A pre-commit check for Python

Know what your change breaks before you commit it.

Magellan Lite maps your code from its syntax trees, finds exactly what a change touched, follows it to every caller it can break, and runs a checklist built from real software disasters. One verdict: ok review block.

a real run: the sensor example
$ magellan-lite check

The dangerous change is rarely the one you're looking at

$460M

in 45 minutes. Knight Capital's order router woke up code that a 2005 change had left unable to stop.

SEC Release 34-70694

8.5M

Windows machines crashed when a content update reached code that read one field past its input.

CrowdStrike root cause analysis, 2024

27 min

of global outage from one regular expression that took super-linear time on every server at once.

Cloudflare, July 2 2019

How it works

  1. 1 Map

    Every function, method, class and constant, named stably and hashed from its syntax tree. Reformatting, moving code or switching line endings is never a change.

  2. 2 Diff

    Compare with the last commit (or any baseline): what was added, removed, renamed, or had its signature, body or value changed.

  3. 3 Reach

    Walk the call graph backwards from each change: its callers, then theirs. Each hop fades the score, so you get a ranked list of the code it can break.

  4. 4 Check

    Run the checklist on exactly what changed, so old problems elsewhere stay quiet. Each rule comes from a failure that really happened.

Famous failures, replayed

Loading…

Each failure is rebuilt as a short code history and checked by the real engine. Watch what happened and what it cost, the change itself, what it reaches, the issue, and whether Magellan Lite catches it.

Every change, replayed

Regenerate with python demo/build_site.py. Ports of code that is not public say so. Static analysis: a clean report is not proof.

The checklist

Every rule runs only on the definitions a change touched, so old problems elsewhere stay quiet. A few of them, and the failures behind them:

Try it

Three small projects, one line to change in each. Make the change and the real engine checks it as you type, right here in your browser (or on your machine with magellan-lite serve). Nothing is uploaded.

Run it on your project

pip install -e .
magellan-lite check            # against your last commit
magellan-lite check --format json > report.json
magellan-lite serve --open     # this page, with a live API
magellan-lite share            # your work in progress, to your team
magellan-lite team             # what only your work + theirs breaks

Read a report

Open a report.json to see its verdict, checklist and map here.

In VS Code

The verdict in the status bar every time you save, each problem where it lands, a map that follows the code you click on, and your team's work in progress beside yours, live on the Team suite. It brings its own engine: all it needs is a Python 3.10 or newer on the machine, which it finds by itself.

Install it

Download Magellan Lite 0.3.2

Then in VS Code: Extensions, the ... menu, Install from VSIX..., and pick the file. Or paste one line in a terminal: it finds the file (here, in Downloads or on the Desktop), downloads it if it isn't there, and installs it. Windows PowerShell:

$ProgressPreference='SilentlyContinue'; $f = (Get-ChildItem $PWD, "$HOME\Downloads", "$HOME\Desktop" -Filter 'magellan-lite*.vsix' -EA 0 | Sort-Object LastWriteTime -Desc | Select-Object -First 1).FullName; if (!$f) { $f = "$env:TEMP\magellan-lite.vsix"; Invoke-WebRequest https://magellan-code.pages.dev/downloads/magellan-lite.vsix -OutFile $f }; code --install-extension $f --force

macOS or Linux:

f=$(ls -t ./magellan-lite*.vsix ~/Downloads/magellan-lite*.vsix ~/Desktop/magellan-lite*.vsix 2>/dev/null | head -1); [ -n "$f" ] || { f=/tmp/magellan-lite.vsix; curl -fsSL -o "$f" https://magellan-code.pages.dev/downloads/magellan-lite.vsix; }; code --install-extension "$f" --force

Then

  1. Open a folder that is a git repository.
  2. Save a change: the status bar says ok, review or block, and each finding shows where the damage lands, even in files you didn't open.
  3. Magellan Lite: Show the map: click into a function and the map shows what it reaches; the lock holds it still.
  4. Turn on Share On Save and Open the Team suite: your team sees your work in progress as you go.

Team

Brayton

The engine and backend (map, diff, blast radius), the local server and the VS Code extension

Braxton

The website

Faidh

Website quality checks, and tasks on the VS Code extension