Open sourcev0.2.0MIT

Know what a code change can break before you merge it.

RepoRipple builds a lightweight dependency graph, reads the current Git change, traces reverse dependencies, recommends relevant tests, and packages the evidence for humans and coding agents.

RepoRipple tracing a changed file through its dependency blast radius and producing a high-risk report

Release proof

CLI, Action, and MCP
3 surfaces
v0.2.0 release gate
41 tests
Python, JavaScript, TypeScript
3 languages

One core, three workflows

CLI

Analyze a worktree or compare a branch, then emit a review-ready Markdown or JSON report.

GitHub Action

Attach impact evidence to pull requests and fail CI when a change crosses a configured risk threshold.

MCP server

Give coding agents typed tools to forecast proposed edits or inspect real changes inside an allowed workspace root.

Run it in one command.

The deterministic path needs no API key or hosted service. Use the package directly, run it without installing through uvx, or start its local MCP server.

pip install reporipple
reporipple . --base origin/main

# No-install execution
uvx reporipple . --base origin/main

# Read-only MCP server
uvx reporipple mcp --root /path/to/workspace

Trust boundaries

  • Repository files are parsed, never executed or uploaded by the deterministic analyzer.
  • MCP tools are read-only and reject repository requests outside the configured workspace root.
  • Optional OpenRouter explanations receive anonymized evidence only and cannot change risk or CI results.

Try RepoRipple on a real change.

Published on PyPI and in the MCP Registry.