RepoRipple 0.3.0 makes change-impact analysis safer, faster, and more complete on real pull requests—especially when files are deleted, renamed, ignored, unusually named, or duplicated across Python source roots.
Highlights
- Complete Git change discovery: analyzes additions, modifications, deletions, type changes, and both sides of renames.
- Historical dependency tracing: retains pre-change source for deleted and renamed files so remaining dependents still appear in the blast radius.
- Safer
--basehandling: validates revisions, rejects option-like input, and resolves the base to a commit ID before invokinggit diff. - Faster repository scans: prunes built-in and
.gitignore-excluded directories before walking and skips source files larger than 1 MB. - Deterministic Python resolution: handles duplicate module names predictably and reports ambiguity instead of silently choosing unstable results.
- More accurate risk signals: recognizes sensitive production paths across common naming styles while avoiding noise from tests and documentation.
- CLI and MCP parity: deleted- and renamed-file analysis works through both the command line and the local MCP server.
Install or upgrade
python -m pip install --upgrade reporipple==0.3.0Run without installing:
uvx reporipple@0.3.0 . --base origin/mainGitHub Action:
- uses: adiarora06/RepoRipple@v0.3.0Security and correctness
This release fixes a Git option-injection risk in user-supplied base revisions and switches Git path parsing to NUL-delimited output so unusual filenames remain intact. It also closes correctness gaps that previously omitted deleted files, lost rename origins, traversed ignored dependency trees, or produced unstable Python import resolution.
Behavior note: the supplied repository path must now be the Git top level. This replaces previously silent, incorrect analysis when a subdirectory was supplied.
Verification
- 68 tests passing
- CI passing on Python 3.11, 3.12, and 3.13
- Ruff passing
- Wheel and source distribution built successfully
- Strict package metadata checks passing
- Clean-wheel CLI and MCP smoke tests passing