Skip to content

Plugins ​

Scruple plugins package named, tested rules. They can check common engineering problems or standards your team repeats in review. Register each factory under the namespace used by its rule IDs, then enable individual rules in rules.

Rules start from bounded parser targets. They can use the configured provider to classify ambiguous possible candidates, then send selected candidates for the final rule decision. A finding appears only when the provider chooses the finding label and its final answer clears the rule's probability and confidence thresholds.

Every threshold option is an object with warning and error probabilities. The numeric form is not accepted, and warning cannot exceed error. Scores from warning up to error produce non-blocking warnings. Scores at or above error produce blocking errors. The rule must also meet minConfidence. Configuring a rule as "warn" caps output at warning; "error" allows either tier.

PluginChoose it for
API ContractsFunction contracts and explicit Fastify or Express route behavior
AsyncConcurrency, sequencing, cancellation, and async lifetime
CommentsComment usefulness, accuracy, suppressions, and deprecations
ErrorsSwallowed, wrapped, and message-dispatched exceptions
ObservabilitySafe, actionable, stable, and non-duplicated telemetry
Relational DatabasesJoins, loop queries, transaction scope, and pagination order
ResourcesCleanup, ownership, retry limits, backoff, jitter, and deadlines
SecurityAuthorization, exposure, and direct request-to-sensitive-sink flows
TestsMeaningful oracles, specific failures, and reliable synchronization

Rule configuration follows the ESLint/Oxlint shape: use a severity alone, or [severity, options]. Plugin factories themselves take no arguments.

ts
plugins: { comments: comments() },
rules: {
  "comments/no-misleading-comments": [
    "warn",
    { threshold: { warning: 0.9, error: 0.97 } },
  ],
},

Rule registry

Find the check you need.

49 semantic rules across 9 plugins.

49 rules

API Contracts
api-contracts/no-ambiguous-failure-contracts

Disallow overlapping public failure channels.

API Contracts
api-contracts/no-ignored-significant-results

Do not discard meaningful call results.

API Contracts
api-contracts/no-misleading-function-names

Disallow names that contradict visible behavior.

API ContractsHTTP contracts
api-contracts/no-misleading-http-status

Disallow statuses that contradict visible outcomes.

API ContractsHTTP contracts
api-contracts/no-side-effects-in-safe-http-methods

Disallow requested mutation through safe HTTP methods.

API ContractsInput validation
api-contracts/require-input-validation

Require validation of untrusted boundary input.

AsyncAsync lifecycle
async/no-async-initialization

Disallow async work hidden in initialization.

AsyncConcurrency
async/no-serial-independent-work

Do not run independent awaits in series.

AsyncConcurrency
async/no-unbounded-concurrency

Disallow potentially unbounded promise fan-out.

AsyncAsync lifecycle
async/no-unobserved-async-work

Do not leave started async work unobserved.

AsyncCancellation
async/require-abort-listener-cleanup

Require cleanup of abort listeners.

AsyncCancellation
async/require-cancellation-propagation

Require accepted cancellation to be forwarded.

AsyncConcurrency
async/require-race-loser-cleanup

Require cleanup of locally owned race losers.

CommentsComment quality
comments/no-change-history-comments

Disallow obsolete change narration.

CommentsComment quality
comments/no-commented-out-code

Disallow disabled executable implementation.

CommentsComment correctness
comments/no-misleading-comments

Disallow claims contradicted by visible code.

CommentsComment quality
comments/no-useless-comments

Disallow comments with no maintenance value.

CommentsComment quality
comments/prefer-concise-comments

Prefer useful but concise comment prose.

CommentsAPI documentation
comments/require-actionable-deprecations

Require migration guidance in deprecations.

CommentsComment quality
comments/require-actionable-todos

Require actionable TODO, FIXME, and HACK markers.

CommentsTooling directives
comments/require-justified-suppressions

Require explanations for tool suppressions.

ErrorsError handling
errors/no-lossy-error-wrapping

Disallow replacement errors that lose the original cause.

ErrorsError handling
errors/no-message-based-error-dispatch

Disallow control flow coupled to exception prose.

ErrorsError handling
errors/no-swallowed-errors

Disallow silently suppressed unexpected failures.

ErrorsError handling
errors/no-useless-catch-boundaries

Disallow catch handlers that add no behavior.

ObservabilityError telemetry
observability/no-duplicate-error-reporting

Do not report the same caught failure twice.

ObservabilityData protection
observability/no-sensitive-logs

Disallow sensitive values emitted without redaction.

ObservabilityError telemetry
observability/no-unactionable-errors

Require operation and failure evidence in error events.

ObservabilityTelemetry context
observability/require-operation-context

Require a stable operation identity in events.

ObservabilityTelemetry cardinality
observability/require-stable-telemetry-names

Require stable event, span, and metric names.

Relational DatabasesDatabase performance
relational-databases/no-query-in-loop

Disallow per-item relational queries.

Relational DatabasesDatabase performance
relational-databases/prefer-database-join

Prefer joining related query results in the database.

Relational DatabasesDatabase correctness
relational-databases/require-deterministic-pagination-order

Require visible ordering for pagination.

Relational DatabasesDatabase correctness
relational-databases/require-transaction-scoped-client

Require transaction-scoped database clients.

ResourcesResource lifecycle
resources/no-leaked-resources

Disallow owned resources left unreleased.

ResourcesRetries
resources/require-bounded-retries

Require a finite bound on retry behavior.

ResourcesResource lifecycle
resources/require-cleanup-on-failure

Require cleanup that is safe on failure.

ResourcesResource lifecycle
resources/require-complete-resource-cleanup

Require complete cleanup of multiple resources.

ResourcesRetries
resources/require-retry-backoff-with-jitter

Require retry backoff with jitter.

ResourcesRetries
resources/require-retry-time-budget

Require an overall deadline for retry work.

SecurityData protection
security/no-sensitive-data-exposure

Disallow sensitive data sent through output sinks.

SecurityWeb security
security/no-unsafe-redirect

Disallow request-controlled redirect targets.

SecurityInjection
security/no-untrusted-command-execution

Disallow request data reaching command or code execution.

SecurityInput validation
security/no-untrusted-mass-assignment

Disallow wholesale persistence of request objects.

SecurityAuthorization
security/no-user-controlled-authorization

Disallow authorization based on attacker-controlled claims.

TestsTest reliability
tests/no-fixed-delay-synchronization

Disallow sleeps used to synchronize tests.

TestsTest reliability
tests/no-nondeterministic-tests

Disallow uncontrolled inputs that make tests flaky.

TestsTest effectiveness
tests/no-vacuous-tests

Disallow tests with no effective behavior verification.

TestsTest effectiveness
tests/require-specific-error-assertions

Require assertions that identify the expected failure.

Does your team repeat a code-review standard that is not listed here?

Write a plugin that selects the relevant code, defines the allowed answers and thresholds, and supplies the warning.
Write a custom rule

Released under the MIT License.