Skip to content

RepoRipple v0.3.0 — safer, faster change-impact analysis

Latest

Choose a tag to compare

@adiarora06 adiarora06 released this 30 Sep 18:49
b4d4a1a

RepoRipple 0.3.0 makes change-impact analysis safer, faster, and more complete on real pull requests—especially when files are deleted, renamed, ignored, unusually named, or duplicated across Python source roots.

Highlights

  • Complete Git change discovery: analyzes additions, modifications, deletions, type changes, and both sides of renames.
  • Historical dependency tracing: retains pre-change source for deleted and renamed files so remaining dependents still appear in the blast radius.
  • Safer --base handling: validates revisions, rejects option-like input, and resolves the base to a commit ID before invoking git diff.
  • Faster repository scans: prunes built-in and .gitignore-excluded directories before walking and skips source files larger than 1 MB.
  • Deterministic Python resolution: handles duplicate module names predictably and reports ambiguity instead of silently choosing unstable results.
  • More accurate risk signals: recognizes sensitive production paths across common naming styles while avoiding noise from tests and documentation.
  • CLI and MCP parity: deleted- and renamed-file analysis works through both the command line and the local MCP server.

Install or upgrade

python -m pip install --upgrade reporipple==0.3.0

Run without installing:

uvx reporipple@0.3.0 . --base origin/main

GitHub Action:

- uses: adiarora06/RepoRipple@v0.3.0

Security and correctness

This release fixes a Git option-injection risk in user-supplied base revisions and switches Git path parsing to NUL-delimited output so unusual filenames remain intact. It also closes correctness gaps that previously omitted deleted files, lost rename origins, traversed ignored dependency trees, or produced unstable Python import resolution.

Behavior note: the supplied repository path must now be the Git top level. This replaces previously silent, incorrect analysis when a subdirectory was supplied.

Verification

  • 68 tests passing
  • CI passing on Python 3.11, 3.12, and 3.13
  • Ruff passing
  • Wheel and source distribution built successfully
  • Strict package metadata checks passing
  • Clean-wheel CLI and MCP smoke tests passing

Links