{"id":39933421,"url":"https://github.com/joshmfrankel/simplecov-check-action","last_synced_at":"2026-01-18T18:32:00.775Z","repository":{"id":37776243,"uuid":"460966973","full_name":"joshmfrankel/simplecov-check-action","owner":"joshmfrankel","description":"SimpleCov+ Action","archived":false,"fork":false,"pushed_at":"2025-09-17T18:55:42.000Z","size":216,"stargazers_count":45,"open_issues_count":5,"forks_count":18,"subscribers_count":1,"default_branch":"main","last_synced_at":"2025-10-26T13:37:06.900Z","etag":null,"topics":["coverage","ruby"],"latest_commit_sha":null,"homepage":"","language":"Ruby","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"mit","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/joshmfrankel.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null}},"created_at":"2022-02-18T18:41:29.000Z","updated_at":"2025-10-24T13:48:40.000Z","dependencies_parsed_at":"2024-05-29T14:34:39.211Z","dependency_job_id":"40b1e919-6585-4d9c-af3e-0030fd7acc57","html_url":"https://github.com/joshmfrankel/simplecov-check-action","commit_stats":{"total_commits":34,"total_committers":1,"mean_commits":34.0,"dds":0.0,"last_synced_commit":"80bff9575301ca82742eac01efb49afbddaee626"},"previous_names":[],"tags_count":3,"template":false,"template_full_name":null,"purl":"pkg:github/joshmfrankel/simplecov-check-action","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/joshmfrankel%2Fsimplecov-check-action","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/joshmfrankel%2Fsimplecov-check-action/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/joshmfrankel%2Fsimplecov-check-action/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/joshmfrankel%2Fsimplecov-check-action/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/joshmfrankel","download_url":"https://codeload.github.com/joshmfrankel/simplecov-check-action/tar.gz/refs/heads/main","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/joshmfrankel%2Fsimplecov-check-action/sbom","scorecard":{"id":534188,"data":{"date":"2025-08-11","repo":{"name":"github.com/joshmfrankel/simplecov-check-action","commit":"0743d75f9c88262f651e1ec402bbd3d586f6e7ac"},"scorecard":{"version":"v5.2.1-40-gf6ed084d","commit":"f6ed084d17c9236477efd66e5b258b9d4cc7b389"},"score":4.8,"checks":[{"name":"Code-Review","score":1,"reason":"Found 4/28 approved changesets -- score normalized to 1","details":null,"documentation":{"short":"Determines if the project requires human code review before pull requests (aka merge requests) are merged.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#code-review"}},{"name":"Maintained","score":0,"reason":"0 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 0","details":null,"documentation":{"short":"Determines if the project is \"actively maintained\".","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#maintained"}},{"name":"Binary-Artifacts","score":10,"reason":"no binaries found in the repo","details":null,"documentation":{"short":"Determines if the project has generated executable (binary) artifacts in the source repository.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#binary-artifacts"}},{"name":"Packaging","score":-1,"reason":"packaging workflow not detected","details":["Warn: no GitHub/GitLab publishing workflow detected."],"documentation":{"short":"Determines if the project is published as a package that others can easily download, install, easily update, and uninstall.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#packaging"}},{"name":"Dangerous-Workflow","score":10,"reason":"no dangerous workflow patterns detected","details":null,"documentation":{"short":"Determines if the project's GitHub Action workflows avoid dangerous patterns.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#dangerous-workflow"}},{"name":"Token-Permissions","score":9,"reason":"detected GitHub workflow tokens with excessive permissions","details":["Warn: no topLevel permission defined: .github/workflows/testing.yml:1","Info: no jobLevel write permissions found"],"documentation":{"short":"Determines if the project's workflows follow the principle of least privilege.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#token-permissions"}},{"name":"CII-Best-Practices","score":0,"reason":"no effort to earn an OpenSSF best practices badge detected","details":null,"documentation":{"short":"Determines if the project has an OpenSSF (formerly CII) Best Practices Badge.