Skip to main content
This reference is generated automatically. Last updated: October 6, 2026
CodeRabbit supports integration with 59 static analysis tools, linters, and security scanners. You can configure each tool individually via the web interface or your .coderabbit.yaml file, see the configuration overview for details.

All tools

actionlint is a static checker for GitHub Actions workflow files.Version: v1.7.12Configuration options:
boolean
Enable actionlintDefaults to true.
Example configuration:
.coderabbit.yaml
ast-grep is a code analysis tool that helps you to find patterns in your codebase using abstract syntax trees patterns.Version: v0.45.3Configuration options:
boolean
Enable ast-grepDefaults to true.
array of string
List of rules directories.Defaults to [].
array of string
List of utils directories.Defaults to [].
boolean
Use ast-grep essentials package.Defaults to true.
array of string
Predefined packages to be used.Defaults to [].
Example configuration:
.coderabbit.yaml
Biome is a fast formatter, linter, and analyzer for web projects.Version: v2.5.13Configuration options:
boolean
Enable BiomeDefaults to true.
Example configuration:
.coderabbit.yaml
Blinter is a linter for Windows batch files that provides comprehensive static analysis to identify syntax errors, security vulnerabilities, performance issues, and style problems.Version: v1.1.27Configuration options:
boolean
Enable BlinterDefaults to true.
Example configuration:
.coderabbit.yaml
Brakeman is a static analysis security vulnerability scanner for Ruby on Rails applications.Version: v8.0.6Configuration options:
boolean
Enable BrakemanDefaults to true.
Example configuration:
.coderabbit.yaml
Buf offers linting for Protobuf files.Version: v1.73.0Configuration options:
boolean
Enable BufDefaults to true.
Example configuration:
.coderabbit.yaml
checkmake is a linter for Makefiles.Version: v0.3.2Configuration options:
boolean
Enable checkmakeDefaults to true.
Example configuration:
.coderabbit.yaml
Checkov is a static code analysis tool for infrastructure-as-code files.Version: v3.3.17Configuration options:
boolean
Enable CheckovDefaults to true.
Example configuration:
.coderabbit.yaml
CircleCI tool is a static checker for CircleCI config files.Version: v1.0.50462Configuration options:
boolean
Enable CircleCIDefaults to true.
Example configuration:
.coderabbit.yaml
Configuration for Clang to perform static analysis on C and C++ codeVersion: v14.0.6Configuration options:
boolean
Enable Clang for C/C++ static analysis and code quality checksDefaults to true.
Example configuration:
.coderabbit.yaml
Clippy is a collection of lints to catch common mistakes and improve your Rust code.Configuration options:
boolean
Enable ClippyDefaults to true.
Example configuration:
.coderabbit.yaml
Cppcheck is a static code analysis tool for the C and C++ programming languages.Version: v2.21.0Configuration options:
boolean
Enable CppcheckDefaults to true.
Example configuration:
.coderabbit.yaml
Detekt is a static code analysis tool for Kotlin files.Version: v1.23.8Configuration options:
boolean
Enable detekt: detekt is a static code analysis tool for Kotlin files.Defaults to true.
string
Optional path to the detekt configuration file relative to the repository.
Example configuration:
.coderabbit.yaml
dotenv-linter is a tool for checking and fixing .env files for problems and best practicesVersion: v4.0.0Configuration options:
boolean
Enable dotenv-linterDefaults to true.
Example configuration:
.coderabbit.yaml
ember-template-lint is a linter for Handlebars template files that checks for common issues such as accessibility violations, deprecated patterns, and template anti-patterns.Version: v7.9.3Configuration options:
boolean
Enable ember-template-lintDefaults to true.
Example configuration:
.coderabbit.yaml
ESLint is a static code analysis tool for JavaScript files.Configuration options:
boolean
Enable ESLintDefaults to true.
string
Optional path to an ESLint configuration file relative to the repository. When set, this configuration is used for every file instead of discovering ESLint configurations recursively.
object
@e18e/eslint-plugin modernization, performance, and dependency replacement checks.
Example configuration:
.coderabbit.yaml
