Asguardian - Universal Development Tools Suite
Project description
Asguardian
Named after the realm of the Norse gods, Asguardian is a comprehensive suite of development quality assurance tools for Python projects. It covers static analysis, security scanning, API validation, performance metrics, infrastructure generation, and more — all from a single package.
Installation
pip install asguardian
Python 3.11 or higher is required.
Quick Start
Static Analysis and Code Quality
# Analyse a project directory
asgard heimdall analyze ./src
# Get letter ratings (A–E) for Maintainability, Reliability, and Security
asgard heimdall ratings ./src
# Check quality gate (pass/fail against thresholds)
asgard heimdall gate ./src
# Check for security vulnerabilities
asgard heimdall security scan ./src
# View tracked issues with lifecycle states
asgard heimdall issues ./src
Security Scanning
# Detect security hotspots requiring manual review
asgard heimdall security hotspots ./src
# OWASP Top 10 and CWE Top 25 compliance report
asgard heimdall security compliance ./src
# Taint analysis: source-to-sink injection tracking
asgard heimdall security taint ./src
API and Schema Validation
# Validate an OpenAPI specification
asgard forseti validate openapi.yaml
# Check for breaking changes between two specs
asgard forseti breaking-changes old.yaml new.yaml
# Validate a GraphQL schema
asgard forseti validate schema.graphql
Web and UI Testing
# Crawl a site and check for broken links
asgard freya crawl http://localhost:3000
# Run image optimisation scan
asgard freya images http://localhost:3000
Performance Metrics
# Calculate web vitals from a metrics file
asgard verdandi report ./metrics.json
# Check SLO compliance
asgard verdandi slo ./metrics.json
Infrastructure Generation
# Generate Kubernetes manifests
asgard volundr generate kubernetes --name myapp --image myapp:latest
# Generate a Dockerfile
asgard volundr generate dockerfile --lang python
# Generate a GitHub Actions CI/CD pipeline
asgard volundr generate ci github
Web Dashboard
Asguardian includes a standalone web dashboard that displays your project's quality metrics, issues, and history in a browser.
Launch the dashboard
# Start on the default port (8080)
asgard-dashboard --path ./src
# Specify a custom port
asgard-dashboard --path ./src --port 9090
Then open http://localhost:8080 in your browser.
The dashboard provides three pages:
- Overview — quality gate status, A–E ratings (Maintainability, Reliability, Security), and issue summary
- Issues — filterable table of all tracked issues with severity and lifecycle status
- History — trend view of analysis snapshots over time
The heimdall dashboard command is an alias for asgard-dashboard.
MCP Server (AI Agent Integration)
Asguardian includes a JSON-RPC MCP server that exposes analysis results to AI coding assistants such as Claude Code, Cursor, and Windsurf.
Start the MCP server
asgard-mcp --path ./src
Configure Claude Code
Add the following to your .claude/mcp.json (or Claude Code settings):
{
"mcpServers": {
"asguardian": {
"command": "asgard-mcp",
"args": ["--path", "/path/to/your/project"]
}
}
}
Once configured, your AI assistant can query quality ratings, issues, hotspots, and history directly.
Quality Profiles
Asguardian ships with built-in quality profiles that group rules into named sets.
# List available profiles
asgard heimdall profiles list
# Run analysis using a specific profile
asgard heimdall analyze ./src --profile "Asgard Way - Strict"
Built-in profiles:
| Profile | Description |
|---|---|
| Asgard Way - Python | Balanced rule set for Python projects |
| Asgard Way - Strict | Stricter thresholds for production codebases |
Quality Gates
# Evaluate the built-in "Asgard Way" gate
asgard heimdall gate ./src
# Specify a custom gate configuration
asgard heimdall gate ./src --gate my-gate.yaml
A gate returns PASSED or FAILED with a per-condition breakdown. Exit code is 0 for pass and 1 for failure, making it suitable for CI/CD pipelines.
New Code Period
Track metrics specifically for code changed since a baseline commit or date.
# Metrics for code changed since a git tag
asgard heimdall new-code ./src --since v1.0.0
# Metrics for code changed in the last 30 days
asgard heimdall new-code ./src --days 30
SBOM Generation
Generate a Software Bill of Materials in industry-standard formats.
# SPDX 2.3 format
asgard heimdall sbom ./src --format spdx
# CycloneDX 1.4 format
asgard heimdall sbom ./src --format cyclonedx
Auto CodeFix
Get template-based fix suggestions for common rule violations.
asgard heimdall codefix ./src
Language Support
| Language | Rules |
|---|---|
| Python | Complexity, duplication, smells, security, naming (PEP 8), documentation, taint analysis |
| JavaScript | no-eval, no-debugger, no-var, eqeqeq, no-console, complexity (12 rules) |
| TypeScript | All JS rules + no-explicit-any, no-any-cast, no-non-null-assertion, prefer-interface |
| Shell/Bash | eval injection, curl --insecure, hardcoded secrets, missing set -e/u (12 rules) |
Python API
All modules can be used directly in Python code.
