How to wire these into a pipeline is on Gates in CI. This page lists every flag.
repowise coverage add
Ingest coverage reports into the index. With no path it discovers
coverage/lcov.info, coverage.xml, coverage.out, JaCoCo XML, a
repo-root .coverage and similar. init and update also ingest what they
discover.
repowise coverage add [PATHS...] [OPTIONS]| Parameter | Type | Default | Description |
|---|---|---|---|
PATHS | string | — | Report paths or quoted globs ('artifacts/**/lcov.info'). PATH=PREFIX prepends PREFIX to the paths inside that report. A path that matches no file is an error. |
--format | string | — | Force a parser: lcov, cobertura, clover, repowise-json, go-coverprofile, jacoco |
--strict | boolean | false | Also exit non-zero when some report files did not map to the repo tree. |
--path | string | — | Repo path (defaults to cwd / workspace primary). |
--verbose / -v | boolean | false | Show debug logs. |
repowise coverage add # discover reports
repowise coverage add .coverage # plus the per-test map (coverage run --contexts=test)
repowise coverage add web.lcov api.lcov # merged, a line any report ran counts as run
repowise coverage add web/coverage/lcov.info=webIt exits non-zero when nothing was stored, so coverage add ... || exit 1
tells a real ingest from a no-op. Each ingest is kept as history (the newest
50), which draws the coverage trend in the dashboard and in
get_health.
repowise coverage status
Show the coverage currently ingested. --path, --format table|json.
repowise coverage check
Gate a change on its patch coverage: the share of the changed executable lines the tests ran. Needs git and a report. No index.
repowise coverage check [REVSPEC] [OPTIONS]| Parameter | Type | Default | Description |
|---|---|---|---|
REVSPEC | string | — | origin/main...HEAD, base..head or one commit. Default: the CI pull request's target, else the remote's default branch. |
--report | string | — | Report path or glob, repeatable, PATH=PREFIX allowed. Default: coverage.paths, else discovery. |
--report-format | string | — | Force a parser: lcov, cobertura, clover, repowise-json, go-coverprofile, jacoco |
--fail-under | number | — | Exit 1 below this patch coverage percent. Default: coverage.fail_under. Unset reports without gating. |
--min-coverable-lines | number | — | A change with fewer changed executable lines is reported but never fails. Default: coverage.min_coverable_lines. |
--fail-under-risky | number | — | Gate the risky files alone (hotspots or bug magnets from the index; on git alone, the top quartile by bug-fix history). Default: coverage.fail_under_risky. |
--fail-under-branches | number | — | Gate the share of branches taken on changed lines. Reported beside patch coverage, never blended in. Default: coverage.fail_under_branches. |
--base-report | string | — | Report measured at the change's base. Adds project coverage at base and head, and files whose coverage changed outside the change. |
--max-drop | number | — | Exit 1 when project coverage falls more than this many points from the base. Default: coverage.max_drop. |
--path | string | — | A path inside the repository. Config is read at the repo root. |
--format | string | table | table, json, markdown, github |
repowise coverage check origin/main...HEAD --report coverage/lcov.info --fail-under 80
repowise coverage check --report 'artifacts/**/lcov.info' --min-coverable-lines 5
repowise coverage check --report lcov.info --base-report base/lcov.info --max-drop 0.5Rows list the riskiest changed files first. With an index, each uncovered
range also names up to three test files to extend. Path-scoped gates in
coverage.gates are judged too; see
Configuration.
repowise coverage suggest-gates
Propose path-scoped coverage.gates from CODEOWNERS, top-level packages
and, when indexed, graph communities. Writes nothing: paste what you keep
under coverage: and give each gate a fail_under.
repowise coverage suggest-gates # yaml block to paste
repowise coverage suggest-gates --format jsonrepowise impacted-tests
Print the tests a change needs. With a per-test coverage map it matches changed lines; without one it follows the import and call graph, and lists those tests apart as not coverage-backed.
repowise impacted-tests [REVSPEC] [OPTIONS]| Parameter | Type | Default | Description |
|---|---|---|---|
REVSPEC | string | — | A range or commit. Default: the staged changes locally, the pull request's change in CI. |
--staged | boolean | false | Diff the staged changes (git diff --cached). |
--format | string | table | table, json, list (test ids, one per line), args (one line of runner arguments, or :all) |
--runner | string | auto | Who --format args is for: auto, pytest, go, jest, files |
--path | string | — | Repo path (defaults to cwd / workspace primary). |
repowise impacted-tests main...HEAD
repowise impacted-tests main...HEAD --format args --runner pytest--format args prints :all whenever the selection is not certain, with
the reasons on stderr. Branch on that, never on an empty line. The rules and
the tests.* config keys are on Gates in CI.
repowise doc-drift
Show documentation drift: references in
your markdown that the tree no longer supports. Without --check it reads
the findings the index stored. With --check it reads the working tree and
needs no index.
repowise doc-drift [PATH] [OPTIONS]| Parameter | Type | Default | Description |
|---|---|---|---|
--kind | string | — | Only this reference class, repeatable: path, link, anchor, command, symbol |
--document | string | — | Only findings in this document (repo-relative). Repeatable. |
--min-confidence | number | — | Hide findings below this confidence (0 to 1). |
--check | boolean | false | Gate mode: read the working tree without an index and exit 1 when the gate fails. With --kind symbol it also checks symbols, which needs an index. |
--fail-on-confidence | number | 0.7 | With --check, fail on findings at or above this confidence. |
--baseline | string | — | With --check, accept findings recorded in this file; only new ones fail. |
--write-baseline | string | — | With --check, record the current findings to this file and exit 0. |
--since | string | — | With --check, gate only drift this change is answerable for. A ref means REF...HEAD plus uncommitted changes; auto reads the target branch from CI. |
--format | string | table | table, json, markdown, github, sarif, gitlab |
--repo | string | — | In workspace mode, target one repo. |
--no-workspace | boolean | false | Force single-repo mode. |
repowise doc-drift # everything the index stored
repowise doc-drift --kind anchor # renamed-heading links only
repowise doc-drift --check --since auto --format githubrepowise security check
Gate a change on the security findings it adds. Scans the files the change touched and keeps findings on changed lines. Secret kinds are also checked in every commit of the change, so a key added and then deleted inside it still fails. Needs git only.
repowise security check [REVSPEC] [OPTIONS]| Parameter | Type | Default | Description |
|---|---|---|---|
REVSPEC | string | — | origin/main...HEAD, base..head or one commit. Default: the CI pull request's target, else the remote's default branch. |
--fail-on | string | high | Exit 1 on a finding of this severity or above: high, med, low |
--staged | boolean | false | Check what the next commit records. For a pre-commit hook; takes no REVSPEC. |
--baseline | string | — | Accept findings recorded in this file; only new ones fail. |
--write-baseline | string | — | Add this change's findings to this file and exit 0. |
--path | string | — | A path inside the repository. |
--format | string | table | table, json, markdown, github, sarif, gitlab |
repowise security check origin/main...HEAD
repowise security check --staged
repowise security check --format sarif > security.sarifA repowise-security-ignore comment on a finding's line silences it
(repowise-security-ignore: kind, kind silences only those kinds). It is
still counted and listed. To run the check before every commit, use
repowise hook install --security.