You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
docs(ruby): add Ruby standards page and update language matrix
Add content/docs/standards/ruby.md with full Ruby tooling docs.
Update _index.md language support matrix and target mapping tables.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Copy file name to clipboardExpand all lines: content/docs/standards/_index.md
+15-14Lines changed: 15 additions & 14 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -2,7 +2,7 @@
2
2
title: "Standards"
3
3
linkTitle: "Standards"
4
4
weight: 20
5
-
description: "Per-language tooling standards for Python, Bash, Terraform, Ansible, and universal security tools."
5
+
description: "Per-language tooling standards for Python, Bash, Terraform, Ansible, Ruby, and universal security tools."
6
6
---
7
7
8
8
DevRail defines opinionated tooling standards for each supported language ecosystem. Every tool is pre-installed in the dev-toolchain container and invoked through consistent Makefile targets.
@@ -11,15 +11,15 @@ DevRail defines opinionated tooling standards for each supported language ecosys
11
11
12
12
The following table shows the default tool for each concern per language. These tools are pre-installed in the `dev-toolchain` container.
description: "Ruby and Rails tooling standards: rubocop, brakeman, bundler-audit, rspec, reek, and sorbet."
6
+
---
7
+
8
+
Ruby projects use rubocop for linting and formatting, brakeman and bundler-audit for security, rspec for testing, reek for code smell detection, and optionally sorbet for type checking.
rubocop handles both linting and formatting. Do not use standardrb or prettier-ruby separately.
61
+
62
+
### reek
63
+
64
+
Config file: `.reek.yml` at repository root.
65
+
66
+
```yaml
67
+
# .reek.yml -- code smell detection configuration
68
+
exclude_paths:
69
+
- vendor
70
+
- db/schema.rb
71
+
- bin
72
+
73
+
detectors:
74
+
IrresponsibleModule:
75
+
enabled: false
76
+
UncommunicativeVariableName:
77
+
accept:
78
+
- e
79
+
- i
80
+
- k
81
+
- v
82
+
```
83
+
84
+
### rspec
85
+
86
+
Config file: `.rspec`at repository root.
87
+
88
+
```text
89
+
--require spec_helper
90
+
--format documentation
91
+
--color
92
+
```
93
+
94
+
### sorbet
95
+
96
+
Config file: `sorbet/config`at repository root.
97
+
98
+
```text
99
+
--dir
100
+
.
101
+
--ignore=vendor/
102
+
--ignore=db/
103
+
--ignore=bin/
104
+
```
105
+
106
+
Sorbet uses typed signatures (`# typed: strict`, `# typed: true`, etc.) at the top of each file. Start with `# typed: false` and incrementally adopt stricter levels.
107
+
108
+
### brakeman
109
+
110
+
No config file required. Brakeman scans Rails applications for common security vulnerabilities (SQL injection, XSS, mass assignment, etc.). It only runs for Rails projects (detected by the presence of `config/application.rb`).
111
+
112
+
### bundler-audit
113
+
114
+
No config file required. Scans `Gemfile.lock` for known vulnerable gem versions. Run `bundler-audit update` periodically to refresh the advisory database.
- `reek .`-- code smell detection (when project is large)
148
+
- `sorbet`-- type checking (when project adopts typed signatures)
149
+
150
+
## Notes
151
+
152
+
- **rubocop is the single tool for both linting and formatting.** Do not use standardrb or prettier-ruby.
153
+
- **`rubocop-rails`, `rubocop-rspec`, and `rubocop-performance`** are rubocop extensions loaded via `require:` in `.rubocop.yml`. They are not standalone CLI tools.
154
+
- **`brakeman` only runs for Rails applications.** It is skipped if `config/application.rb` is not present.
155
+
- **`bundler-audit` only runs if `Gemfile.lock` exists.** It checks for known vulnerabilities in declared gem dependencies.
156
+
- **`reek` runs as part of `make lint`.** It detects code smells (feature envy, too-many-instance-variables, data clump, etc.).
157
+
- **`sorbet` is optional.** Projects can incrementally adopt it by adding `# typed:` sigils to Ruby files. The `sorbet-runtime` gem provides runtime type annotations.
158
+
- **All tools are pre-installed in the dev-toolchain container.** Do not install them on the host.
0 commit comments