from Asgard.Heimdall.Ratings.services.ratings_calculator import RatingsCalculator
from Asgard.Heimdall.QualityGate.services.quality_gate_evaluator import QualityGateEvaluator
from Asgard.Heimdall.Security.services.hotspot_detector import HotspotDetector
from Asgard.Heimdall.Security.services.taint_analyzer import TaintAnalyzer
from Asgard.Heimdall.Issues.services.issue_tracker import IssueTracker
from Asgard.Reporting.services.history_store import HistoryStore
from Asgard.Dashboard.services.data_collector import DataCollector
from Asgard.Forseti.OpenAPI.services import SpecValidatorService
from Asgard.Verdandi.Web.services import VitalsCalculator
from Asgard.Volundr.Kubernetes.services import ManifestGenerator
CLI Reference
Unified CLI (asgard)
asgard heimdall analyze <path>
asgard heimdall ratings <path>
asgard heimdall gate <path>
asgard heimdall profiles list
asgard heimdall history <path>
asgard heimdall new-code <path>
asgard heimdall issues <path>
asgard heimdall sbom <path>
asgard heimdall codefix <path>
asgard heimdall mcp-server
asgard heimdall dashboard
asgard heimdall quality documentation <path>
asgard heimdall quality naming <path>
asgard heimdall quality bugs <path>
asgard heimdall quality javascript <path>
asgard heimdall quality typescript <path>
asgard heimdall quality shell <path>
asgard heimdall security hotspots <path>
asgard heimdall security compliance <path>
asgard heimdall security taint <path>
asgard freya crawl <url>
asgard freya images <url>
asgard forseti validate <spec>
asgard forseti breaking-changes <old> <new>
asgard verdandi report <metrics>
asgard verdandi slo <metrics>
asgard volundr generate kubernetes
asgard volundr generate dockerfile
asgard volundr generate ci
Standalone entry points
heimdall Individual Heimdall CLI
freya Individual Freya CLI
forseti Individual Forseti CLI
verdandi Individual Verdandi CLI
volundr Individual Volundr CLI
asgard-mcp Start the MCP JSON-RPC server
asgard-dashboard Start the web dashboard
Project Structure
Asgard/
├── Asgard/
│ ├── cli.py
│ ├── Heimdall/ # Static analysis, security, quality
│ ├── Freya/ # Visual and UI testing
│ ├── Forseti/ # API and schema validation
│ ├── Verdandi/ # Runtime performance metrics
│ ├── Volundr/ # Infrastructure generation
│ ├── Reporting/ # History store, PR decoration
│ ├── MCP/ # MCP JSON-RPC server
│ └── Dashboard/ # Web dashboard
├── Asgard_Test/ # Test suite (716 tests)
├── pyproject.toml
├── CHANGELOG.md
└── README.md
License
Polyform Noncommercial License 1.0.0 — free for personal and non-commercial use. Commercial use requires a separate license. See LICENSE for details.
Project details
Release history Release notifications | RSS feed
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
Built Distribution
Filter files by name, interpreter, ABI, and platform.
If you're not sure about the file name format, learn more about wheel file names.
Copy a direct link to the current filters
File details
Details for the file asguardian-1.2.1.tar.gz.
File metadata
- Download URL: asguardian-1.2.1.tar.gz
- Upload date:
- Size: 1.0 MB
- Tags: Source
- Uploaded using Trusted Publishing? Yes
- Uploaded via: twine/6.1.0 CPython/3.13.7
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
d45ee50d9b8e119aa1ce6d693865244fe056593c3e5fe0ba49993882f662c8c5
|
|
| MD5 |
4438b75538814dedb52333c9b70e873e
|
|
| BLAKE2b-256 |
fbe614bc0deb23185976e13f9f7831c6343c4bb72a23c9db5ae11e0ef21dcbd6
|
Provenance
The following attestation bundles were made for asguardian-1.2.1.tar.gz:
Publisher:
publish.yml on JakeDruett/asgard
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
asguardian-1.2.1.tar.gz -
Subject digest:
d45ee50d9b8e119aa1ce6d693865244fe056593c3e5fe0ba49993882f662c8c5 - Sigstore transparency entry: 1095447254
- Sigstore integration time:
-
Permalink:
JakeDruett/asgard@3179c2d361dca9145c4cdd5ceaf7fc8600eb13aa -
Branch / Tag:
refs/tags/v1.2.1 - Owner: https://github.com/JakeDruett
-
Access:
public
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
self-hosted -
Publication workflow:
publish.yml@3179c2d361dca9145c4cdd5ceaf7fc8600eb13aa -
Trigger Event:
push
-
Statement type:
File details
Details for the file asguardian-1.2.1-py3-none-any.whl.
File metadata
- Download URL: asguardian-1.2.1-py3-none-any.whl
- Upload date:
- Size: 1.4 MB
- Tags: Python 3
- Uploaded using Trusted Publishing? Yes
- Uploaded via: twine/6.1.0 CPython/3.13.7
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
31442828415a75c7f8e9cdaf9493d0422a127e603b02a638560ec56e9b87fdc8
|
|
| MD5 |
25acc192cf70b63def85f9bf1c752620
|
|
| BLAKE2b-256 |
7ae2bb466df260d83085dda2b60d4f6cad9d140215b907f2c5655dc1b6008282
|
Provenance
The following attestation bundles were made for asguardian-1.2.1-py3-none-any.whl:
Publisher:
publish.yml on JakeDruett/asgard
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
asguardian-1.2.1-py3-none-any.whl -
Subject digest:
31442828415a75c7f8e9cdaf9493d0422a127e603b02a638560ec56e9b87fdc8 - Sigstore transparency entry: 1095447257
- Sigstore integration time:
-
Permalink:
JakeDruett/asgard@3179c2d361dca9145c4cdd5ceaf7fc8600eb13aa -
Branch / Tag:
refs/tags/v1.2.1 - Owner: https://github.com/JakeDruett
-
Access:
public
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
self-hosted -
Publication workflow:
publish.yml@3179c2d361dca9145c4cdd5ceaf7fc8600eb13aa -
Trigger Event:
push
-
Statement type: