Skip to main content

Summary

FeatureStatusNotes
Maintainability✔Complexity, duplication, code smells
Linting✔
Auto-formatting✔
Custom checks✔
Security scanning✔AppSec, dependencies, and secrets
Code metrics✔
Code coverage✔

Details

Maintainability
Complexity✔Aka cognitive complexity
Cyclomatic complexity✔
Identical code duplication✔
Similar code duplication✔
Code smells✔
Linters
RuboCop✔Ruby static code analyzer and formatter
Reek✔Code smell detector for Ruby
StandardRB✔Ruby style guide, linter, and formatter
Brakeman✔Static analysis security vulnerability scanner
Auto-formatters
RuboCop✔Includes formatting capabilities
StandardRB✔Zero-config Ruby formatter
Custom checks
ast-grep✔
Semgrep✔
ripgrep✔
Security scanning
Brakeman✔AppSec (SAST) for Ruby on Rails applications
Gitleaks✔Secrets scanning
OSV-Scanner✔Dependency scanning (SCA)
Semgrep✔AppSec (SAST)
Trivy✔Dependency scanning (SCA)
TruffleHog✔Secrets scanning
Code coverage
SimpleCov✔
Cobertura coverage format✔
JSON coverage format✔

File extensions

By default, Ruby files are defined as:
These patterns can be overridden from qlty.toml.

Code coverage setup

QLTY supports code coverage for Ruby through SimpleCov. For a full working example, see our example Ruby repository.

SimpleCov configuration

To instrument test coverage with SimpleCov:
  1. Install SimpleCov:
  1. Configure SimpleCov to generate JSON reports:
If you want to combine the JSON format with other formats, use SimpleCov’s MultiFormatter:
  1. Publish SimpleCov’s JSON coverage reports using qlty coverage publish:
For GitHub Actions users, you can use our example workflow.

Supported Ruby versions

We officially support Ruby 2.5 and later for maintainability checks and code coverage. SimpleCov version 0.22.0+ is recommended for code coverage. Each plugin may have its own version requirements.