Skip to main content

pyrigor

PyPI version Downloads CI Publish Python 3.11-3.14 Ruff pre-commit Type hints: Pyright Type hints: mypy Type hints: ty Pylint pydocstyle Complexity: xenon Code complexity: radon Cognitive complexity: complexipy pytest: 100% coverage License: MIT actionlint Security: bandit Dead code: vulture codespell Checked with pyrigor

Catches the class of bug type checkers structurally cannot: a NamedTuple/keyword-only-argument/return-value-usage rule set for Python, inspired by safety-critical coding guidelines from other languages.

  • Enforced rules catching real, silent bugs mypy strict mode passes clean
  • Validated against real, public codebases: CPython's stdlib, Home Assistant, mypy, requests, hypothesis, abseil-py
  • Checks an 18,187-file real-world codebase in under a minute
  • Drop-in pre-commit integration, or run standalone

Table of Contents

The problem, in one example

The Mars Climate Orbiter was lost because two teams silently disagreed about units. The code for that class of bug would still get past mypy today.

Thrust = NewType("Thrust", float)
FuelMass = NewType("FuelMass", float)


def compute_burn_time(*, thrust: Thrust, fuel_mass: FuelMass) -> float: ...


# Both floats. Nothing about a bare float stops this from running,
# type-checking cleanly, and silently swapping the two values.
compute_burn_time(thrust=fuel_mass, fuel_mass=thrust)

This is pyrigor's PYR201 rule, NewType for same-typed values at risk of being swapped. It is documented today, not yet enforced. What pyrigor already catches, right now:

$ pyrigor launch_sequence.py
launch_sequence.py:12:1: PYR402 Function 'compute_burn_time' has
positional parameters; all parameters should be keyword-only
(keyword-only-arguments)

Usage

pip install pyrigor
pyrigor path/to/file.py [path/to/another.py ...]

Every rule marked enforced in guidelines/RULES.md runs automatically. A violation exits non-zero and prints path:line:col: PYRxxx message (symbolic-name).

Run pyrigor --version to check the installed version. Use --select=CODE,CODE to restrict checking to specific rules, for example pyrigor --select=PYR401,keyword-only-arguments path/. Use --ignore=CODE,CODE to exclude specific rules instead, running every other one. Both may be combined — --ignore removes codes from --select's set (or from every rule, if --select is omitted). The codes may be given as the full code, the bare number, or the symbolic name, the same as suppression comments. An unrecognized code exits immediately with an error naming it, as does a --select/--ignore combination that leaves no rules to check. Use --exclude PATH to omit a file or directory and everything below it. Repeat the option to exclude multiple paths. This exclusion is applied by pyrigor itself, independently of any pre-commit file filter.

For the machine-readable editor or tooling integration, use --output-format=json. It emits one JSON document containing diagnostics, read/parse errors, and suppression counts. The default human-readable format is unchanged. See guidelines/JSON_DIAGNOSTICS.md for the contract and schema.

To suppress a specific violation, add a same-line comment with a reason:

def f(weight, bias):  # pyrigor PYR402 # matches a fixed external API
    ...

Codes may be given as the full code (PYR402), the bare number (402), or the rule's symbolic name (keyword-only-arguments). Multiple codes: # pyrigor 402,403 # reason. A suppression comment without a reason is ignored, and a warning is printed. Suppressed violations are counted per rule in the summary (PYR402: 1 suppressed), not silently discarded.

When stacking with another tool's own suppression comment on the same line (# nosec, # complexipy: ignore, ...), put pyrigor's own comment last — # nosec # pyrigor PYR402 # reason. Pyrigor's own comment must come after any other tool's comment, since its reason captures to the end of the line.

A suppression comment may also go on the line directly above the violation, or anywhere within a multi-line statement's own span — useful when a long, descriptive name plus the mandatory reason would not fit on the violating line itself:

# pyrigor PYR402 # long test names plus a mandatory reason need more room
def apply_correction_for_the_pytest_fixture_injection_case(weight, bias): ...

The same-line still works exactly as before — these are additional locations, not a replacement. This flexibility is a deliberate design advantage over tools like ruff or bandit, which require the suppression comment to sit on the exact physical line of the violation, making it easy to place incorrectly on wrapped statements. Pyrigor's suppression works anywhere within the violation's span, so placement matters less.

Adding pyrigor to your own project

Add pyrigor to your own .pre-commit-config.yaml as a pinned, remote hook, the same way you would add ruff or black:

- repo: https://github.com/jarl-hoyem/pyrigor
  rev: v0.11.0
  hooks:
    - id: pyrigor
      args: [ --exclude, generated ]

Pin rev: to a real, released tag, not main. Check the release page for the latest version.

Show it in your own README:

[![Checked with pyrigor](https://img.shields.io/badge/checked%20with-pyrigor-blue)](https://github.com/jarl-hoyem/pyrigor)

What this is

Python's failure modes are often silent: implicit type coercion, positional-argument swaps between same-typed parameters, mutable default arguments, float equality checks, and tuple-unpacking that "type-checks" while being semantically wrong are all real, tool-catchable classes of bugs that slip past mypy, pylint, and ruff's default rule sets.

pyrigor is a set of guidelines, with real, working tooling enforcing them today, growing as more rules are built out.

Status

Early stage.

See guidelines/RULES.md for the full, generated list of every rule and whether it is enforced yet.

  • Guideline documentation
  • Standalone AST-based checkers (pre-commit local hooks)
  • Editor integration (deferred until real demand exists, see #152)

Guidelines

See guidelines/ for the full list. Each guideline has a rule ID, rationale, example, and — once implemented — a link to its enforcing check.

guidelines/RULES.md has a generated table of every rule and whether it is enforced yet — generated from the real guideline docs and CHECKERS, never hand-maintained, so it cannot drift the way this table once did.

Philosophy

Prefer explicit over implicit. Make illegal states unrepresentable. Do not rely on convention or code review where a tool can enforce correctness instead.

The tool pyrigor is prescriptive by design: each guideline does not just flag a risky pattern, it commits to one specific, verified fix. This is a deliberate choice, not an oversight — a codebase where every developer independently improvises their own fix for the same problem is exactly the inconsistency pyrigor exists to close.

Contributing

Participation is governed by the Code of Conduct.

  1. Every change starts with an issue. Check open issues labeled ready for a well-scoped starting point, or open a new one.
  2. Adding a new rule? Follow guidelines/ADDING_A_RULE.md step by step.
  3. Run pre-commit run --all-files before pushing.
  4. Open a Pull Request.

See CONTRIBUTING.md for full setup and workflow details.

Feedback

Evaluating pyrigor for your own project? Open an issue and tell me about your use case — I use real adoption signals to drive priorities.

Acknowledgements

The tool pyrigor's own rules draw directly on real, external sources, not invented in isolation: Steve McConnell's Code Complete, the OSSF Secure Coding Guide for Python, and Google's Python Style Guide. Built on the shoulders of the real, open source tooling, it runs alongside every day: ruff, pylint, mypy, pyright, and pytest, among others credited throughout this project's own guideline docs.

Contact

Created and maintained by jarl-hoyem. For questions or ideas, open an issue.

License

MIT

Metadata

Release files for pyrigor 0.12.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for pyrigor 0.12.0
File Size Uploaded
pyrigor-0.12.0.tar.gz 39.3 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for pyrigor 0.12.0
File Interpreter ABI Platform
pyrigor-0.12.0-py3-none-any.whl Python 3 none any Details

Total release size: 72.4 kB

Release files / pyrigor-0.12.0.tar.gz

Download URL pyrigor-0.12.0.tar.gz
Size 39.3 kB
Tags Source
SHA-256 checksum
How to use checksums
1c26f46dc3bb19fc80d472a8ad154ebd526407ac544dc91ca9468b014693cadb
BLAKE2b-256 checksum
How to use checksums
ffadd877daef5de3a09ead2f41849b7d5777d4636eb03ba63303b231a7f69261
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Aug 28, 2026.

Transparency log

Release files / pyrigor-0.12.0-py3-none-any.whl

Download URL pyrigor-0.12.0-py3-none-any.whl
Size 33.2 kB
Tags Python 3
SHA-256 checksum
How to use checksums
c6f08911b90b92785948f2ea847b9411d575396f090726880fc2c93ac6d18104
BLAKE2b-256 checksum
How to use checksums
1c829964defeef447a87276a969413776fd6022e7f71cec7b68ec483d40d3402
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Aug 28, 2026.

Transparency log

Release history Release notifications | RSS feed

0.13.1

2 release files

This release

0.12.0 This release

2 release files

0.11.0

2 release files

0.10.0

2 release files

0.9.0

2 release files

0.8.0

2 release files

0.7.4

2 release files

0.7.3

2 release files

0.7.2

2 release files

0.7.1

2 release files

0.7.0

2 release files

0.6.0

2 release files

0.5.0

2 release files

0.4.0

2 release files

0.3.0

2 release files

0.2.3

2 release files

0.2.2

2 release files

0.2.1

2 release files

0.2.0

2 release files

0.1.1

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page