Skip to main content

⚡ ApiPatch

Autonomous AI Agent for API Breaking Changes & Self-Maintaining Codebases

License: MIT Python 3.9+ PyPI version Open Source Tests: Passing


🛑 The Problem

Over 30% of cloud outages and broken builds are caused by silent, third-party API breaking changes. When vendors release major SDK updates (OpenAI v1.0+, Pydantic v2, Stripe SCA/PaymentIntents, LangChain LCEL, React hooks, Next.js App Router…), engineering teams spend days hunting broken calls and rewriting legacy code.

Tools like Dependabot and Renovate only bump version numbers in requirements.txt or package.json—they do not fix actual code logic.

[ Traditional Dependency Bumper ]
  requirements.txt: openai==0.28.0 ──► openai==1.50.0 ──❌ (Code breaks at runtime!)

[ ApiPatch Autonomous Agent ]
  1. Detects breaking API calls across ANY library — Python, JS, TS, JSX, TSX…
  2. Refactors code via LLM reasoning (Gemini 2.5 Flash Lite, Claude, GPT-4o)
  3. Validates safety & self-heals syntax/structure via AST feedback loop
  4. Generates ready-to-merge Pull Requests ───────────────────────✅ (Build passes!)

🚀 Key Features

  • 🌟 Smart 2026 Repository Discovery (apipatch discover): Automatically finds trending, active, non-archived repositories updated in the last 30 days and audits them for breaking changes.
  • 🤖 Autonomous GitHub PR Pipeline (apipatch pr): Scans an entire remote repository, auto-forks/branches, commits refactorings via atomic Git Database API, and opens live Pull Requests.
  • 10x Faster Parallel Auditing: Inspects multiple candidate files concurrently using multi-threaded asynchronous workers (ThreadPoolExecutor).
  • 🩺 AST Self-Healing Feedback Loop: Automatically catches any LLM syntax errors or dropped functions and directs the AI to self-heal before outputting code.
  • 💡 Optimized gemini-2.5-flash-lite Engine: Sub-second dynamic reasoning with smooth quota pacing and automated fallbacks.
  • GitHub App & Webhook Daemon (apipatch webhook): Listens for repository push events, verifies HMAC signatures, and autonomously runs the audit & PR pipeline in the background.
  • 🔑 Smart Token Discovery: Automatically resolves GitHub tokens from CLI flags, GITHUB_TOKEN / GH_TOKEN env, github_token.txt file, or .env.
  • 🧠 Universal LLM Engine: Audits ANY third-party library in any language dynamically — no hardcoded rules required.
  • 🌐 Multi-Language Support: Full support for .py, .js, .ts, .jsx, .tsx, .mjs, .cjs files.
  • 🛡️ AST & Safety Guard: Validates every refactored Python file through AST syntax parsing. JS/TS files checked for truncation and brace/bracket balance.
  • 📦 Flexible CLI: Rich terminal interface with discover, pr, scan, fix --write, detect, hunt, webhook, and --output report.json.
  • 🔄 Safe In-Place Refactoring: Automatically generates .bak backups before modifying local files.

🌍 Universal Coverage — Any Library, Any Language

ApiPatch is not limited to a fixed list of rules. The LLM engine can detect and fix breaking changes in any third-party library it has been trained on, including:

Language Libraries / Frameworks
Python OpenAI (v0.x → v1.x), Pydantic (v1 → v2 @field_validator), Stripe (Charge → PaymentIntent), LangChain (LLMChain → LCEL), Supabase, SQLAlchemy, FastAPI, Boto3/AWS, Celery, HuggingFace, and more
JavaScript / TypeScript React (class → hooks), Next.js (Pages → App Router), Axios, Stripe.js, Supabase JS, OpenAI Node SDK, Express, and more
Any Language If the LLM knows about a library's breaking change, ApiPatch can fix it

⚡ Quickstart

1. Installation

pip install apipatch

Or install from Git:

pip install git+https://github.com/MoradMoqbel/apipatch.git

🔑 Setting Up AI & GitHub Tokens

AI Provider Keys

Create a .env file in your directory or export variables:

# Google Gemini (Fastest & Free Tier Available)
GEMINI_API_KEY="AIzaSy..."

# OpenAI
OPENAI_API_KEY="sk-..."

# Anthropic Claude
ANTHROPIC_API_KEY="sk-ant-..."

GitHub Token Setup

ApiPatch automatically resolves your GitHub token in this priority:

  1. --token <ghp_...> CLI option
  2. GITHUB_TOKEN or GH_TOKEN environment variable
  3. github_token.txt in your working directory or project root
  4. .env file

💻 CLI Commands & Usage

1. 🌟 Smart Active Repository Discovery (New in v0.6.0)

Discovers trending, modern 2026 repositories and audits them for breaking changes:

# Discover AI repositories updated in the last 30 days with 10+ stars
apipatch discover "topic:ai language:python" --days 30 --min-stars 10

# Discover FastAPI & LLM projects
apipatch discover "fastapi topic:ai" --days 30 --min-stars 10

# Submit live Pull Requests automatically on discovered repositories
apipatch discover "topic:llm language:python" --days 30 --submit

2. 🚀 Autonomous Live GitHub Pull Request

Audits an entire GitHub repository, forks if needed, commits modernized files, and opens a real live PR:

# Dry run / preview changes without opening PR
apipatch pr owner/repo --dry-run

# Open live PR on repository
apipatch pr owner/repo

3. 🎯 Proactive GitHub Code Hunter

Searches GitHub for legacy patterns with strict recency and star filters:

# Search for Pydantic v1 @validator in repositories updated in last 30 days
apipatch hunt "from pydantic import validator language:python" --days 30 --min-stars 10

# Search for OpenAI v0.x legacy calls
apipatch hunt "openai.ChatCompletion.create language:python" --days 60 --min-stars 10

4. ⚡ GitHub App Webhook Daemon

Runs the continuous webhook server to trigger autonomous PRs on every repository push:

apipatch webhook --port 8080 --secret "my_webhook_secret"

5. 🔍 Scan a Codebase Locally (Dry Run)

Audits local files recursively, detects deprecated calls, and outputs colorized diff previews:

apipatch scan /path/to/project
apipatch scan /path/to/project --provider gemini

6. ⚡ Refactor and Apply Fixes In-Place

Automatically updates local code with .bak safety backups:

apipatch fix /path/to/project --write

🧪 Testing

pytest

All 76 tests are offline-safe and mocked (no external network or live LLM required for the test suite).


🗺️ Roadmap

  • Universal LLM engine — no hardcoded rules, ANY library supported
  • Multi-language support: Python, JavaScript, TypeScript, JSX, TSX
  • AST Syntax & Safety Validator
  • Multi-LLM Provider (Gemini 2.5 Flash Lite, OpenAI, Claude) with auto-discovery
  • In-place refactoring with automatic backup (--write)
  • Automated test suite (76/76 tests passing)
  • v0.5.0: Autonomous GitHub PR Engine (apipatch pr)
  • v0.5.0: GitHub App Webhook Daemon (apipatch webhook)
  • v0.6.0: Smart 2026 Repository Discovery Engine (apipatch discover)
  • v0.6.0: Multi-threaded parallel file auditing (10x performance boost)
  • v0.6.0: AST Self-Healing feedback loop
  • PyPI Release (pip install apipatch)

📄 License

MIT License. Built by Morad Moqbel.

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

apipatch-0.6.2.tar.gz (61.4 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

apipatch-0.6.2-py3-none-any.whl (55.9 kB view details)

Uploaded Python 3

File details

Details for the file apipatch-0.6.2.tar.gz.

File metadata

  • Download URL: apipatch-0.6.2.tar.gz
  • Upload date:
  • Size: 61.4 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/7.0.0 CPython/3.13.2

File hashes

Hashes for apipatch-0.6.2.tar.gz
Algorithm Hash digest
SHA256 045ad1f111c3e026cad6bbbd37f65e3a8c756dfc477d4bf50cfc35acfc7641af
MD5 90834a775e9ff466e8f4036a40e2d5d9
BLAKE2b-256 a7f5bc973cec803727f30d5025190feb4dc09cc50335c4433a32f395454fe12b

See more details on using hashes here.

File details

Details for the file apipatch-0.6.2-py3-none-any.whl.

File metadata

  • Download URL: apipatch-0.6.2-py3-none-any.whl
  • Upload date:
  • Size: 55.9 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/7.0.0 CPython/3.13.2

File hashes

Hashes for apipatch-0.6.2-py3-none-any.whl
Algorithm Hash digest
SHA256 5ea190382c7b3814415ef7f8c4f29b0f305e752ce508923f5c3a9de9e13742ea
MD5 ac826b2f4a2f4d9e24bab6ba2c6458a0
BLAKE2b-256 cfcf9b2de963951e39ae2394314170fe5936846854f2f6d6f52288d44df8b21b

See more details on using hashes here.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page