CodeClimate reporter
-r codeclimate (alias gitlab) writes the issue format GitLab reads for its Code Quality widget: each clone becomes an issue at each of its two locations, with a fingerprint that stays the same across pipelines, so a merge request lists which duplication it adds and which it removes. GitLab takes SARIF as security findings only; this reporter is how clones reach a merge request as quality issues. Available since jscpd 5.1.0.
Run it
jscpd . -r codeclimate --output report
CodeClimate report saved to report/gl-code-quality-report.json
{
"reporters": ["console", "codeclimate"],
"output": "report"
}
The output
The file is a JSON array of issues. One of them, from the repository's fixtures/mcp-demo folder scanned with --ignore-identifiers --ignore-literals --max-gap-lines 1:
{
"type": "issue",
"check_name": "jscpd/similar-code",
"description": "Duplicated code block (197 tokens), duplicated at src/print/invoice.js:1",
"categories": ["Duplication"],
"severity": "minor",
"fingerprint": "4b46d31b85a7ff81",
"location": {
"path": "src/invoice.js",
"lines": { "begin": 1, "end": 12 }
},
"other_locations": [
{
"path": "src/print/invoice.js",
"lines": { "begin": 1, "end": 13 }
}
]
}
| Field | Meaning |
|---|---|
check_name | The rule id of the clone's kind, the same as in SARIF: jscpd/duplicate-code, jscpd/renamed-code, jscpd/similar-code, jscpd/similar-function (5.4.0+) or jscpd/semantic-code (5.3.3+) |
description | The token count and the other copy's location |
severity | minor, or major under a gate (below) |
fingerprint | A hash of the pair's content, the path and the start line, so GitLab tells an existing issue from a new one across pipelines, and a file that duplicates itself gets two distinct issues |
location | The copy this issue is anchored at: a path relative to the scanned directory and a line range |
other_locations | The other copy; part of the CodeClimate specification, ignored by GitLab, kept for other consumers |
Every clone yields two issues, one anchored at each copy, so the widget annotates the duplication whichever side a merge request touches.
Where it shows up
Declare the file as a codequality report artifact. The Code Quality widget is available in every GitLab tier.
jscpd:
stage: test
image: node:22
before_script:
- npm install -g jscpd@5
script:
- jscpd . -r console,codeclimate --output report
artifacts:
when: always
reports:
codequality: report/gl-code-quality-report.json
The merge request then shows the duplication issues it adds and the ones it resolves against the target branch.
With gates
| Severity | When |
|---|---|
minor | The default |
major | The clone is new against --baseline or --baseline-from-ref, or the duplication of the run is above --threshold; then every issue is major |
The comparison with the threshold is strictly greater, the same one that fails the build. --kind keeps only the kinds you name.
Options
| Flag | Effect on the file |
|---|---|
-o, --output | The directory of gl-code-quality-report.json |
-t, --threshold P | Every issue at major when the run is above P |
--baseline, --baseline-from-ref | major for new clones |
-a, --absolute | Absolute paths in reports |
Related
- OpenMetrics reporter for the numbers of a run in a GitLab metrics report.
- CI for the GitLab pipeline with a baseline.
- Clone types for the kinds behind
check_name.
SARIF reporter
A SARIF 2.1.0 log with one result per clone, its counterpart as a related location and a stable fingerprint, for GitHub code scanning and other SARIF consumers.
OpenMetrics reporter
The counts of a run as OpenMetrics gauges, one sample per format, for GitLab metrics reports and Prometheus-style tooling.