Flake8 is a Python linter that wraps PyFlakes, pycodestyle and Ned Batchelder’s McCabe script.Version: v7.3.0Configuration options:
boolean
Enable Flake8Defaults to true.
Example configuration:
.coderabbit.yaml
Fortitude is a Fortran linter that checks for code quality and style issues.Version: v0.9.2Configuration options:
boolean
Enable Fortitude: Fortitude is a Fortran linter that checks for code quality and style issuesDefaults to true.
Example configuration:
.coderabbit.yaml
GitHub Checks integration configuration.Configuration options:
boolean
Enable GitHub Checks: Enable integration, defaults to trueDefaults to true.
Example configuration:
.coderabbit.yaml
Betterleaks is a secret scanner (an improved version of Gitleaks).Version: v1.8.1Configuration options:
boolean
Enable BetterleaksDefaults to true.
Example configuration:
.coderabbit.yaml
golangci-lint is a fast linters runner for Go.Version: v2.13.2Configuration options:
boolean
Enable golangci-lintDefaults to true.
string
Optional path to the golangci-lint configuration file relative to the repository. Useful when the configuration file is named differently than the default ‘.golangci.yml’, ‘.golangci.yaml’, ‘.golangci.toml’, ‘.golangci.json’.
Example configuration:
.coderabbit.yaml
Hadolint is a Dockerfile linter.Version: v2.15.1Configuration options:
boolean
Enable HadolintDefaults to true.
Example configuration:
.coderabbit.yaml
HTMLHint is a static code analysis tool for HTML files.Version: v1.9.2Configuration options:
boolean
Enable HTMLHintDefaults to true.
Example configuration:
.coderabbit.yaml
Configuration for Infer to find bugs in Java and C/C++ codeVersion: v1.3.0Configuration options:
boolean
Enable Infer for static bug analysis in Java and C/C++ codeDefaults to true.
boolean
Enable Java analysis: Disabled by default because Java analysis may require compiling more than the changed files.Defaults to false.
Example configuration:
.coderabbit.yaml
LanguageTool is a style and grammar checker for 30+ languages.Configuration options:
boolean
Enable LanguageTool: Enable LanguageTool integration.Defaults to true.
array of string
IDs of rules to be enabled. The rule won’t run unless ‘level’ is set to a level that activates the rule.Defaults to [].
array of string
IDs of rules to be disabled. Note: EN_UNPAIRED_BRACKETS, and EN_UNPAIRED_QUOTES are always disabled.Defaults to [].
array of string
IDs of categories to be enabled.Defaults to [].
array of string
IDs of categories to be disabled. Note: TYPOS, TYPOGRAPHY, and CASING are always disabled.Defaults to [].
boolean
Run only the rules and categories listed in enabled_rules or enabled_categories, instead of the default set.Defaults to false.With enabled_only: true, at least one rule or category is required. If both lists are empty, CodeRabbit skips LanguageTool and reports an error.
enum
If set to ‘picky’, additional rules will be activated, i.e. rules that you might only find useful when checking formal text.One of: default, pickyDefaults to "default".
Example configuration:
.coderabbit.yaml
Configuration for Lua code linting to ensure code qualityVersion: v1.2.0Configuration options:
boolean
Enable Lua code linting: Luacheck helps maintain consistent and error-free Lua codeDefaults to true.
Example configuration:
.coderabbit.yaml
markdownlint-cli2 is a static analysis tool to enforce standards and consistency for Markdown files.Version: v0.23.2Configuration options:
boolean
Enable markdownlintDefaults to true.
Example configuration:
.coderabbit.yaml
oasdiff detects breaking changes between OpenAPI specifications.Version: v1.32.1Configuration options:
boolean
Enable oasdiffDefaults to true.
Example configuration:
.coderabbit.yaml
OpenGrep is a high-performance static code analysis engine, compatible with Semgrep configurations.Version: v1.30.0Configuration options:
boolean
Enable OpenGrep: OpenGrep is a high-performance static code analysis engine for finding security vulnerabilities and bugs across 17+ languages.Defaults to true.
Example configuration:
.coderabbit.yaml
OSV Scanner is a tool for vulnerability package scanning.Version: v2.6.0Configuration options:
boolean
Enable OSV Scanner: OSV Scanner is a tool for vulnerability package scanningDefaults to true.
Example configuration:
.coderabbit.yaml
