How Blast Radius Analysis Traces Affected Code Through the Dependency Graph in code-review-graph

The blast radius analysis in code-review-graph traces affected code by performing a forward reachability walk from changed symbols through a multi-language dependency graph, following call, import, and inheritance edges with configurable depth limits and edge-weighted heuristics.

code-review-graph is an open-source tool that builds language-aware dependency graphs for code repositories and analyzes the cascading impact of changes. Its blast radius analysis identifies every symbol that could be affected by a code change—directly or indirectly—by traversing the dependency graph starting from modified nodes. Understanding how this traversal works helps developers prioritize review attention, select relevant tests, and assess deployment risk.

How the Dependency Graph Is Constructed

Before any impact analysis can run, code-review-graph assembles a comprehensive graph of code relationships. This happens in code_review_graph/graph.py, which defines the core data structures (Graph, Node, Edge) and utilities for populating them.

The graph construction process involves multiple edge types:

  • Call edges — when function A calls function B, a directed edge A→B is created
  • Import edges — import X or from X import … adds edges from importing modules to imported symbols
  • Inheritance edges — class inheritance relationships are captured as directed edges
  • Attribute access edges — symbol lookups and attribute resolutions generate additional connections

Language-specific resolvers populate these edges. For Python, code_review_graph/jedi_resolver.py uses the Jedi library to parse source files and resolve cross-language references. Other resolvers handle additional languages in multi-codebase scenarios.

Detecting Changes: Building the Seed Set

Blast radius analysis requires a starting point: the set of symbols modified in a change. This detection occurs in code_review_graph/graph_diff.py, which computes symbol-level diffs between graph snapshots.

The diff engine identifies:

  • Added symbols (new functions, classes, or variables)
  • Modified symbols (bodies changed while signatures remain)
  • Removed symbols (deleted code that may have dependents)

These touched symbols become the seed set for blast radius traversal. Without accurate seed detection, downstream impact analysis would miss critical entry points or waste cycles on unchanged code.

The Blast Radius Traversal Algorithm

The core impact analysis lives in code_review_graph/analysis.py. Starting from the seed set, the engine performs a forward reachability walk that follows outgoing dependency edges to discover all affected symbols.

Traversal Mechanics

The algorithm operates breadth-first or depth-first depending on configuration, with several key behaviors:

  • Edge weighting — call edges carry higher impact weight than import edges, allowing the engine to prioritize runtime-affected paths over structural dependencies
  • Depth limits — configurable max_depth parameters cap traversal distance from seed symbols
  • Pruning heuristics — symbols marked as private (names starting with _) can be excluded to reduce noise in the output

The traversal accumulates all reachable nodes into the final blast radius set: every symbol that might exhibit changed behavior due to the original modification.

Code Example: Using the Python API

from code_review_graph.analysis import blast_radius
from code_review_graph.graph import Graph

# Build the full graph for the repository (cached on first run)

graph = Graph.from_repo_path('.')

# Define seed symbols from a detected diff

changed_symbols = {'my_module.my_function', 'my_module.HelperClass'}

# Execute blast radius analysis with depth limiting

affected = blast_radius(
    graph,
    seeds=changed_symbols,
    max_depth=5  # Stop traversal after 5 dependency hops

)

print(f"Found {len(affected)} potentially impacted symbols:")
for symbol in sorted(affected):
    print(f"  - {symbol}")

This API pattern enables integration into custom tooling, CI pipelines, and automated review systems.

CLI Integration and Practical Usage

The tool exposes blast radius functionality through a command-line interface defined in code_review_graph/cli.py. Developers can quickly assess local changes without writing Python code.

Running Blast Radius from the Command Line


# Analyze impact of changes in a specific file

code-review-graph blast-radius --file src/core/parser.py

# Output results as JSON for downstream processing

code-review-graph blast-radius --json --file src/core/parser.py > impact.json

# Limit search depth for faster results on large codebases

code-review-graph blast-radius --file src/core/parser.py --max-depth 3

CI/CD Pipeline Integration


# .github/workflows/blast-radius.yml

name: Blast Radius Impact Check
on:
  push:
    paths:
      - '**/*.py'

jobs:
  impact:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v3
      
      - name: Install code-review-graph
        run: pip install code-review-graph
      
      - name: Compute blast radius
        id: impact
        run: |
          IMPACT_COUNT=$(code-review-graph blast-radius --json | jq '.nodes | length')
          echo "affected_count=$IMPACT_COUNT" >> $GITHUB_OUTPUT
      
      - name: Flag large blast radius
        if: ${{ steps.impact.outputs.affected_count > 50 }}
        run: |
          echo "::warning::Large blast radius detected: ${{ steps.impact.outputs.affected_count }} symbols affected"

This pattern enforces impact thresholds, triggering additional review requirements when changes touch too much of the codebase.

Key Source Files for Blast Radius Analysis

File Purpose
code_review_graph/graph.py Core graph data structures and construction utilities
code_review_graph/jedi_resolver.py Python-specific symbol resolution using Jedi
code_review_graph/graph_diff.py Symbol-level diff computation producing seed sets
code_review_graph/analysis.py Forward reachability engine for blast radius traversal
code_review_graph/cli.py Command-line interface for blast-radius commands

Summary

  • code-review-graph builds a multi-language dependency graph with call, import, and inheritance edges
  • Change detection in graph_diff.py produces a seed set of modified symbols
  • Blast radius analysis in analysis.py performs forward reachability from seeds with edge weighting and depth limits
  • Both Python API and CLI interfaces enable flexible integration into developer workflows
  • The traversal respects pruning heuristics to filter noise and focus on meaningful impact

Frequently Asked Questions

What edge types does the blast radius analyzer follow?

The analyzer follows call edges, import edges, inheritance edges, and attribute access edges. Call edges receive higher weight in impact scoring than structural dependencies like imports.

How does the tool handle multi-language repositories?

code_review_graph/graph.py aggregates edges from multiple language-specific resolvers. The Python resolver in jedi_resolver.py handles Python files, while other resolvers can be added for additional languages. All edges feed into the same unified graph for cross-language impact analysis.

Can I exclude certain symbols from blast radius results?

Yes. The traversal supports pruning heuristics that exclude private symbols (names starting with _) and can apply custom filters based on symbol patterns, file paths, or edge weights. Configure these through the blast_radius() API parameters.

What performance optimizations exist for large codebases?

The engine implements depth limiting via max_depth parameters, caching of constructed graphs between runs, and incremental diff computation to avoid rebuilding the full graph on every change. For monorepos, consider setting conservative depth limits and filtering seed sets to modified packages only

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →