Skip to main content

Pryti Semantic Reviewer

Git tells you what lines changed. Pryti tells you what those changes mean.

Pryti reads a Python web codebase and, for any pull request, commit, or branch, turns a huge diff into a short, ranked list of the things that actually matter: new endpoints, new database writes, new external calls, and data that now leaves the system. It cuts through refactor noise and points you at the exact lines that matter — and it's honest about what it couldn't resolve.

Also: traced PII leaks (the exact field → where it leaves), dependency bumps that gain new powers (network/subprocess/native), PR descriptions that contradict the code, and the rules your codebase follows (discover, confirm, enforce, and blame the commit that broke one). Outputs to the terminal, a web UI, JSON, HTML, SARIF, inline PR comments, a triage label, and a Mermaid diagram. Full walkthrough: The Complete Guide in the repo (blog/pryti-complete-guide.md).

Install

pip install pryti-semantic-reviewer

Zero third-party dependencies. Needs Python 3.8+, plus git and tar on the PATH.

Commands

The repo argument can be a local path or a GitHub URL (URLs are cloned & cached).

pryti review — review a PR, commit, or range

pryti review https://github.com/owner/repo --pr 481      # a GitHub PR by number
pryti review /path/to/repo --commit 9cca6d24             # a single commit (vs its parent)
pryti review /path/to/repo --merge <merge-sha>           # a merge commit
pryti review /path/to/repo --base master --head feature  # any two refs / commits

Output formats and CI gating:

pryti review <repo> --pr 481 \
    --out review.md \                     # Markdown (default; used by CI to post a PR comment)
    --json review.json --html review.html # structured JSON + a self-contained clickable report

pryti review <repo> --pr 481 \
    --invariants pryti-invariants.json \  # enforce your confirmed rules
    --fail-on violation                   # exit non-zero on a new violation (or: crit)

Set GITHUB_TOKEN for private repos / to avoid GitHub API rate limits.

pryti post — put a review on a GitHub PR

pryti post 481 review.md --json review.json --inline --label

Posts a sticky summary comment, inline comments pinned to the exact changed lines, and one pryti:* triage label. Needs GITHUB_TOKEN + the gh CLI (present on GitHub runners).

pryti serve — interactive web UI (with graph view)

cd /path/to/repo && pryti serve      # auto-selects the current git repo, opens a browser

In the UI: paste a GitHub PR link, or type a PR #, commit sha, or base + head, or browse the repo's PRs. Each change gets an interactive flow graph (route → handler → tables / external / jobs) and a list of exact file:line locations.

Preload a review straight from the command line:

pryti serve --pr 481          # open a PR on load
pryti serve --commit <sha>    # open a commit's diff on load
pryti serve --base A --head B # open a range

Options: --repo <path-or-url> · --port 8765 · --invariants <file> · --no-open.

pryti invariants — discover rules from git history

pryti invariants /path/to/repo --snapshots 10

Ranks properties by how long they've held across history, writing invariants_report.md and invariants.discovered.json. Confirm the ones you want and feed them to pryti review --invariants.

Or bootstrap every repo at once: pryti invariants <repo> --bootstrap --baseline org-baseline.json auto-confirms the safe rules and freezes today's state, so it only flags new violations — turning the moat on across many repos with no hand-confirming.

pryti digest — org-wide roll-up for leadership

pryti digest --org my-org --slack "$SLACK_WEBHOOK"

Counts the open PRs across a whole org by the pryti:* triage label Pryti already applied — 🔴 security / 🟠 money / 🟡 new write. No re-analysis, and no GitHub Advanced Security needed. Needs a GITHUB_TOKEN with org read access.

What it detects (without running your code)

  • API routes (new / modified / removed) and their auth level (e.g. AllowAny vs Authenticated)
  • Database reads & writes
  • External API calls (Stripe, Twilio, PayTM, …)
  • Async task dispatches (Celery, threads, signals)
  • PII egress — personal data leaving the system

Each fact is marked ✓ verified / ⚠ potential / ? unknown — it never reports "safe" for something it didn't actually trace.

GitHub Action

# .github/workflows/pryti.yml
name: Pryti
on: { pull_request: {} }
permissions: { contents: read, pull-requests: write }
jobs:
  pryti:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v4
        with: { fetch-depth: 0 }
      - uses: AnkushSinghGandhi/pryti-semantic-reviewer@v1
        with:
          fail_on: violation   # violation | crit | none

Inputs include fail_on, invariants, comment, inline, label, scan_deps, and upload_sarif (set false on private repos without GitHub Advanced Security so the SARIF upload is skipped and the check stays green).

Full documentation, the graph UI, and architecture details: GitHub repository.

License

Elastic License 2.0 — free to use, self-host, and modify; not to resell or offer as a hosted service.

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

pryti_semantic_reviewer-0.4.0.tar.gz (86.2 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

pryti_semantic_reviewer-0.4.0-py3-none-any.whl (72.1 kB view details)

Uploaded Python 3

File details

Details for the file pryti_semantic_reviewer-0.4.0.tar.gz.

File metadata

  • Download URL: pryti_semantic_reviewer-0.4.0.tar.gz
  • Upload date:
  • Size: 86.2 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/7.0.0 CPython/3.10.12

File hashes

Hashes for pryti_semantic_reviewer-0.4.0.tar.gz
Algorithm Hash digest
SHA256 e7a7e80cd5801034f25195ff09ad8e313f8e677317e3c7c70ad8acd1de4a68ec
MD5 7f7d9751f5e700ced75fd4b73184014b
BLAKE2b-256 36ce4f919f7d0b07e4869cf46aefcb94a6b0157943d5b405cb9fac0317e2f95c

See more details on using hashes here.

File details

Details for the file pryti_semantic_reviewer-0.4.0-py3-none-any.whl.

File metadata

File hashes

Hashes for pryti_semantic_reviewer-0.4.0-py3-none-any.whl
Algorithm Hash digest
SHA256 5576ee1b19b0406d34b87d0163d5bee973e7109bd8baab32d2a80950662cbfc6
MD5 3f9425239c41c55d37a4538bace97483
BLAKE2b-256 07b943f27d22ba5789dc7a23a99dda405947aa8f73cc6e9cba12b004e8ff1d79

See more details on using hashes here.

Release history Release notifications | RSS feed

This release

0.4.0 This release

2 files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page