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#cii-best-practices"}},{"name":"Security-Policy","score":0,"reason":"security policy file not detected","details":["Warn: no security policy file detected","Warn: no security file to analyze","Warn: no security file to analyze","Warn: no security file to analyze"],"documentation":{"short":"Determines if the project has published a security policy.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#security-policy"}},{"name":"Fuzzing","score":0,"reason":"project is not fuzzed","details":["Warn: no fuzzer integrations found"],"documentation":{"short":"Determines if the project uses fuzzing.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#fuzzing"}},{"name":"Pinned-Dependencies","score":0,"reason":"dependency not pinned by hash detected -- score normalized to 0","details":["Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/testing.yml:18: update your workflow using https://app.stepsecurity.io/secureworkflow/joshmfrankel/simplecov-check-action/testing.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/testing.yml:21: update your workflow using https://app.stepsecurity.io/secureworkflow/joshmfrankel/simplecov-check-action/testing.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/testing.yml:31: update your workflow using https://app.stepsecurity.io/secureworkflow/joshmfrankel/simplecov-check-action/testing.yml/main?enable=pin","Warn: containerImage not pinned by hash: Dockerfile:1: pin your Docker image by updating ruby:3.1.0-alpine to ruby:3.1.0-alpine@sha256:0602d61c893480f4cd05c1941459e371e2d30ff82203fd3dabaaf2358f301894","Info:   0 out of   1 GitHub-owned GitHubAction dependencies pinned","Info:   0 out of   2 third-party GitHubAction dependencies pinned","Info:   0 out of   1 containerImage dependencies pinned"],"documentation":{"short":"Determines if the project has declared and pinned the dependencies of its build process.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#pinned-dependencies"}},{"name":"License","score":10,"reason":"license file detected","details":["Info: project has a license file: LICENSE:0","Info: FSF or OSI recognized license: MIT License: LICENSE:0"],"documentation":{"short":"Determines if the project has defined a license.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#license"}},{"name":"Signed-Releases","score":-1,"reason":"no releases found","details":null,"documentation":{"short":"Determines if the project cryptographically signs release artifacts.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#signed-releases"}},{"name":"Vulnerabilities","score":10,"reason":"0 existing vulnerabilities detected","details":null,"documentation":{"short":"Determines if the project has open, known unfixed vulnerabilities.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#vulnerabilities"}},{"name":"Branch-Protection","score":-1,"reason":"internal error: error during branchesHandler.setup: internal error: githubv4.Query: Resource not accessible by integration","details":null,"documentation":{"short":"Determines if the default and release branches are protected with GitHub's branch protection settings.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#branch-protection"}},{"name":"SAST","score":0,"reason":"SAST tool is not run on all commits -- score normalized to 0","details":["Warn: 0 commits out of 9 are checked with a SAST tool"],"documentation":{"short":"Determines if the project uses static code analysis.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#sast"}}]},"last_synced_at":"2025-08-20T06:31:00.630Z","repository_id":37776243,"created_at":"2025-08-20T06:31:00.631Z","updated_at":"2025-08-20T06:31:00.631Z"},"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":28547205,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-01-18T14:59:57.589Z","status":"ssl_error","status_checked_at":"2026-01-18T14:59:46.540Z","response_time":98,"last_error":"SSL_read: unexpected eof while reading","robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":false,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["coverage","ruby"],"created_at":"2026-01-18T18:32:00.680Z","updated_at":"2026-01-18T18:32:00.771Z","avatar_url":"https://github.com/joshmfrankel.png","language":"Ruby","funding_links":[],"categories":[],"sub_categories":[],"readme":"# SimpleCov+ Action\n\nA Github check action which displays failing test coverage from SimpleCov while providing the option\nto fail a build based on minimum coverage threshold.