# How Blast Radius Analysis Traces Affected Code Through the Dependency Graph in code-review-graph

> Discover how blast radius analysis traces affected code in code-review-graph. Learn how it uses dependency graphs and reachability walks to map code changes and their impact.

- Repository: [Tirth Kanani/code-review-graph](https://github.com/tirth8205/code-review-graph)
- Tags: deep-dive
- Published: 2026-08-14

---

**The blast radius analysis in `code-review-graph` traces affected code by performing a forward reachability walk from changed symbols through a multi-language dependency graph, following call, import, and inheritance edges with configurable depth limits and edge-weighted heuristics.**

`code-review-graph` is an open-source tool that builds language-aware dependency graphs for code repositories and analyzes the cascading impact of changes. Its **blast radius analysis** identifies every symbol that could be affected by a code change—directly or indirectly—by traversing the dependency graph starting from modified nodes. Understanding how this traversal works helps developers prioritize review attention, select relevant tests, and assess deployment risk.

## How the Dependency Graph Is Constructed

Before any impact analysis can run, `code-review-graph` assembles a comprehensive graph of code relationships. This happens in [`code_review_graph/graph.py`](https://github.com/tirth8205/code-review-graph/blob/main/code_review_graph/graph.py), which defines the core data structures (`Graph`, `Node`, `Edge`) and utilities for populating them.

The graph construction process involves multiple edge types:

- **Call edges** — when function A calls function B, a directed edge A→B is created
- **Import edges** — `import X` or `from X import …` adds edges from importing modules to imported symbols
- **Inheritance edges** — class inheritance relationships are captured as directed edges
- **Attribute access edges** — symbol lookups and attribute resolutions generate additional connections

Language-specific resolvers populate these edges. For Python, [`code_review_graph/jedi_resolver.py`](https://github.com/tirth8205/code-review-graph/blob/main/code_review_graph/jedi_resolver.py) uses the Jedi library to parse source files and resolve cross-language references. Other resolvers handle additional languages in multi-codebase scenarios.

## Detecting Changes: Building the Seed Set

Blast radius analysis requires a starting point: the set of symbols modified in a change. This detection occurs in [`code_review_graph/graph_diff.py`](https://github.com/tirth8205/code-review-graph/blob/main/code_review_graph/graph_diff.py), which computes symbol-level diffs between graph snapshots.

The diff engine identifies:

- Added symbols (new functions, classes, or variables)
- Modified symbols (bodies changed while signatures remain)
- Removed symbols (deleted code that may have dependents)

These **touched symbols** become the **seed set** for blast radius traversal. Without accurate seed detection, downstream impact analysis would miss critical entry points or waste cycles on unchanged code.

## The Blast Radius Traversal Algorithm

The core impact analysis lives in [`code_review_graph/analysis.py`](https://github.com/tirth8205/code-review-graph/blob/main/code_review_graph/analysis.py). Starting from the seed set, the engine performs a **forward reachability walk** that follows outgoing dependency edges to discover all affected symbols.

### Traversal Mechanics

The algorithm operates breadth-first or depth-first depending on configuration, with several key behaviors:

- **Edge weighting** — call edges carry higher impact weight than import edges, allowing the engine to prioritize runtime-affected paths over structural dependencies
- **Depth limits** — configurable `max_depth` parameters cap traversal distance from seed symbols
- **Pruning heuristics** — symbols marked as private (names starting with `_`) can be excluded to reduce noise in the output

The traversal accumulates all reachable nodes into the final **blast radius set**: every symbol that might exhibit changed behavior due to the original modification.

### Code Example: Using the Python API

```python
from code_review_graph.analysis import blast_radius
from code_review_graph.graph import Graph

# Build the full graph for the repository (cached on first run)

graph = Graph.from_repo_path('.')

# Define seed symbols from a detected diff

changed_symbols = {'my_module.my_function', 'my_module.HelperClass'}

# Execute blast radius analysis with depth limiting

affected = blast_radius(
    graph,
    seeds=changed_symbols,
    max_depth=5  # Stop traversal after 5 dependency hops

)

print(f"Found {len(affected)} potentially impacted symbols:")
for symbol in sorted(affected):
    print(f"  - {symbol}")

```

This API pattern enables integration into custom tooling, CI pipelines, and automated review systems.

