impactcheck-cli
v2.3.2
Published
Pre-PR impact detection — structural + semantic + local HTML report
Maintainers
Readme
ImpactCheck CLI
Know what breaks before your PR merges.
ImpactCheck scans your codebase locally, builds a heuristic call graph, and shows which methods, callers, and API endpoints are structurally affected when something changes — before you raise a PR.
Important: ImpactCheck is a heuristic static analyser, not a runtime oracle. It detects structural changes in the scanned codebase only. Consumers in other services or repos are not checked. Confidence percentages are heuristic estimates, not measured probabilities.
npx impactcheck-cli@latest init
npx impactcheck-cli@latest checkLooking for impactguard-cli? Renamed to
impactcheck-cli. Use:npm install impactcheck-cli
How it works
Your code changes
↓
npx impactcheck-cli@latest check
↓
⛔ 1 BREAKING — push blocked
⛔ Method Removed [95%]
DriversService.assignNearestDriver
callers : DriversController.assignDriver
api : POST /caption/assign
detail : 1 direct caller found in scanned codebase.
Consumers outside this repo not checked.Quick start
# Setup — once per project (auto-detects language)
cd your-project
npx impactcheck-cli@latest init
# After every code change
npx impactcheck-cli@latest check
# View full results in browser (optional, local only)
npx impactcheck-cli@latest config --web-report on
npx impactcheck-cli@latest checkLanguage support — honest scope
| Language | Framework | Scanner | Coverage | |---|---|---|---| | TypeScript / Node | NestJS, Express, Fastify | ts-morph AST | Strongest — full class/method/decorator analysis | | Java | Spring Boot | Regex-based | Basic — detects common patterns, misses generics, lambdas, nested classes | | Python | FastAPI, Flask | Python AST | Moderate — detects function calls, no type resolution or symbol analysis | | Salesforce | Apex, LWC | Regex-based | Beta — Apex class/trigger detection, LWC wire calls |
Language is auto-detected — no --lang flag needed:
npx impactcheck-cli@latest init
# Detected : java project ← from pom.xml
# Detected : python project ← from requirements.txt
# Detected : node project ← from package.json / tsconfig.json
# Detected : salesforce project ← from sfdx-project.jsonWhat it detects
| Change | Severity | Confidence | Notes | |---|---|---|---| | Method removed | Breaking | 95% (heuristic) | Consumers in other repos not checked | | Endpoint removed | Breaking | 95% (heuristic) | All callers will get 404 | | Signature changed | Warning | 85% (heuristic) | Caller may or may not be incompatible | | Return type changed | Warning | 80% (heuristic) | Verify caller compatibility manually | | Method renamed | Warning | 45% (heuristic) | Low confidence — verify manually |
All confidence percentages are heuristic estimates, not measured probabilities.
What it does NOT check
ImpactCheck is a heuristic static call-graph generator — not a runtime analyser:
- Logic changes inside methods (what code does, not how it is structured)
- Feature flag behaviour
- Database migrations
- Dynamic calls —
service[method]() - Consumers in other services or repos
- Cross-service dependencies (roadmap — Phase 3)
- Runtime polymorphism
- Schema compatibility in OpenAPI ($ref resolution)
These are shown at the bottom of every report.
Known limitations
- Baseline is personal —
.impactcheck/baseline.jsonis local and gitignored. Two developers can check the same branch against different baselines. Shared baseline across a team is a Team Plan feature. - Java regex coverage — common Spring Boot patterns are detected. Complex patterns (generics, lambdas, nested classes) may be missed or misattributed.
- TypeScript identity — methods are keyed as
ClassName.methodName. Common names across modules can collide. Use verbose mode to verify findings. - Consumer rule — only warns when a consumer is found in the scanned codebase. Missing a consumer means no warning, not safety.
Commands
# Setup
npx impactcheck-cli@latest init
# Check after every change
npx impactcheck-cli@latest check
# Check since specific commit
npx impactcheck-cli@latest check --since HEAD~1
# Combined OpenAPI + call graph
npx impactcheck-cli@latest check --base-spec old.yaml --new-spec new.yaml
# Update baseline after intentional changes
npx impactcheck-cli@latest check --update-baseline
# Configuration
npx impactcheck-cli@latest config --web-report on
npx impactcheck-cli@latest config --telemetry off
# Generate call graph manually
npx impactcheck-cli@latest generate
# Install git pre-push hook
npx impactcheck-cli@latest install-hook
---
## Feedback
Try it and tell us:
1. Did it catch something you would not have noticed?
2. Did it miss something it should have caught?
3. Was anything flagged incorrectly?
Issues: **github.com/impactcheckcli/impactguard-cli/issues**
Email: **[email protected]**
---
*ImpactCheck is a heuristic static call-graph generator. It identifies likely structural impacts and explains why they are at risk. It is not a substitute for tests, code review, or runtime monitoring.*