\n\n![Github PR Check UI](img/simple-cov-check-basic.png)\n\nWant to see more examples of this check in action? :wink: See [screenshots.md](/screenshots.md)\n\n## Basic Installation\nIn order for SimpleCov+ Action to function properly, you first need the simplecov gem. See [Getting Started](https://github.com/simplecov-ruby/simplecov#getting-started).\n\nAssuming you've followed the guide above (you have the gem in your Gemfile and have properly setup test_helper.rb), then the only other step is to utilize the Github action within your workflow.\n\n```yml\n  # However you run your tests to generate code coverage\n  - name: Run my tests\n    run: |\n      bundle exec rspec specs/\n\n  # Minimum configuration\n  - uses: joshmfrankel/simplecov-check-action@main\n    with:\n      github_token: ${{ secrets.GITHUB_TOKEN }}\n```\n\n## Configuration Options\nSee [https://github.com/joshmfrankel/simplecov-check-action/blob/main/action.yml](https://github.com/joshmfrankel/simplecov-check-action/blob/main/action.yml) for all available options and their defaults.\n\nMost useful is the **minimum_suite_coverage** option as it allows specification as to the value at which a failure result should be produced.\n\n## Advanced Installation\nThe advanced installation switches the coverage failing mode from **overall test coverage** to **per file coverage**. This is similiar to the `minimum_coverage_by_file` option that SimpleCov provides. See [minimum_coverage_by_file](https://github.com/simplecov-ruby/simplecov#minimum-coverage-by-file)\n\nIn order to activate advanced mode, you'll need to configure the simplecov-json gem. See [Usage](https://github.com/vicentllongo/simplecov-json#usage) for simplecov-json.\n\nYou'll need to setup both the standard formatter as well as json formatter within your test_helper.rb. Example below:\n\n```ruby\nrequire \"simplecov\"\nrequire \"simplecov-json\"\nSimpleCov.formatters = SimpleCov::Formatter::MultiFormatter.new([\n  SimpleCov::Formatter::HTMLFormatter,\n  SimpleCov::Formatter::JSONFormatter\n])\nSimpleCov.start do\n  # your config\nend\n```\n\nOne large benefit to this approach is that your code coverage minimum threshold is less skewed by outlier results. Said best by the SimpleCov documentation:\n\n\u003e You can define the minimum coverage by file percentage expected... This is useful to help ensure coverage is relatively consistent, rather than being skewed by particularly good or bad areas of the code.\n\n## Example configuration\n\nStill struggling to set this up? SimpleCov+ Action utilizes itself within a Github workflow. You can view the workflow and the spec_helper files for a good example of how to configure this check.\n\n[Example Github Workflow](/.github/workflows/testing.yml)\n\n[Example Spec Helper SimpleCov Setup](/specs/spec_helper.rb)\n\n## FAQs\n\nFirst off there is a `debug` option which prints many of the API calls made to Github. This can be helpful for diagnosing faults in SimpleCov+ Action.\n\n### I don't want to fail coverage on a per-file basis\n\nIf you've configured SimpleCov-json then SimpleCov+ Action will automatically\nfail CI when any file is below the minimum file coverage. This can be disabled if\nyou want to utilize SimpleCov-json but don't want SimpleCov+ Action to fail by\nsetting `minimum_file_coverage` to 0.\n\n### My Code Coverage isn't accurate for Rails parallelize \n\nUse the following configuration within your test_helper.rb or spec_helper.rb:\n\n```ruby\n\n# inside test_helper.rb or spec_helper.rb\nclass ActiveSupport::TestCase\n  parallelize(workers: :number_of_processors)\n\n  parallelize_setup do |worker|\n    SimpleCov.command_name \"#{SimpleCov.command_name}-#{worker}\"\n  end\n\n  parallelize_teardown do\n    SimpleCov.result\n  end\nend\n```\n\nAdditionally, make sure that your test environment is eager loading your application. This ensures that SimpleCov picks up coverage for all files accurately.\n\n```ruby\n# config/environments/test.rb\nRails.application.configure do\n  # many more configs...\n  \n  # Note: ENV[\"CI\"] is set to true by default from Github in the testing environment\n  config.eager_load = ENV[\"CI\"].present?\n  \n  # some more configs...\nend\n```\n\n\n## Development Setup\n\n```bash\ngit clone git@github.com:joshmfrankel/simplecov-check-action.git\ncd simplecov-check-action\nbundle install\nbundle exec rspec specs\n```\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fjoshmfrankel%2Fsimplecov-check-action","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fjoshmfrankel%2Fsimplecov-check-action","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fjoshmfrankel%2Fsimplecov-check-action/lists"}