Oxlint is a JavaScript/TypeScript linter for OXC written in Rust.Version: v1.83.0Configuration options:
boolean
Enable OxlintDefaults to true.
Example configuration:
.coderabbit.yaml
PHP CodeSniffer is a PHP linter and coding standard checker.Version: v3.13.6Configuration options:
boolean
Enable PHP CodeSnifferDefaults to true.
Example configuration:
.coderabbit.yaml
PHPMD is a tool to find potential problems in PHP code.Version: v2.15.0Configuration options:
boolean
Enable PHPMDDefaults to true.
Example configuration:
.coderabbit.yaml
PHPStan is a tool to analyze PHP code.Version: v2.2.14Configuration options:
boolean
Enable PHPStan: PHPStan requires config file in your repository root. Please ensure that this file contains the paths: parameter.Defaults to true.
enum
Level: Specify the rule level to run. When set to default, the level is determined by the review profile: chill uses level 3 (real bugs only — return/property type mismatches, array offset errors) and assertive uses level 8 (adds dead code detection, argument type checking, null safety, and typehint checks). This setting is ignored if your configuration file already has a level: parameter.One of: 0, 1, 2, 3, 4, 5, 6, 7, 8, 9, default, maxDefaults to "default".
Example configuration:
.coderabbit.yaml
PMD is an extensible multilanguage static code analyzer. It’s mainly concerned with Java.Version: v7.27.0Configuration options:
boolean
Enable PMDDefaults to true.
string
Optional path to the PMD configuration file relative to the repository.
Example configuration:
.coderabbit.yaml
Microsoft Presidio Analyzer 2.2.364 detects sensitive identifiers (including payment cards, US SSN, cryptocurrency wallets, and phone numbers) in changed files. Tune entities, thresholds, and languages in repository Presidio configuration (for example .presidiocli or AnalyzerEngineProvider YAML); the built-in scan uses fixed defaults and is skipped when that configuration is present.Version: v2.2.364Configuration options:
boolean
Enable Microsoft Presidio Analyzer for high-signal PII in changed filesDefaults to true.
Example configuration:
.coderabbit.yaml
Configuration for Prisma Schema linting to ensure schema file qualityVersion: v0.13.1Configuration options:
boolean
Enable Prisma Schema linting: Prisma Schema linting helps maintain consistent and error-free schema filesDefaults to true.
Example configuration:
.coderabbit.yaml
PSScriptAnalyzer is a static code checker for PowerShell scripts and modules.Version: v1.25.0Configuration options:
boolean
Enable PSScriptAnalyzerDefaults to true.
Example configuration:
.coderabbit.yaml
Pylint is a Python static code analysis tool.Version: v4.0.8Configuration options:
boolean
Enable PylintDefaults to true.
Example configuration:
.coderabbit.yaml
React Doctor scans React codebases for security, performance, correctness, and accessibility issues.Version: v0.9.14Configuration options:
boolean
Enable React DoctorDefaults to true.
Example configuration:
.coderabbit.yaml
Regal is a linter and language server for Rego.Version: v0.42.0Configuration options:
boolean
Enable RegalDefaults to true.
Example configuration:
.coderabbit.yaml
RuboCop is a Ruby static code analyzer (a.k.a. linter ) and code formatter.Version: v1.91.0Configuration options:
boolean
Enable RuboCopDefaults to true.
Example configuration:
.coderabbit.yaml
Ruff is a Python linter and code formatter.Version: v0.16.7Configuration options:
boolean
Enable RuffDefaults to true.
string
Optional path to a Ruff configuration file relative to the repository. When set, this configuration is used for every reviewed file instead of Ruff’s closest-config discovery.
Example configuration:
.coderabbit.yaml
Semgrep is a static analysis tool designed to scan code for security vulnerabilities and code quality issues.Version: v1.177.0Configuration options:
boolean
Enable SemgrepDefaults to true.
string
Optional path to the Semgrep configuration file relative to the repository.
Example configuration:
.coderabbit.yaml
ShellCheck is a static analysis tool that finds bugs in your shell scripts.Version: v0.11.0Configuration options:
boolean
Enable ShellCheck: ShellCheck is a static analysis tool that finds bugs in your shell.Defaults to true.
Example configuration:
.coderabbit.yaml
Configuration for Shopify Theme Check to ensure theme quality and best practicesVersion: cli 4.8.0, theme 3.58.2Configuration options:
