Brakeman OSS


Language / Framework: Ruby/Rails
Checks: 85
Categories: Security
Channels: stable: Brakeman v4.3.1, beta: Brakeman v5.3.1

Brakeman OSS is a static analysis tool which checks Ruby on Rails applications for security vulnerabilities.


  • Brakeman has asked that we direct all feedback around this issue to [email protected]. They'll be able to provide some further context on when we'll be able to update the Brakeman plugin on

Enable the Plugin

To enable Brakeman analysis, add the following to your .codeclimate.yml configuration file:

    enabled: true

More information about the CLI is available in the README here:

Configure the Plugin

The Brakeman engine supports Brakeman configuration files (and ignore files) as described in the Brakeman documentation.

Sub-Directory Support


Sub-directory Support

If your application exists in a sub-directory, you can specify the sub-directory as an "app_path" in your config block. For example, if your rails app lives at "app/our_repo/", you would specify the following in your .codeclimate.yml:

    enabled: true
        app_path: app/our_repo

Understand the Plugin

Consult the official Brakeman documentation for more information about Brakeman analysis.