\\n\"\n}\n[/block]\n\n\n**Language / Framework:** Ruby/Rails \n**Checks:** 85 \n**Categories:** Security \n**Channels:** `stable`: Brakeman v4.3.1, Brakeman v6.0.1\n\n[Brakeman OSS](https://github.com/presidentbeef/brakeman) is a static analysis tool which checks Ruby on Rails applications for security vulnerabilities. \n\n## Enable the Plugin\n\nTo enable Brakeman analysis, add the following to your .codeclimate.yml configuration file:\n\n```yaml .codeclimate.yml\nplugins:\n brakeman:\n enabled: true\n```\n\n**More information about the CLI is available in the README here: **\n\n## Brakeman versions\n\nTo use a newer version of Brakeman (v6.0.1), specify the `brakeman-6-0-1` channel within your .codeclimate.yml configuration file:\n\n```yaml .codeclimate.yml\nplugins:\n brakeman:\n channel: brakeman-6-0-1\n enabled: true\n```\n\n## Configure the Plugin\n\nThe Brakeman engine supports Brakeman configuration files (and ignore files) as described in the Brakeman documentation.\n\n## Sub-Directory Support\n\n> 🚧 Sub-directory Support\n> \n> If your application exists in a sub-directory, you can specify the sub-directory as an \"app_path\" in your config block. For example, if your rails app lives at \"app/our_repo/\", you would specify the following in your .codeclimate.yml:\n\n```yaml .codeclimate.yml\nplugins:\n brakeman:\n enabled: true\n config:\n app_path: app/our_repo\n```\n\n## Understand the Plugin\n\nConsult the official Brakeman documentation for more information about Brakeman analysis.","order":2,"isReference":false,"deprecated":false,"hidden":false,"sync_unique":"","link_url":"","link_external":false,"reusableContent":[],"previousSlug":"","slugUpdatedAt":"2022-11-18T12:03:53.957Z","revision":11,"_id":"57e17235463a9120006d6eb5","createdAt":"2015-11-23T23:08:11.051Z","parentDoc":null,"project":"57e17235463a9120006d6e7d","category":"57e17235463a9120006d6e81","__v":2,"user":"6802655ea0c31b0038c71658","githubsync":"","version":"57e17235463a9120006d6e7f","updatedAt":"2025-04-30T15:41:20.953Z","pendingAlgoliaPublish":false,"lastUpdatedHash":"040aa1c3cb406db2f0b226e9d3b407685a934025","isApi":false,"id":"57e17235463a9120006d6eb5"},"meta":{"slug":"brakeman","type":"docs","parent":null,"image":[],"title":"Brakeman OSS","title_seo":"Brakeman OSS","description":"⚠️ Code Climate Quality is being replaced with Qlty Cloud — New users should sign up directly at qlty.sh.— To migrate an existing account, please see our Migration Guide. Language / Framework: Ruby/RailsChecks: 85Categories: SecurityChannels: stable: Brakeman v4.3.1, Brakeman v6.0.1 Brakeman OSS is ...","_id":"57e17235463a9120006d6eb5","hidden":false},"config":{"algoliaIndex":"readme_search_v2","amplitude":{"apiKey":"dc8065a65ef83d6ad23e37aaf014fc84","enabled":true},"asset_url":"https://cdn.readme.io","domain":"readme.io","domainFull":"https://dash.readme.com","encryptedLocalStorageKey":"ekfls-2025-03-27","fullstory":{"enabled":true,"orgId":"FSV9A"},"metrics":{"billingCronEnabled":"true","dashUrl":"https://m.readme.io","defaultUrl":"https://m.readme.io","exportMaxRetries":12,"wsUrl":"wss://m.readme.io"},"proxyUrl":"https://try.readme.io","readmeRecaptchaSiteKey":"6LesVBYpAAAAAESOCHOyo2kF9SZXPVb54Nwf3i2x","releaseVersion":"5.396.0","sentry":{"dsn":"https://3bbe57a973254129bcb93e47dc0cc46f@o343074.ingest.sentry.io/2052166","enabled":true},"shMigration":{"promoVideo":"","forceWaitlist":false,"migrationPreview":false},"sslBaseDomain":"readmessl.com","sslGenerationService":"ssl.readmessl.com","stripePk":"pk_live_5103PML2qXbDukVh7GDAkQoR4NSuLqy8idd5xtdm9407XdPR6o3bo663C1ruEGhXJjpnb2YCpj8EU1UvQYanuCjtr00t1DRCf2a","superHub":{"newProjectsEnabled":true},"wootric":{"accountToken":"NPS-122b75a4","enabled":true}},"context":{"labs":{},"user":{},"terms":[],"variables":{"user":{},"defaults":[]},"project":{"_id":"57e17235463a9120006d6e7d","appearance":{"hideTableOfContents":false,"javascript":"","showVersion":true,"header":{"img_pos":"tl","img_size":"auto","img":[],"style":"solid","linkStyle":"buttons"},"hide_logo":true,"html_footer":"","logo":["https://files.readme.io/XZInkgKTAerd7E4rjoUh_code-climate-logo.png","code-climate-logo.png","280","80","#241c24","https://files.readme.io/2ElCNFp1SWLds6tdHhFX_code-climate-logo.png"],"promos":[{"extras":{"type":"html","buttonPrimary":"get-started","buttonSecondary":""},"title":"Code Climate Quality Documentation","text":"","_id":"5653462e0672922b003be690"}],"html_footer_meta":"","html_promo":"\n
\n \n\n
\n \n
\n ⚠️\n Code Climate Quality is being replaced with Qlty Cloud\n
\n \n
\n
\n — New users should sign up directly at qlty.sh\n
\n
\n — To migrate an existing account, please see our Migration Guide\n
\n
\n \n
\n\n\n
\n
\n
\n\n\n Need help with Code Climate Quality?Look no further.\n