improve specification of version attributes 2020-04-19 11:30:04 +02:00
cppcheck.cppcheck
cppcheck.sln Updated to Visual Studio 2019 2019-07-06 12:11:19 +02:00
createrelease createrelease: update daca@home 2019-12-21 20:11:00 +01:00
doxyfile
generate_coverage_report
naming.json Check for JSON error when parsing addon .json files + fixes (#2374) 2019-11-20 15:37:09 +01:00
philosophy.md
pylintrc_travis pylintrc_travis: Add check for bad-indentation, fix issues in misra.py (#2349) 2019-11-11 13:53:19 +01:00
readme.md Add badge for GitHub Actions 2020-03-28 16:04:36 +01:00
readme.txt compiling; you can put z3 files in externals/z3 2020-02-11 17:42:40 +01:00
readmeja.md Update readmeja (#2108) 2019-08-22 22:15:09 +02:00
requirements.txt Update pcre version since the link is broken (#2089) 2019-08-15 20:48:10 +02:00
runastyle Format rules files as well 2019-09-26 19:58:39 +02:00
runastyle.bat
webreport.sh

readme.md

Cppcheck

GitHub Actions Linux Build Status Windows Build Status OSS-Fuzz Coverity Scan Build Status License
Github Action Status Linux Build Status Windows Build Status OSS-Fuzz Coverity Scan Build Status License

About the name

The original name of this program was "C++check", but it was later changed to "Cppcheck".

Despite the name, Cppcheck is designed for both C and C++.

Manual

A manual is available online.

Donate CPU

Cppcheck is a hobby project with limited resources. You can help us by donating CPU (1 core or as many as you like). It is simple:

  1. Download (and extract) Cppcheck source code
  2. Run script: python cppcheck/tools/donate-cpu.py

The script will analyse debian source code and upload the results to a cppcheck server. We need these results both to improve Cppcheck and to detect regressions.

You can stop the script whenever you like with Ctrl C.

Compiling

Any C++11 compiler should work. For compilers with partial C++11 support it may work. If your compiler has the C++11 features that are available in Visual Studio 2013 / GCC 4.6 then it will work.

To build the GUI, you need Qt.

When building the command line tool, PCRE is optional. It is used if you build with rules.

There are multiple compilation choices:

  • qmake - cross platform build tool
  • cmake - cross platform build tool
  • Windows: Visual Studio (VS 2013 and above)
  • Windows: Qt Creator + mingw
  • gnu make
  • g++ 4.6 (or later)
  • clang++

cmake

Example, compiling Cppcheck with cmake:

mkdir build
cd build
cmake ..
cmake --build .

If you want to compile the GUI you can use the flag -DBUILD_GUI=ON

For rules support (requires pcre) use the flag -DHAVE_RULES=ON

For release builds it is recommended that you use: -DUSE_MATCHCOMPILER=ON

qmake

You can use the gui/gui.pro file to build the GUI.

cd gui
qmake
make

Visual Studio

Use the cppcheck.sln file. The file is configured for Visual Studio 2019, but the platform toolset can be changed easily to older or newer versions. The solution contains platform targets for both x86 and x64.

To compile with rules, select "Release-PCRE" or "Debug-PCRE" configuration. pcre.lib (pcre64.lib for x64 builds) and pcre.h are expected to be in /externals then. A current version of PCRE for Visual Studio can be obtained using vcpkg.

Qt Creator + MinGW

The PCRE dll is needed to build the CLI. It can be downloaded here: http://software-download.name/pcre-library-windows/

GNU make

Simple, unoptimized build (no dependencies):

make

The recommended release build is:

make MATCHCOMPILER=yes FILESDIR=/usr/share/cppcheck HAVE_RULES=yes CXXFLAGS="-O2 -DNDEBUG -Wall -Wno-sign-compare -Wno-unused-function"

Flags:

  1. MATCHCOMPILER=yes Python is used to optimise cppcheck. The Token::Match patterns are converted into C++ code at compile time.

  2. FILESDIR=/usr/share/cppcheck Specify folder where cppcheck files are installed (addons, cfg, platform)

  3. HAVE_RULES=yes Enable rules (PCRE is required if this is used)

  4. CXXFLAGS="-O2 -DNDEBUG -Wall -Wno-sign-compare -Wno-unused-function" Enables most compiler optimizations, disables cppcheck-internal debugging code and enables basic compiler warnings.

g++ (for experts)

If you just want to build Cppcheck without dependencies then you can use this command:

g++ -o cppcheck -std=c++11 -Iexternals -Iexternals/simplecpp -Iexternals/tinyxml -Ilib cli/*.cpp lib/*.cpp externals/simplecpp/simplecpp.cpp externals/tinyxml/*.cpp

If you want to use --rule and --rule-file then dependencies are needed:

g++ -o cppcheck -std=c++11 -lpcre -DHAVE_RULES -Ilib -Iexternals -Iexternals/simplecpp -Iexternals/tinyxml cli/*.cpp lib/*.cpp externals/simplecpp/simplecpp.cpp externals/tinyxml/*.cpp

MinGW

mingw32-make LDFLAGS=-lshlwapi

Other Compiler/IDE

  1. Create an empty project file / makefile.
  2. Add all cpp files in the cppcheck cli and lib folders to the project file / makefile.
  3. Add all cpp files in the externals folders to the project file / makefile.
  4. Compile.

Cross compiling Win32 (CLI) version of Cppcheck in Linux

sudo apt-get install mingw32
make CXX=i586-mingw32msvc-g++ LDFLAGS="-lshlwapi" RDYNAMIC=""
mv cppcheck cppcheck.exe

Webpage

http://cppcheck.sourceforge.net/