pyrigor
Disciplined Python patterns for catching bugs that type checkers and standard linters miss — inspired by safety-critical coding guidelines from other languages, adapted for a language and ecosystem they were not written for.
The problem, in one example
The Mars Climate Orbiter was lost because two teams silently disagreed about units. The code for that class of bug äs still would get pass mypy today.
Thrust = NewType("Thrust", float)
FuelMass = NewType("FuelMass", float)
def compute_burn_time(*, thrust: Thrust, fuel_mass: FuelMass) -> float:
...
# Both floats. Nothing about a bare float stops this from running,
# type-checking cleanly, and silently swapping the two values.
compute_burn_time(thrust=fuel_mass, fuel_mass=thrust)
This is pyrigor’s PYR201 rule, NewType for same-typed values at
risk of being swapped. It is documented today, not yet enforced.
What pyrigor already catches, right now:
$ pyrigor launch_sequence.py
launch_sequence.py:12:1: PYR402 Function 'compute_burn_time' has
positional parameters; all parameters should be keyword-only
(keyword-only-arguments)
Usage
pip install pyrigor
pyrigor path/to/file.py [path/to/another.py ...]
PYR301, PYR401, PYR402, PYR403, PYR405, and PYR406 are enforced today. A violation
exits non-zero and prints path:line:col: PYR40x message (symbolic-name).
Run pyrigor --version to check the installed version.
Use --only=CODE,CODE to restrict checking to specific rules, for
example pyrigor --only=PYR401,keyword-only-arguments path/. The Codes
may be given as the full code, the bare number, or the symbolic
name, the same as suppression comments. An unrecognized code exits
immediately with an error naming it.
To suppress a specific violation, add a same-line comment with a reason:
def f(weight, bias): # pyrigor: PYR402 # matches a fixed external API
...
Codes may be given as the full code (PYR402), the bare number
(402), or the rule’s symbolic name (keyword-only-arguments).
Multiple codes: # pyrigor: 402,403 # reason. A suppression comment
without a reason is ignored, and a warning is printed. Suppressed
violations are counted per rule in the summary (PYR402: 1 suppressed), not silently discarded.
Adding pyrigor to your own project
Add pyrigor to your own .pre-commit-config.yaml as a pinned,
remote hook, the same way you would add ruff or black:
- repo: https://github.com/jarl-hoyem/pyrigor
rev: v0.7.1
hooks:
- id: pyrigor
Pin rev: to a real, released tag, not main. Check the
release page for
the latest version.
What this is
Python’s failure modes are often silent: implicit type coercion, positional-argument swaps between same-typed parameters, mutable default arguments, float equality checks, and tuple-unpacking that "type-checks" while being semantically wrong are all real, tool-catchable classes of bugs that slip past mypy, pylint, and ruff’s default rule sets.
pyrigor collects a set of guidelines — and, over time, tooling to enforce
them — aimed at closing those gaps.
Status
Early stage. As of mid 2026, six rules are implemented and enforced (PYR301, PYR401, PYR402, PYR403, PYR405, PYR406). Eight more are documented but not yet enforced.
- Guideline documentation
- Standalone AST-based checkers (pre-commit local hooks) — PYR301, PYR401, PYR402, PYR403, PYR405, and PYR406 are implemented. PYR201, PYR202, PYR203, PYR204, PYR205, PYR302, PYR404, PYR501, PYR502 are documented but not yet enforced.
- pylint plugin
Guidelines
See guidelines/ for the full list. Each guideline has a
rule ID, rationale, example, and — once implemented — a link to its
enforcing check.
Guidelines documented so far:
| ID | Rule | Enforced by |
|---|---|---|
| PYR201 | Use NewType for same-typed values at risk of being swapped |
Not yet implemented |
| PYR202 | Use Enum instead of magic strings, ints, or bools for closed states |
Not yet implemented |
| PYR203 | Use Final named constants for any number other than 0, 1, or -1 |
Not yet implemented |
| PYR204 | Never compare floats with ==; use tolerance-based comparison |
Not yet implemented |
| PYR205 | Use a Final constant for a numeric literal duplicated in a file |
Not yet implemented |
| PYR301 | Use NamedTuple instead of a bare fixed-length tuple type |
pyrigor CLI (pre-commit hook) |
| PYR302 | Use frozen=True for dataclasses holding structured state |
Not yet implemented |
| PYR401 | Use NamedTuple for any function returning more than one value |
pyrigor CLI (pre-commit hook) |
| PYR402 | Force keyword-only arguments for 2+ function parameters (bare *) |
pyrigor CLI (pre-commit hook) |
| PYR403 | Force keyword-only arguments for single-parameter functions | pyrigor CLI (pre-commit hook) |
| PYR404 | Use immutable default argument values, never mutable ones | Not yet implemented |
| PYR405 | Use NamedTuple for multi-value parameter types, not bare tuple |
pyrigor CLI (pre-commit hook) |
| PYR406 | Use every locally defined function's non-None return value |
pyrigor CLI (pre-commit hook) |
| PYR501 | End a match over a closed set with case _: assert_never(...) |
Not yet implemented |
| PYR502 | State implicit input assumptions as explicit assert preconditions |
Not yet implemented |
Philosophy
Prefer explicit over implicit. Make illegal states unrepresentable. Do not rely on convention or code review where a tool can enforce correctness instead.
The tool pyrigor is prescriptive by design: each guideline does not just flag a risky pattern, it commits to one specific, verified fix. This is a deliberate choice, not an oversight — a codebase where every developer independently improvises their own fix for the same problem is exactly the inconsistency pyrigor exists to close.
Contributing
- Browse or open an issue on GitHub Issues
- Adding a new rule? Follow
guidelines/ADDING_A_RULE.mdstep by step. - Run
pre-commit run --all-filesbefore pushing. - Open a Pull Request.
See CONTRIBUTING.md for full setup and workflow details.
Contact
Maintained by jarl-hoyem. For questions or ideas, open an issue.
License
MIT
Metadata
Release files for pyrigor 0.7.2
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| pyrigor-0.7.2.tar.gz | 22.9 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| pyrigor-0.7.2-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 45.7 kB
Release files / pyrigor-0.7.2.tar.gz
| Download URL | pyrigor-0.7.2.tar.gz |
|---|---|
| Size | 22.9 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
50ef8ad612450b391ab4ca58f484921e20fd8270b18ccfeae62b7876a4fdb63d
|
|
BLAKE2b-256 checksum How to use checksums |
b023739d6152f598b7a9c7ace75030c24cb35a22b4435e410be7bcb09c185de4
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Aug 18, 2026.
Transparency logRelease files / pyrigor-0.7.2-py3-none-any.whl
| Download URL | pyrigor-0.7.2-py3-none-any.whl |
|---|---|
| Size | 22.8 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
e311205d071e4f547d31ff77e689152a4d15056caa2d86ffb605c439c674a95e
|
|
BLAKE2b-256 checksum How to use checksums |
c58f466016f6ef366761cca894196df1ecb2dfe566ebbd299693566f911adb49
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Aug 18, 2026.
Transparency log