整理 Flake8、mypy、ruff、Safety、pylint、Bandit 等质量与安全检查工具。

导航

收录来源

  • raw/langs/pythons/tools/checker.rst
  • raw/langs/pythons/tools/checkers/Flake8.rst
  • raw/langs/pythons/tools/checkers/mypy.rst
  • raw/langs/pythons/tools/checkers/ruff.rst
  • raw/langs/pythons/tools/checkers/Safety.rst
  • raw/langs/pythons/tools/checkers/pylint.rst
  • raw/langs/pythons/tools/checkers/Bandit.rst

条目内容

Flake8

  • 结合了 Pyflakes、pep8 和 McCabe 检查器的工具。
  • 用于检查 Python 代码中的语法错误、编码标准和代码复杂度。
  • 比 Pylint 更轻量,速度更快。

静态类型检查工具mypy

  • static type checker
  • Mypy 是一个用于 Python 的静态类型检查器。它可以帮助您在编写代码时发现错误,并使您的代码更易于阅读和维护。

主要功能

  • 类型检查: Mypy 可以检查您的代码是否符合您指定的类型注解。这可以帮助您发现潜在的错误,例如将字符串分配给数字变量。
  • 类型推断: Mypy 可以推断许多变量的类型,即使您没有为它们提供显式类型注解。这可以使您的代码更简洁易读。
  • 文档生成: Mypy 可以生成包含类型信息的文档。这可以帮助其他开发人员了解您的代码。
  • Type checkers help ensure that you’re using variables and functions in your code correctly. With mypy, add type hints (PEP 484) to your Python programs, and mypy will warn you when you use those types incorrectly.
  • Python is a dynamic language, so usually you’ll only see errors in your code when you attempt to run it. Mypy is a static checker, so it finds bugs in your programs without even running them!
  • Adding type hints for mypy does not interfere with the way your program would otherwise run. Think of type hints as similar to comments! You can always use the Python interpreter to run your code, even if mypy reports errors.
  • 官网: https://mypy.readthedocs.io/en/stable/getting_started.html
  • GitHub: https://github.com/python/mypy

ruff

安装:

pip install ruff

Usage

To run Ruff as a linter, try any of the following:

ruff check                          # Lint all files in the current directory (and any subdirectories).
ruff check path/to/code/            # Lint all files in `/path/to/code` (and any subdirectories).
ruff check path/to/code/*.py        # Lint all `.py` files in `/path/to/code`.
ruff check path/to/code/to/file.py  # Lint `file.py`.
ruff check @arguments.txt           # Lint using an input file, treating its contents as newline-delimited command-line arguments.

To run Ruff as a formatter:

ruff format                          # Format all files in the current directory (and any subdirectories).
ruff format path/to/code/            # Format all files in `/path/to/code` (and any subdirectories).
ruff format path/to/code/*.py        # Format all `.py` files in `/path/to/code`.
ruff format path/to/code/to/file.py  # Format `file.py`.
ruff format @arguments.txt           # Format using an input file, treating its contents as newline-delimited command-line arguments.

Ruff can also be used as a pre-commit hook via ruff-pre-commit:

- repo: https://github.com/astral-sh/ruff-pre-commit
  # Ruff version.
  rev: v0.4.4
  hooks:
    # Run the linter.
    - id: ruff
      args: [ --fix ]
    # Run the formatter.
    - id: ruff-format

Safety

  • 扫描你的Python依赖项以查找已知的安全漏洞。它检查已安装软件包的版本与漏洞数据库中的版本,并向你警告任何潜在的风险。

静态类型检查工具pylint

  • static type checker
  • PyLint 是一个用于 Python 代码的静态代码分析工具。它可以帮助您发现潜在的错误、代码风格问题和最佳实践违规行为。PyLint 可以提高您的代码质量,使其更易于阅读和维护。
  • 官网: https://pylint.readthedocs.io/en/latest/

主要功能

  • 代码分析: PyLint 可以分析您的代码以发现各种问题,包括语法错误、逻辑错误、重复代码、未使用变量和未使用的导入。
  • 代码风格检查: PyLint 可以检查您的代码是否符合 PEP 8 等代码风格指南。
  • 最佳实践建议: PyLint 可以建议您如何改进您的代码以遵循最佳实践。

安装:

pip install pylint

# check spelling with enchant
pip install pylint[spelling]

Bandit

  • 用于检测 Python 代码中的安全漏洞的工具。
  • 支持多种安全漏洞的检测,如 SQL 注入、命令注入等。