scopio
Code metrics auditor with SQLite history, diffs and quality gates.
Features
- Audits code metrics (lines, complexity, warnings, languages) across multiple projects.
- Stores audit history in SQLite with diffs and quality gates.
- Exports results as JSON, CSV and Markdown.
- Compares audits and detects regressions for CI (
--fail-on-regression).
Install
pip install scopio
Requirements
- Python >= 3.11
lizard>= 1.24.0 (required for CSV parsing mode)scc>= 3.3.0 (optional, used for language/line counting) — the boyter/scc code counter, not the unrelated PyPIsccpackage:# Download a binary from https://github.com/boyter/scc/releases, or: go install github.com/boyter/scc/v3@latest
git(optional, used for metadata)
Quick Start
scopio --config scopio.toml run
All output artifacts (database, JSON, CSV, Markdown) are stored in the .scopio/ directory by default. Use --output-dir to override.
If scc or lizard versions differ from the expected range, a non-blocking tool_version_diverge warning is emitted in the logs.
Usage
Run audit
scopio --config scopio.toml run
scopio --config scopio.toml run --verbose
scopio --config scopio.toml run --incremental
Report history
scopio report --project my-project --limit 10
Diff between audits
scopio diff --project my-project
Diff report with file-level detail
scopio diff-report --project my-project --files --threshold-ccn 6
CI integration
scopio ci --project my-project --fail-on-regression
Clean old audits
scopio clean --keep 50
Archive old data
scopio archive --older-than 2026-01-01 --format csv
Initialize config
scopio init
Configuration
[discovery]
ignore_hidden = true
projects = ["my-project"]
[filters]
global_dirs = ["node_modules", "target", "dist", "build"]
minified_files = ["*.min.js", "*.min.css"]
ignored_langs = ["JSON", "Markdown", "TOML"]
[quality_gates]
max_ccn = 10.0 # average CCN per function
max_function_ccn = 15.0 # worst function complexity (disabled if omitted)
max_warnings = 10
max_ccn_trend_increase = 0.2
trend_sensitive_projects = []
[quality_gates.per_project]
# "my-project" = { max_ccn = 12.0, max_warnings = 15, max_function_ccn = 20.0 }
[quality_gates.per_language]
# Python = { max_ccn = 12.0, max_warnings = 20 }
[ci]
max_loc_trend_increase = 0.0 # fail if LOC grows above this ratio (0.0 = any growth)
Audit behavior
- Each audit run creates/updates a single row per
(project, branch, commit_hash). - Same commit, same branch: metrics are upserted (updated) and
runs_countis incremented. This avoids data staleness when re-running on the same commit (e.g. after changing.scopio.tomlfilters). - Different commit: a new row is created with
runs_count = 1. - The
runs_countfield is exposed inreport, CSV, JSON and Markdown exports. - Diff and CI comparisons compare the previous audit against the current one by default (use
--base firstto compare against the very first audit). - Quality gates use the current audit's values; the trend gate compares against the previous historical audit.
What the numbers mean
- LOC: source lines of code counted by
scc. - NLOC: logical lines of code counted by
lizard. LOC and NLOC are intentionally different metrics (different counting methodologies). - CCN (avg): cyclomatic complexity averaged over all functions. Averages hide outliers.
- ccn_max /
max_function_ccn: cyclomatic complexity of the worst single function — this is what the per-function quality gate checks. - warnings: currently always
0— thelizard --csvformat does not emit warnings. Language-specific warning adapters (clippy, eslint, ruff) are planned. - file_metrics: stored per-function in the database; the granular
diff-reportaggregates them per file (NLOC sum, CCN max).
GitHub Actions
name: Scopio
on:
push:
branches: [main]
pull_request:
branches: [main]
jobs:
scopio:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- name: Install uv
uses: astral-sh/setup-uv@v10.0.1
with:
enable-cache: true
cache-dependency-glob: "uv.lock"
- name: Install Python
run: uv python install 3.11
- name: Install scopio
run: pip install scopio
- name: Run scopio
run: scopio ci --project my-project --fail-on-regression
Development
This project uses uv as the Python toolchain.
See CONTRIBUTING.md for the commit convention and release workflow.
Architecture and scope decisions are recorded in docs/DECISIONS.md.
# Sync dependencies and create a virtual environment
uv sync
# Run tests
uv run pytest
# Run a lint check
uv run ruff check
# Run scopio locally
uv run scopio --help
Semantic Versioning
This project adheres to Semantic Versioning.
License
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
Built Distribution
Filter files by name, interpreter, ABI, and platform.
If you're not sure about the file name format, learn more about wheel file names.
Copy a direct link to the current filters
File details
Details for the file scopio-0.5.0.tar.gz.
File metadata
- Download URL: scopio-0.5.0.tar.gz
- Upload date:
- Size: 129.7 kB
- Tags: Source
- Uploaded using Trusted Publishing? Yes
- Uploaded via:
twine/7.0.0 CPython/3.13.14
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
0783bccde92d44c18210b1a05a5723da4e05b92342e92ff70969f9bccdb9dd9e
|
|
| MD5 |
46fbd10147d52ebb548749216db60b75
|
|
| BLAKE2b-256 |
481541da1c3928e598bc1f8f702da887bccaf133f0977a53554f0f0f97a1a9fc
|
Provenance
The following attestation bundles were made for scopio-0.5.0.tar.gz:
Publisher:
publish.yml on ImGabe/scopio
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
scopio-0.5.0.tar.gz -
Subject digest:
0783bccde92d44c18210b1a05a5723da4e05b92342e92ff70969f9bccdb9dd9e - Sigstore transparency entry: 2647138864
- Sigstore integration time:
-
Permalink:
ImGabe/scopio@6d4b6ff75a6bf434cb0bede3c394c73a1b1e0f65 -
Branch / Tag:
refs/tags/v0.5.0 - Owner: https://github.com/ImGabe
-
Access:
public
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
publish.yml@6d4b6ff75a6bf434cb0bede3c394c73a1b1e0f65 -
Trigger Event:
push
-
Statement type:
File details
Details for the file scopio-0.5.0-py3-none-any.whl.
File metadata
- Download URL: scopio-0.5.0-py3-none-any.whl
- Upload date:
- Size: 30.1 kB
- Tags: Python 3
- Uploaded using Trusted Publishing? Yes
- Uploaded via:
twine/7.0.0 CPython/3.13.14
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
7ccb220b4de2f8546e77bf23145f172aa5eae39fe1a5259e069221ac4ca37749
|
|
| MD5 |
c6e7df59cbe4b3fad00c12746ca0ecf4
|
|
| BLAKE2b-256 |
9b056f2187dbd8c40cf239f3f3e40e7ac03ade5560a73e412dc36731296ae43f
|
Provenance
The following attestation bundles were made for scopio-0.5.0-py3-none-any.whl:
Publisher:
publish.yml on ImGabe/scopio
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
scopio-0.5.0-py3-none-any.whl -
Subject digest:
7ccb220b4de2f8546e77bf23145f172aa5eae39fe1a5259e069221ac4ca37749 - Sigstore transparency entry: 2647138905
- Sigstore integration time:
-
Permalink:
ImGabe/scopio@6d4b6ff75a6bf434cb0bede3c394c73a1b1e0f65 -
Branch / Tag:
refs/tags/v0.5.0 - Owner: https://github.com/ImGabe
-
Access:
public
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
publish.yml@6d4b6ff75a6bf434cb0bede3c394c73a1b1e0f65 -
Trigger Event:
push
-
Statement type: