crie works with zero configuration — every setting below has a built-in default.
Run crie init to scaffold a commented crie.config.yaml in the current directory,
or point crie analyze at one explicitly with --config. Discovery order
(crie/config/loader.py): an explicit --config path, then crie.config.yaml /
crie.config.yml / .crie.yaml at the repository root, then built-in defaults.
# Glob patterns (relative to the repo root) to include/exclude from analysis.
include:
- "**/*"
exclude: []
# - "vendor/**"
# - "**/*.generated.*"
# Restrict analysis to specific languages. Empty = every supported language.
# Valid values: python, javascript, typescript
languages: []
# Cap how many commits git-history-based analyzers walk. Omit for full history.
max_commits: 5000
# Per-analyzer enable/disable and options. Names match `crie list-analyzers`.
analyzers:
test_coverage:
enabled: true
options:
report_path: coverage.xml
coupling:
options:
min_shared_commits: 2
git_history:
enabled: true
scoring:
normalization: percentile # percentile | minmax
weight_profile: balanced # balanced | regression-focused | greenfield
dimensions:
overall_risk:
weights:
churn: 0.40 # overrides just this category; every other category on this
# dimension keeps its preset value
severity_thresholds:
high: 0.6 # overrides just this cutoff; moderate/critical keep their defaults
output:
directory: crie-report
formats: [json, markdown]
top_n: 25
# CI gating: non-zero exit from `crie analyze` if any file's score on
# `fail_on_dimension` meets or exceeds `fail_on_score`.
fail_on_score: 0.9
fail_on_dimension: overall_risk
# Override automatic project-type detection. Omit to auto-detect. See
# docs/software-evaluation.md for the full list of profile values.
# profile: backend_service
# Select a focus preset (restricts + prioritizes analyzers). Omit to run everything.
# See docs/software-evaluation.md for what each preset changes.
# focus: debugging| Key | Type | Default | Notes |
|---|---|---|---|
include |
list of globs | ["**/*"] |
Applied before exclusion; a file must match at least one include pattern. |
exclude |
list of globs | [] |
Merged with a built-in exclude list (.git, node_modules, __pycache__, .venv/venv, dist, build, cache dirs) that's always applied, plus anything git itself ignores. Patterns match anywhere in the path — a leading **/ is optional and applied automatically if omitted. |
languages |
list of strings | [] (all) |
One or more of python, javascript, typescript. |
max_commits |
int or null | null (full history) |
Caps how many commits git log walks — useful on very large repositories. |
analyzers.<name>.enabled |
bool | true |
Disable a specific analyzer. |
analyzers.<name>.options |
dict | {} |
Analyzer-specific options — see the table below. |
scoring.normalization |
percentile | minmax |
percentile |
How raw metric values are converted to [0,1]. See scoring-model.md. |
scoring.weight_profile |
string | balanced |
One of the named presets in crie/config/defaults.py, or a custom name you've fully defined via scoring.dimensions. |
scoring.dimensions.<dimension>.weights |
dict | {} |
Per-category weight overrides for one dimension. Only the categories you list are overridden; everything else keeps the preset value. |
scoring.severity_thresholds |
dict | {} |
Overrides for the Low/Moderate/High/Critical percentile cutoffs (keys moderate/high/critical; must stay strictly ascending). See scoring-model.md. |
output.directory |
path | crie-report |
Relative to your current working directory unless absolute (not relative to the analyzed repo path). |
output.formats |
list | [json, markdown] |
Any subset of the registered reporters (crie list-analyzers doesn't list reporters; there's no dedicated list-reporters command yet — the built-ins are json, markdown). |
output.top_n |
int | 25 |
How many files/modules the Markdown "top risk" view highlights. |
fail_on_score |
float or null | null |
If set, crie analyze exits with code 1 when any file meets or exceeds this on fail_on_dimension. |
fail_on_dimension |
string | overall_risk |
Which of the five dimensions fail_on_score gates on. |
profile |
string or null | null (auto-detect) |
Overrides project-type detection — see software-evaluation.md for valid values. Same as --profile. |
focus |
string or null | null (none) |
Selects a focus preset — see software-evaluation.md for valid values. Same as --focus. |
| Analyzer | Option | Default | Meaning |
|---|---|---|---|
test_coverage |
report_path |
auto-detects coverage.xml / cobertura.xml at the repo root |
Path (relative to repo root) to a Cobertura-format coverage report. |
coupling |
min_shared_commits |
2 |
Minimum number of shared commits before two files are considered coupled. |
Analyzers with no listed options (git_history, size, complexity_python,
complexity_js, dependency_graph, architecture, readability,
maintainability, debuggability, reliability, testing,
performance_readiness) take none today.
Not part of crie.config.yaml — configured via environment and CLI flags instead,
since it's specific to one command and shouldn't be something a checked-in config
file accidentally enables for everyone who runs crie analyze:
| Setting | How | Default |
|---|---|---|
| Enable AI synthesis | pip install "code-risk-intelligence-engine[ai]" + ANTHROPIC_API_KEY env var |
disabled |
| Model | crie ask ... --model NAME |
claude-sonnet-5 |
| Force-disable per invocation | crie ask ... --no-ai |
— |
See custom-inquiries.md for full setup steps (getting a key,
setting the environment variable correctly per-shell) and
custom-inquiries.md#troubleshooting if
crie ask isn't producing synthesized answers — it distinguishes "not configured"
from "configured but failed" in its output, with the actual failure reason shown
in the latter case.
Every CLI flag on crie analyze overrides the corresponding config value for that
run only — the config file itself is never modified. See
cli-reference.md.