SpotBugs
Metrics as of , from the GitHub or GitLab API of each repository. Refreshed monthly.
What SpotBugs is
SpotBugs is a program that uses static analysis to find bugs in Java code. It continues the FindBugs project with community maintenance. Running it requires a JRE or JDK 11 or later. It can still analyze code compiled for older Java versions. It runs standalone or through integrations with Ant, Maven, Gradle and Eclipse. The README also lists integrations for SonarQube, IntelliJ IDEA and VS Code. Plugins can add new detectors, and community plugins such as find-sec-bugs extend the checks.
Written from the project's README, read , and its documentation (see sources).
- Category
- Code quality and static analysis
- License
- LGPL-2.1
- Language
- Java
- Changelog
- Releases on GitHub
Repository metrics
Status
activeLast commit within 90 days of the fetch date.Computed from the last commit date and the archive flag on the fetch date. See the status rules.
Alternatives
Listed code quality and static analysis tools, same primary language first, then by GitHub stars. Each line gives one fact from the tool's documentation where it differs from SpotBugs's, with its source.
SonarQube: Languages or files analysed: Java, JavaScript, TypeScript, Python, C#, Go, PHP, Kotlin and other language pages; IaC files such as Docker, Kubernetes, Terraform. source: Docs: Supported languages
Checkstyle: Languages or files analysed: Java source code. source: Docs: Checkstyle home
Ruff: Languages or files analysed: Python files (*.py, *.pyi), Jupyter Notebooks (*.ipynb) and pyproject.toml. source: Docs: Configuring Ruff
ShellCheck: Languages or files analysed: Shell scripts in the sh, bash, dash, ksh and BusyBox dialects. source: Docs: shellcheck(1) manual
ESLint: Languages or files analysed: ECMAScript/JavaScript code; JSX parsing when enabled. source: README
mypy: Languages or files analysed: Python programs with type hints. source: README
golangci-lint: Languages or files analysed: Go code. source: README
Semgrep: Languages or files analysed: Community supported in Semgrep CE: C/C++, C#, Go, Java, JavaScript, TypeScript, Kotlin, Python, Ruby, Rust, PHP, Scala, Swift, Terraform. source: Docs: Supported languages for Semgrep Community Edition (CE)
Questions
Is SpotBugs open source?
Yes. SpotBugs is released under LGPL-2.1, an OSI-approved license, as reported by the GitHub API on 2026-09-22.
Is SpotBugs maintained?
On 2026-09-22, the last commit to the default branch was on 2026-09-19, so the listed status is active. Rule: Last commit within 90 days of the fetch date.
How many GitHub stars does SpotBugs have?
3,946 stars on 2026-09-22, from the GitHub API. The number is refreshed at each monthly update.
What language is SpotBugs written in?
The repository's primary language, as reported by the GitHub API, is Java.
Sources
- GitHub REST API: repository, read
- GitHub REST API: commits, read
- GitHub REST API: latest release, read
- GitHub REST API: contributors, read
- README, read
- SpotBugs homepage, read