CI: Codacy tutorial

Codacy is a static code analysis tool used to review code quality and ensure that it follows programming best practices. It provides automated analysis across multiple programming languages and helps developers identify issues such as style errors, security issues, code complexity, duplication and more.

Table of contents

  1. Get token from Codacy
  2. Register the secret in your repository
  3. Codacy workflow
  4. Try it!

Get token from Codacy

  • Go to Codacy.com. Click the Start free button and then the GitHub button.
  • Add your GitHub account. You must add permission to either all your repositories or the uvlhub repository. We recommend you choose the second option.
  • Go to Organizations and choose your GitHub username.
  • Go to Repositories and click on the repository you want to apply Codacy to.
  • Go to Settings (the cogwheel) and go to Integrations.
  • Go to the bottom. Under Repository API tokens the token you need appears.

Register the secret in your repository

  • In GitHub, in your repository, go to Settings -> Secrets and variables -> Actions.
  • Click the green New repository secret button.
  • In Name type CODACY_PROJECT_TOKEN.
  • In Secret, add the token you got from Codacy’s Repository API tokens field.

Codacy workflow

In the .github/workflows folder you have to add the following codacy.yml.

name: Codacy CI

on:
  push:
    branches:
      - main
  pull_request:
    branches:
      - main

jobs:
  codacy:
    runs-on: ubuntu-24.04
    services:
      mariadb:
        image: mariadb:12.0.2
        env:
          MARIADB_ROOT_PASSWORD: uvlhub_root_password
          MARIADB_DATABASE: uvlhubdb_test
          MARIADB_USER: uvlhub_user
          MARIADB_PASSWORD: uvlhub_password
        ports:
          - 3306:3306
        options: >-
          --health-cmd="mariadb-admin ping -u root -p$MARIADB_ROOT_PASSWORD"
          --health-interval=10s
          --health-timeout=5s
          --health-retries=3

    steps:
    - name: Checkout code
      uses: actions/checkout@v5

    - name: Set up Python
      uses: actions/setup-python@v6
      with:
        python-version: '3.13'

    - name: Install dependencies
      run: |
        python -m pip install --upgrade pip
        pip install -r requirements.txt
        pip install -e ./rosemary

    - name: Run tests with coverage
      run: |
        coverage run -m pytest app/features/ --ignore-glob='*selenium*'
        coverage xml
      env:
        FLASK_ENV: testing
        MARIADB_HOSTNAME: 127.0.0.1
        MARIADB_PORT: 3306
        MARIADB_TEST_DATABASE: uvlhubdb_test
        MARIADB_USER: uvlhub_user
        MARIADB_PASSWORD: uvlhub_password

    - name: Upload coverage to Codacy
      run: bash <(curl -Ls https://coverage.codacy.com/get.sh) report -r coverage.xml
      env:
        CODACY_PROJECT_TOKEN: ${{ secrets.CODACY_PROJECT_TOKEN }}

Do not use pip install codacy-coverage

Earlier versions of this tutorial uploaded the report with the codacy-coverage PyPI package (python-codacy-coverage -r coverage.xml). Codacy archived that package in 2020 and the endpoint it posts to, api.codacy.com/2.0/coverage/..., no longer exists, so the step fails whatever token you use. The supported uploader is the get.sh script above, which reads CODACY_PROJECT_TOKEN from the environment. coverage itself is already pinned in requirements.txt, so nothing else has to be installed.

Try it!

  • Make some changes to your code and upload it to GitHub.
  • Go to Repositories and click on the repository in which you want to study Codacy’s analysis.
  • There you go!

What things do you think we could improve in the code thanks to Codacy’s analysis?