Skip to main content

pyrigor

PyPI version Downloads CI Publish Python 3.11-3.14 Ruff pre-commit Type hints: Pyright Type hints: mypy Type hints: ty Pylint pydocstyle Complexity: xenon Code complexity: radon Cognitive complexity: complexipy pytest: 100% coverage License: MIT actionlint Security: bandit Dead code: vulture codespell

Disciplined Python patterns for catching bugs that type checkers and standard linters miss — inspired by safety-critical coding guidelines from other languages, adapted for a language and ecosystem they were not written for.

The problem, in one example

The Mars Climate Orbiter was lost because two teams silently disagreed about units. The code for that class of bug would still get past mypy today.

Thrust = NewType("Thrust", float)
FuelMass = NewType("FuelMass", float)

def compute_burn_time(*, thrust: Thrust, fuel_mass: FuelMass) -> float:
    ...

# Both floats. Nothing about a bare float stops this from running,
# type-checking cleanly, and silently swapping the two values.
compute_burn_time(thrust=fuel_mass, fuel_mass=thrust)

This is pyrigor’s PYR201 rule, NewType for same-typed values at risk of being swapped. It is documented today, not yet enforced. What pyrigor already catches, right now:

$ pyrigor launch_sequence.py
launch_sequence.py:12:1: PYR402 Function 'compute_burn_time' has
positional parameters; all parameters should be keyword-only
(keyword-only-arguments)

Usage

pip install pyrigor
pyrigor path/to/file.py [path/to/another.py ...]

PYR301, PYR401, PYR402, PYR403, PYR405, and PYR406 are enforced today. A violation exits non-zero and prints path:line:col: PYR40x message (symbolic-name).

Run pyrigor --version to check the installed version. Use --only=CODE,CODE to restrict checking to specific rules, for example pyrigor --only=PYR401,keyword-only-arguments path/. The Codes may be given as the full code, the bare number, or the symbolic name, the same as suppression comments. An unrecognized code exits immediately with an error naming it.

To suppress a specific violation, add a same-line comment with a reason:

def f(weight, bias):  # pyrigor PYR402 # matches a fixed external API
    ...

Codes may be given as the full code (PYR402), the bare number (402), or the rule’s symbolic name (keyword-only-arguments). Multiple codes: # pyrigor 402,403 # reason. A suppression comment without a reason is ignored, and a warning is printed. Suppressed violations are counted per rule in the summary (PYR402: 1 suppressed), not silently discarded.

When stacking with another tool’s own suppression comment on the same line (# nosec, # complexipy: ignore, ...), put pyrigor’s own comment last — # nosec # pyrigor PYR402 # reason. Pyrigor’s own comment must come after any other tool’s, since its reason captures to the end of the line.

A suppression comment may also go on the line directly above the violation, or anywhere within a multi-line statement’s own span — useful when a long, descriptive name plus the mandatory reason would not fit on the violating line itself:

# pyrigor PYR402 # long test names plus a mandatory reason need more room
def apply_correction_for_the_pytest_fixture_injection_case(weight, bias):
    ...

The same-line still works exactly as before — these are additional locations, not a replacement.

Adding pyrigor to your own project

Add pyrigor to your own .pre-commit-config.yaml as a pinned, remote hook, the same way you would add ruff or black:

- repo: https://github.com/jarl-hoyem/pyrigor
  rev: v0.7.3
  hooks:
    - id: pyrigor

Pin rev: to a real, released tag, not main. Check the release page for the latest version.

What this is

Python’s failure modes are often silent: implicit type coercion, positional-argument swaps between same-typed parameters, mutable default arguments, float equality checks, and tuple-unpacking that "type-checks" while being semantically wrong are all real, tool-catchable classes of bugs that slip past mypy, pylint, and ruff’s default rule sets.

pyrigor collects a set of guidelines — and, over time, tooling to enforce them — aimed at closing those gaps.

Status

Early stage. As of mid 2026, six rules are implemented and enforced (PYR301, PYR401, PYR402, PYR403, PYR405, PYR406). Eight more are documented but not yet enforced.

  • Guideline documentation
  • Standalone AST-based checkers (pre-commit local hooks) — PYR301, PYR401, PYR402, PYR403, PYR405, and PYR406 are implemented. PYR201, PYR202, PYR203, PYR204, PYR205, PYR302, PYR404, PYR501, PYR502 are documented but not yet enforced.
  • pylint plugin

Guidelines

See guidelines/ for the full list. Each guideline has a rule ID, rationale, example, and — once implemented — a link to its enforcing check.

Guidelines documented so far:

ID Rule Enforced by
PYR201 Use NewType for same-typed values at risk of being swapped Not yet implemented
PYR202 Use Enum instead of magic strings, ints, or bools for closed states Not yet implemented
PYR203 Use Final named constants for any number other than 0, 1, or -1 Not yet implemented
PYR204 Never compare floats with ==; use tolerance-based comparison Not yet implemented
PYR205 Use a Final constant for a numeric literal duplicated in a file Not yet implemented
PYR301 Use NamedTuple instead of a bare fixed-length tuple type pyrigor CLI (pre-commit hook)
PYR302 Use frozen=True for dataclasses holding structured state Not yet implemented
PYR401 Use NamedTuple for any function returning more than one value pyrigor CLI (pre-commit hook)
PYR402 Force keyword-only arguments for 2+ function parameters (bare *) pyrigor CLI (pre-commit hook)
PYR403 Force keyword-only arguments for single-parameter functions pyrigor CLI (pre-commit hook)
PYR404 Use immutable default argument values, never mutable ones Not yet implemented
PYR405 Use NamedTuple for multi-value parameter types, not bare tuple pyrigor CLI (pre-commit hook)
PYR406 Use every locally defined function's non-None return value pyrigor CLI (pre-commit hook)
PYR501 End a match over a closed set with case _: assert_never(...) Not yet implemented
PYR502 State implicit input assumptions as explicit assert preconditions Not yet implemented

Philosophy

Prefer explicit over implicit. Make illegal states unrepresentable. Do not rely on convention or code review where a tool can enforce correctness instead.

The tool pyrigor is prescriptive by design: each guideline does not just flag a risky pattern, it commits to one specific, verified fix. This is a deliberate choice, not an oversight — a codebase where every developer independently improvises their own fix for the same problem is exactly the inconsistency pyrigor exists to close.

Contributing

  1. Browse or open an issue on GitHub Issues
  2. Adding a new rule? Follow guidelines/ADDING_A_RULE.md step by step.
  3. Run pre-commit run --all-files before pushing.
  4. Open a Pull Request.

See CONTRIBUTING.md for full setup and workflow details.

Contact

Maintained by jarl-hoyem. For questions or ideas, open an issue.

License

MIT

Metadata

Release files for pyrigor 0.8.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for pyrigor 0.8.0
File Size Uploaded
pyrigor-0.8.0.tar.gz 28.8 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for pyrigor 0.8.0
File Interpreter ABI Platform
pyrigor-0.8.0-py3-none-any.whl Python 3 none any Details

Total release size: 53.6 kB

Release files / pyrigor-0.8.0.tar.gz

Download URL pyrigor-0.8.0.tar.gz
Size 28.8 kB
Tags Source
SHA-256 checksum
How to use checksums
206e7a60afcfe1097945f1cafb9b1552acc151244d3ba2fcb0690af8a007df7e
BLAKE2b-256 checksum
How to use checksums
c5d2567547762514fd4fd8fee54b763d62b2693838f328b9822cebd74332d250
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Aug 20, 2026.

Transparency log

Release files / pyrigor-0.8.0-py3-none-any.whl

Download URL pyrigor-0.8.0-py3-none-any.whl
Size 24.8 kB
Tags Python 3
SHA-256 checksum
How to use checksums
d84f9810f0751b177a23105526791580c4fd73b853ab47c234491414a5a74468
BLAKE2b-256 checksum
How to use checksums
4abc393a3212904af611b22b618e41ea8c692b740b2af9102f5d578ab5b702a2
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Aug 20, 2026.

Transparency log

Release history Release notifications | RSS feed

0.13.1

2 release files

0.12.0

2 release files

0.11.0

2 release files

0.10.0

2 release files

0.9.0

2 release files

This release

0.8.0 This release

2 release files

0.7.4

2 release files

0.7.3

2 release files

0.7.2

2 release files

0.7.1

2 release files

0.7.0

2 release files

0.6.0

2 release files

0.5.0

2 release files

0.4.0

2 release files

0.3.0

2 release files

0.2.3

2 release files

0.2.2

2 release files

0.2.1

2 release files

0.2.0

2 release files

0.1.1

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page