## CLI Integration and Practical Usage

The tool exposes blast radius functionality through a command-line interface defined in [`code_review_graph/cli.py`](https://github.com/tirth8205/code-review-graph/blob/main/code_review_graph/cli.py). Developers can quickly assess local changes without writing Python code.

### Running Blast Radius from the Command Line

```bash

# Analyze impact of changes in a specific file

code-review-graph blast-radius --file src/core/parser.py

# Output results as JSON for downstream processing

code-review-graph blast-radius --json --file src/core/parser.py > impact.json

# Limit search depth for faster results on large codebases

code-review-graph blast-radius --file src/core/parser.py --max-depth 3

```

### CI/CD Pipeline Integration

```yaml

# .github/workflows/blast-radius.yml

name: Blast Radius Impact Check
on:
  push:
    paths:
      - '**/*.py'

jobs:
  impact:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v3
      
      - name: Install code-review-graph
        run: pip install code-review-graph
      
      - name: Compute blast radius
        id: impact
        run: |
          IMPACT_COUNT=$(code-review-graph blast-radius --json | jq '.nodes | length')
          echo "affected_count=$IMPACT_COUNT" >> $GITHUB_OUTPUT
      
      - name: Flag large blast radius
        if: ${{ steps.impact.outputs.affected_count > 50 }}
        run: |
          echo "::warning::Large blast radius detected: ${{ steps.impact.outputs.affected_count }} symbols affected"

```

This pattern enforces impact thresholds, triggering additional review requirements when changes touch too much of the codebase.

## Key Source Files for Blast Radius Analysis

| File | Purpose |
|------|---------|
| [`code_review_graph/graph.py`](https://github.com/tirth8205/code-review-graph/blob/main/code_review_graph/graph.py) | Core graph data structures and construction utilities |
| [`code_review_graph/jedi_resolver.py`](https://github.com/tirth8205/code-review-graph/blob/main/code_review_graph/jedi_resolver.py) | Python-specific symbol resolution using Jedi |
| [`code_review_graph/graph_diff.py`](https://github.com/tirth8205/code-review-graph/blob/main/code_review_graph/graph_diff.py) | Symbol-level diff computation producing seed sets |
| [`code_review_graph/analysis.py`](https://github.com/tirth8205/code-review-graph/blob/main/code_review_graph/analysis.py) | Forward reachability engine for blast radius traversal |
| [`code_review_graph/cli.py`](https://github.com/tirth8205/code-review-graph/blob/main/code_review_graph/cli.py) | Command-line interface for `blast-radius` commands |

## Summary

- `code-review-graph` builds a **multi-language dependency graph** with call, import, and inheritance edges
- **Change detection** in [`graph_diff.py`](https://github.com/tirth8205/code-review-graph/blob/main/graph_diff.py) produces a seed set of modified symbols
- **Blast radius analysis** in [`analysis.py`](https://github.com/tirth8205/code-review-graph/blob/main/analysis.py) performs forward reachability from seeds with edge weighting and depth limits
- Both **Python API** and **CLI** interfaces enable flexible integration into developer workflows
- The traversal respects **pruning heuristics** to filter noise and focus on meaningful impact

## Frequently Asked Questions

### What edge types does the blast radius analyzer follow?

The analyzer follows **call edges**, **import edges**, **inheritance edges**, and **attribute access edges**. Call edges receive higher weight in impact scoring than structural dependencies like imports.

### How does the tool handle multi-language repositories?

[`code_review_graph/graph.py`](https://github.com/tirth8205/code-review-graph/blob/main/code_review_graph/graph.py) aggregates edges from multiple language-specific resolvers. The Python resolver in [`jedi_resolver.py`](https://github.com/tirth8205/code-review-graph/blob/main/jedi_resolver.py) handles Python files, while other resolvers can be added for additional languages. All edges feed into the same unified graph for cross-language impact analysis.

### Can I exclude certain symbols from blast radius results?

Yes. The traversal supports **pruning heuristics** that exclude private symbols (names starting with `_`) and can apply custom filters based on symbol patterns, file paths, or edge weights. Configure these through the `blast_radius()` API parameters.

### What performance optimizations exist for large codebases?

The engine implements **depth limiting** via `max_depth` parameters, **caching** of constructed graphs between runs, and **incremental diff computation** to avoid rebuilding the full graph on every change. For monorepos, consider setting conservative depth limits and filtering seed sets to modified packages only