boolean
Enable Shopify Theme Check: A linter for Shopify themes that helps you follow Shopify theme & Liquid best practicesDefaults to true.
Example configuration:
.coderabbit.yaml
SkillSpector is a security scanner for AI agent skills that detects vulnerabilities, malicious patterns, and security risksVersion: v2.11.2Configuration options:
boolean
Enable SkillSpector: SkillSpector is a security scanner for AI agent skills. It detects vulnerabilities, malicious patterns, and security risks in SKILL.md manifests and MCP configurations.Defaults to true.
Example configuration:
.coderabbit.yaml
smarty-lint is a linter for Smarty 3 template files that checks for common issues such as incorrect operator usage, naming conventions, empty blocks, and unquoted strings.Version: v0.3.3Configuration options:
boolean
Enable smarty-lintDefaults to true.
Example configuration:
.coderabbit.yaml
SQLFluff is an open source, dialect-flexible and configurable SQL linter.Version: v4.3.0Configuration options:
boolean
Enable SQLFluffDefaults to true.
string
Optional path to the SQLFluff configuration file relative to the repository. Use this when the config file is not named one of SQLFluff’s default filenames.
Example configuration:
.coderabbit.yaml
Configuration for Squawk to lint Postgres migrations and SQL for safe schema changesVersion: v2.65.0Configuration options:
boolean
Enable Squawk for Postgres migration linting: Detects unsafe schema changes that can cause downtime or blocking locksDefaults to true.
Example configuration:
.coderabbit.yaml
Stylelint is a linter for stylesheets (CSS, SCSS, Sass, Less, SugarSS, Stylus) that helps avoid errors and enforce conventions.Version: v17.14.0Configuration options:
boolean
Enable StylelintDefaults to true.
Example configuration:
.coderabbit.yaml
SwiftLint integration configuration object.Version: v0.65.1Configuration options:
boolean
Enable SwiftLint: SwiftLint is a Swift linter.Defaults to true.
string
Optional path to the SwiftLint configuration file relative to the repository. This is useful when the configuration file is named differently than the default ‘.swiftlint.yml’ or ‘.swiftlint.yaml’.
Example configuration:
.coderabbit.yaml
TFLint is a Terraform linter for finding potential errors and enforcing best practices.Version: v0.64.0Configuration options:
boolean
Enable TFLint: TFLint is a Terraform linter for finding potential errors.Defaults to true.
Example configuration:
.coderabbit.yaml
Trivy is a comprehensive security scanner that detects misconfigurations and secrets in Infrastructure as Code filesVersion: v0.74.0Configuration options:
boolean
Enable Trivy for security scanning of IaC files (Terraform, Kubernetes, Docker, etc.)Defaults to true.
Example configuration:
.coderabbit.yaml
TruffleHog is a secret scanner with verification capabilities that can detect and verify secrets in code.Version: v3.96.0Configuration options:
boolean
Enable TruffleHog: TruffleHog is a secret scanner with verification capabilities.Defaults to true.
Example configuration:
.coderabbit.yaml
Vale lints prose using the repository’s checked-in style rules.Version: v3.21.0Configuration options:
boolean
Enable Vale: Vale checks prose against repository-defined editorial style rules. It runs only when a supported root Vale configuration is present.Defaults to true.
Example configuration:
.coderabbit.yaml
Verilator statically analyzes Verilog and SystemVerilog source files.Version: v5.052Configuration options:
boolean
Enable Verilator: Verilator lints Verilog and SystemVerilog for syntax, width, connectivity, and behavioral correctness issues.Defaults to true.
Example configuration:
.coderabbit.yaml
YAMLlint is a linter for YAML files.Version: v1.37.1Configuration options:
boolean
Enable YAMLlintDefaults to true.
Example configuration:
.coderabbit.yaml
zizmor is a static security analyzer for GitHub Actions workflow files.Version: v1.30.1Configuration options:
boolean
Enable zizmorDefaults to true.
Example configuration:
.coderabbit.yaml

What’s next

Configuration reference

View the complete reference for all CodeRabbit configuration options and settings.

Review commands

Learn how to control and customize code reviews using @coderabbitai commands.