How Blast Radius Analysis Traces Affected Code Through the Dependency Graph in code-review-graph
The blast radius analysis in code-review-graph traces affected code by performing a forward reachability walk from changed symbols through a multi-language dependency graph, following call, import, and inheritance edges with configurable depth limits and edge-weighted heuristics.
code-review-graph is an open-source tool that builds language-aware dependency graphs for code repositories and analyzes the cascading impact of changes. Its blast radius analysis identifies every symbol that could be affected by a code change—directly or indirectly—by traversing the dependency graph starting from modified nodes. Understanding how this traversal works helps developers prioritize review attention, select relevant tests, and assess deployment risk.
How the Dependency Graph Is Constructed
Before any impact analysis can run, code-review-graph assembles a comprehensive graph of code relationships. This happens in code_review_graph/graph.py, which defines the core data structures (Graph, Node, Edge) and utilities for populating them.
The graph construction process involves multiple edge types:
- Call edges — when function A calls function B, a directed edge A→B is created
- Import edges —
import Xorfrom X import …adds edges from importing modules to imported symbols - Inheritance edges — class inheritance relationships are captured as directed edges
- Attribute access edges — symbol lookups and attribute resolutions generate additional connections
Language-specific resolvers populate these edges. For Python, code_review_graph/jedi_resolver.py uses the Jedi library to parse source files and resolve cross-language references. Other resolvers handle additional languages in multi-codebase scenarios.
Detecting Changes: Building the Seed Set
Blast radius analysis requires a starting point: the set of symbols modified in a change. This detection occurs in code_review_graph/graph_diff.py, which computes symbol-level diffs between graph snapshots.
The diff engine identifies:
- Added symbols (new functions, classes, or variables)
- Modified symbols (bodies changed while signatures remain)
- Removed symbols (deleted code that may have dependents)
These touched symbols become the seed set for blast radius traversal. Without accurate seed detection, downstream impact analysis would miss critical entry points or waste cycles on unchanged code.
The Blast Radius Traversal Algorithm
The core impact analysis lives in code_review_graph/analysis.py. Starting from the seed set, the engine performs a forward reachability walk that follows outgoing dependency edges to discover all affected symbols.
Traversal Mechanics
The algorithm operates breadth-first or depth-first depending on configuration, with several key behaviors:
- Edge weighting — call edges carry higher impact weight than import edges, allowing the engine to prioritize runtime-affected paths over structural dependencies
- Depth limits — configurable
max_depthparameters cap traversal distance from seed symbols - Pruning heuristics — symbols marked as private (names starting with
_) can be excluded to reduce noise in the output
The traversal accumulates all reachable nodes into the final blast radius set: every symbol that might exhibit changed behavior due to the original modification.
Code Example: Using the Python API
from code_review_graph.analysis import blast_radius
from code_review_graph.graph import Graph
# Build the full graph for the repository (cached on first run)
graph = Graph.from_repo_path('.')
# Define seed symbols from a detected diff
changed_symbols = {'my_module.my_function', 'my_module.HelperClass'}
# Execute blast radius analysis with depth limiting
affected = blast_radius(
graph,
seeds=changed_symbols,
max_depth=5 # Stop traversal after 5 dependency hops
)
print(f"Found {len(affected)} potentially impacted symbols:")
for symbol in sorted(affected):
print(f" - {symbol}")
This API pattern enables integration into custom tooling, CI pipelines, and automated review systems.
CLI Integration and Practical Usage
The tool exposes blast radius functionality through a command-line interface defined in code_review_graph/cli.py. Developers can quickly assess local changes without writing Python code.
Running Blast Radius from the Command Line
# Analyze impact of changes in a specific file
code-review-graph blast-radius --file src/core/parser.py
# Output results as JSON for downstream processing
code-review-graph blast-radius --json --file src/core/parser.py > impact.json
# Limit search depth for faster results on large codebases
code-review-graph blast-radius --file src/core/parser.py --max-depth 3
CI/CD Pipeline Integration
# .github/workflows/blast-radius.yml
name: Blast Radius Impact Check
on:
push:
paths:
- '**/*.py'
jobs:
impact:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v3
- name: Install code-review-graph
run: pip install code-review-graph
- name: Compute blast radius
id: impact
run: |
IMPACT_COUNT=$(code-review-graph blast-radius --json | jq '.nodes | length')
echo "affected_count=$IMPACT_COUNT" >> $GITHUB_OUTPUT
- name: Flag large blast radius
if: ${{ steps.impact.outputs.affected_count > 50 }}
run: |
echo "::warning::Large blast radius detected: ${{ steps.impact.outputs.affected_count }} symbols affected"
This pattern enforces impact thresholds, triggering additional review requirements when changes touch too much of the codebase.
Key Source Files for Blast Radius Analysis
| File | Purpose |
|---|---|
code_review_graph/graph.py |
Core graph data structures and construction utilities |
code_review_graph/jedi_resolver.py |
Python-specific symbol resolution using Jedi |
code_review_graph/graph_diff.py |
Symbol-level diff computation producing seed sets |
code_review_graph/analysis.py |
Forward reachability engine for blast radius traversal |
code_review_graph/cli.py |
Command-line interface for blast-radius commands |
Summary
code-review-graphbuilds a multi-language dependency graph with call, import, and inheritance edges- Change detection in
graph_diff.pyproduces a seed set of modified symbols - Blast radius analysis in
analysis.pyperforms forward reachability from seeds with edge weighting and depth limits - Both Python API and CLI interfaces enable flexible integration into developer workflows
- The traversal respects pruning heuristics to filter noise and focus on meaningful impact
Frequently Asked Questions
What edge types does the blast radius analyzer follow?
The analyzer follows call edges, import edges, inheritance edges, and attribute access edges. Call edges receive higher weight in impact scoring than structural dependencies like imports.
How does the tool handle multi-language repositories?
code_review_graph/graph.py aggregates edges from multiple language-specific resolvers. The Python resolver in jedi_resolver.py handles Python files, while other resolvers can be added for additional languages. All edges feed into the same unified graph for cross-language impact analysis.
Can I exclude certain symbols from blast radius results?
Yes. The traversal supports pruning heuristics that exclude private symbols (names starting with _) and can apply custom filters based on symbol patterns, file paths, or edge weights. Configure these through the blast_radius() API parameters.
What performance optimizations exist for large codebases?
The engine implements depth limiting via max_depth parameters, caching of constructed graphs between runs, and incremental diff computation to avoid rebuilding the full graph on every change. For monorepos, consider setting conservative depth limits and filtering seed sets to modified packages only
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →