Skip to main content

⚡ ApiPatch

Autonomous AI Agent for API Breaking Changes & Self-Maintaining Codebases

License: MIT Python 3.9+ PyPI version Open Source Tests: Passing


🛑 The Problem

Over 30% of cloud outages and broken builds are caused by silent, third-party API breaking changes. When vendors release major SDK updates (OpenAI v1.0+, Pydantic v2, Stripe SCA/PaymentIntents, LangChain LCEL, React hooks, Next.js App Router…), engineering teams spend days hunting broken calls and rewriting legacy code.

Tools like Dependabot and Renovate only bump version numbers in requirements.txt or package.json—they do not fix actual code logic.

[ Traditional Dependency Bumper ]
  requirements.txt: openai==0.28.0 ──► openai==1.50.0 ──❌ (Code breaks at runtime!)

[ ApiPatch Autonomous Agent ]
  1. Detects breaking API calls across ANY library — Python, JS, TS, JSX, TSX…
  2. DocHunter™ Live Grounding: Fetches official PyPI/npm/GitHub docs & changelogs in 0.1s
  3. Refactors code via LLM reasoning grounded in official documentation
  4. Validates safety & self-heals syntax/structure via AST feedback loop
  5. Generates ready-to-merge Pull Requests ───────────────────────✅ (Build passes!)

🚀 Key Features

  • 🌐 DocHunter™ Live Official Documentation Grounding: Automatically resolves live PyPI/npm package metadata, official documentation URLs, and GitHub changelogs in <0.1s to eliminate hallucinations.
  • 🌟 Smart 2026 Repository Discovery (apipatch discover): Automatically finds trending, active, non-archived repositories updated in the last 30 days and audits them for breaking changes.
  • 🤖 Autonomous GitHub PR Pipeline (apipatch pr): Scans an entire remote repository, auto-forks/branches, commits refactorings via atomic Git Database API, and opens live Pull Requests.
  • ⚡ 10x Faster Parallel Auditing: Inspects multiple candidate files concurrently using multi-threaded asynchronous workers (ThreadPoolExecutor).
  • 🩺 AST Self-Healing Feedback Loop: Automatically catches any LLM syntax errors or dropped functions and directs the AI to self-heal before outputting code.
  • 💡 Optimized gemini-2.5-flash-lite Engine: Sub-second dynamic reasoning with smooth quota pacing and automated fallbacks.
  • ⚡ GitHub App & Webhook Daemon (apipatch webhook): Listens for repository push events, verifies HMAC signatures, and autonomously runs the audit & PR pipeline in the background.
  • 🔑 Smart Token Discovery: Automatically resolves GitHub tokens from CLI flags, GITHUB_TOKEN / GH_TOKEN env, github_token.txt file, or .env.
  • 🧠 Universal LLM Engine: Audits ANY third-party library in any language dynamically — no hardcoded rules required.
  • 🌐 Multi-Language Support: Full support for .py, .js, .ts, .jsx, .tsx, .mjs, .cjs files.
  • 🛡️ AST & Safety Guard: Validates every refactored Python file through AST syntax parsing. JS/TS files checked for truncation and brace/bracket balance.
  • 📦 Flexible CLI: Rich terminal interface with discover, pr, scan, fix --write, detect, hunt, webhook, and --output report.json.
  • 🔄 Safe In-Place Refactoring: Automatically generates .bak backups before modifying local files.

🌍 Universal Coverage — Any Library, Any Language

ApiPatch is not limited to a fixed list of rules. The LLM engine can detect and fix breaking changes in any third-party library it has been trained on, including:

Language Libraries / Frameworks
Python OpenAI (v0.x → v1.x), Pydantic (v1 → v2 @field_validator), Stripe (Charge → PaymentIntent), LangChain (LLMChain → LCEL), Supabase, SQLAlchemy, FastAPI, Boto3/AWS, Celery, HuggingFace, and more
JavaScript / TypeScript React (class → hooks), Next.js (Pages → App Router), Axios, Stripe.js, Supabase JS, OpenAI Node SDK, Express, and more
Any Language If the LLM knows about a library's breaking change, ApiPatch can fix it

⚡ Quickstart

1. Installation

pip install apipatch

Or install from Git:

pip install git+https://github.com/MoradMoqbel/apipatch.git

🔑 Setting Up AI & GitHub Tokens

AI Provider Keys

Create a .env file in your directory or export variables:

# Google Gemini (Fastest & Free Tier Available)
GEMINI_API_KEY="AIzaSy..."

# OpenAI
OPENAI_API_KEY="sk-..."

# Anthropic Claude
ANTHROPIC_API_KEY="sk-ant-..."

GitHub Token Setup

ApiPatch automatically resolves your GitHub token in this priority:

  1. --token <ghp_...> CLI option
  2. GITHUB_TOKEN or GH_TOKEN environment variable
  3. github_token.txt in your working directory or project root
  4. .env file

💻 CLI Commands & Usage

1. 🌟 Smart Active Repository Discovery (New in v0.6.0)

Discovers trending, modern 2026 repositories and audits them for breaking changes:

# Discover AI repositories updated in the last 30 days with 10+ stars
apipatch discover "topic:ai language:python" --days 30 --min-stars 10

# Discover FastAPI & LLM projects
apipatch discover "fastapi topic:ai" --days 30 --min-stars 10

# Submit live Pull Requests automatically on discovered repositories
apipatch discover "topic:llm language:python" --days 30 --submit

2. 🚀 Autonomous Live GitHub Pull Request

Audits an entire GitHub repository, forks if needed, commits modernized files, and opens a real live PR:

# Dry run / preview changes without opening PR
apipatch pr owner/repo --dry-run

# Open live PR on repository
apipatch pr owner/repo

3. 🎯 Proactive GitHub Code Hunter

Searches GitHub for legacy patterns with strict recency and star filters:

# Search for Pydantic v1 @validator in repositories updated in last 30 days
apipatch hunt "from pydantic import validator language:python" --days 30 --min-stars 10

# Search for OpenAI v0.x legacy calls
apipatch hunt "openai.ChatCompletion.create language:python" --days 60 --min-stars 10

4. ⚡ GitHub App Webhook Daemon

Runs the continuous webhook server to trigger autonomous PRs on every repository push:

apipatch webhook --port 8080 --secret "my_webhook_secret"

5. 🔍 Scan a Codebase Locally (Dry Run)

Audits local files recursively, detects deprecated calls, and outputs colorized diff previews:

apipatch scan /path/to/project
apipatch scan /path/to/project --provider gemini

6. ⚡ Refactor and Apply Fixes In-Place

Automatically updates local code with .bak safety backups:

apipatch fix /path/to/project --write

🧪 Testing

pytest

All 76 tests are offline-safe and mocked (no external network or live LLM required for the test suite).


🗺️ Roadmap

  • Universal LLM engine — no hardcoded rules, ANY library supported
  • Multi-language support: Python, JavaScript, TypeScript, JSX, TSX
  • AST Syntax & Safety Validator
  • Multi-LLM Provider (Gemini 2.5 Flash Lite, OpenAI, Claude) with auto-discovery
  • In-place refactoring with automatic backup (--write)
  • Automated test suite (76/76 tests passing)
  • v0.5.0: Autonomous GitHub PR Engine (apipatch pr)
  • v0.5.0: GitHub App Webhook Daemon (apipatch webhook)
  • v0.6.0: Smart 2026 Repository Discovery Engine (apipatch discover)
  • v0.6.0: Multi-threaded parallel file auditing (10x performance boost)
  • v0.6.0: AST Self-Healing feedback loop
  • PyPI Release (pip install apipatch)

📄 License

MIT License. Built by Morad Moqbel.

Metadata

Release files for apipatch 0.7.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for apipatch 0.7.0
File Size Uploaded
apipatch-0.7.0.tar.gz 67.6 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for apipatch 0.7.0
File Interpreter ABI Platform
apipatch-0.7.0-py3-none-any.whl Python 3 none any Details

Total release size: 128.7 kB

Release files / apipatch-0.7.0.tar.gz

Download URL apipatch-0.7.0.tar.gz
Size 67.6 kB
Tags Source
SHA-256 checksum
How to use checksums
afe0ced32fd18832b495296af1830ee261acccf4ed8b51f8d8afba29fdd58cf7
BLAKE2b-256 checksum
How to use checksums
afcb4cfba95391e3b55976879057285e3a23ca2932ea97eaeb0df2da7bf65267
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.13.2

Release files / apipatch-0.7.0-py3-none-any.whl

Download URL apipatch-0.7.0-py3-none-any.whl
Size 61.1 kB
Tags Python 3
SHA-256 checksum
How to use checksums
53706062c38e7140f97dc7af9363f465f726a147c72754a099ee1e0b4d14d081
BLAKE2b-256 checksum
How to use checksums
64419483e9e3c2270a90cabd8b723d30c97acdc868f79b68bdb5a2eb5d832881
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.13.2

Release history Release notifications | RSS feed

0.9.0

2 release files

0.8.2

2 release files

0.8.1

2 release files

0.8.0

2 release files

0.7.4

2 release files

0.7.3

2 release files

0.7.2

2 release files

This release

0.7.0 This release

2 release files

0.6.2

2 release files

0.6.1

2 release files

0.6.0

2 release files

0.5.0

2 release files

0.4.0

2 release files

0.3.4

2 release files

0.3.3

2 release files

0.3.2

2 release files

0.3.1

2 release files

0.3.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page