Skip to main content

refactron (Python wrapper)

The verification layer for AI code change. Refactron proves that a change, your AI agent's, a codemod's, or your own, preserved behavior. It applies the diff in an isolated shadow tree, runs your real test suite, and returns a three-way verdict: SAFE, UNSAFE, or UNPROVEN. Your working tree is never touched.

This package is a thin Python shim around the npm refactron package. It exists so a Python-first toolchain can put the refactron command on your PATH without adding Node to your project manifest. All the real work happens in the Node CLI.

Requirements

  • Node.js 18+ on your PATH. This wrapper does not remove the Node dependency; it only saves you from wiring the CLI in by hand.
  • Python 3.8+, plus coverage.py in the environment your tests run in if you want coverage-backed verdicts.

Install

pip install refactron==0.3.0
npm install -g refactron

Both lines matter. The pip package gives you the refactron entry point; the npm package is what it runs. Keep the two versions equal: the wrapper prints a warning to stderr when they disagree.

The wrapper does not install the npm package for you. A pip install that silently ran npm install -g would write outside your Python environment and would pull whatever version is latest, which is not necessarily the version you pinned. If the Node CLI is missing, the wrapper tells you the exact command to run and exits non-zero.

Prefer not to install globally? Skip the pip package and use npx refactron <command> directly.

Usage

Identical to the npm package. Every argument is passed straight through.

refactron login                                  # or set REFACTRON_TOKEN in CI
refactron verify-diff . --diff change.diff --test-cmd "python3 -m pytest -q"
refactron preflight ./my-sqlalchemy-app
refactron analyze .
refactron run --apply

verify-diff exits 1 on UNSAFE, 2 on bad input, 7 when unauthenticated, and 0 on both SAFE and UNPROVEN. UNPROVEN is a warning, not a rejection: read the verdict field from --json if you want CI to fail on it.

Coverage attestation is Python-only, via coverage.py. A TypeScript, mixed, or otherwise non-Python diff caps at UNPROVEN; it never returns a false SAFE.

MCP server

The npm package also ships a refactron-mcp binary, a stdio MCP server exposing a verify_change tool your agent calls before it lands a change. It is not routed through this wrapper: point your MCP client at refactron-mcp directly. See the MCP docs.

Environment variables

Variable Effect
REFACTRON_TOKEN Authenticates non-interactive runs (CI).
REFACTRON_SKIP_VERSION_CHECK Set to 1 to silence the wrapper's version-skew warning.

License

Apache-2.0. See LICENSE and NOTICE.

Full docs: https://docs.refactron.dev

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

refactron-0.4.2.tar.gz (10.0 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

refactron-0.4.2-py3-none-any.whl (11.2 kB view details)

Uploaded Python 3

File details

Details for the file refactron-0.4.2.tar.gz.

File metadata

  • Download URL: refactron-0.4.2.tar.gz
  • Upload date:
  • Size: 10.0 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/7.0.0 CPython/3.13.14

File hashes

Hashes for refactron-0.4.2.tar.gz
Algorithm Hash digest
SHA256 0a4da63b58455ca8c258452a0bfb6200e2ed71096a1fefd458f4048225f0a687
MD5 e505254264961af2fc84c92dc71bf71d
BLAKE2b-256 b9528b498e87c43b2eb61974e8495b85a580dcdf6764af059bc4969359b40ee1

See more details on using hashes here.

Provenance

The following attestation bundles were made for refactron-0.4.2.tar.gz:

Publisher: release.yml on Refactron-ai/refactron

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file refactron-0.4.2-py3-none-any.whl.

File metadata

  • Download URL: refactron-0.4.2-py3-none-any.whl
  • Upload date:
  • Size: 11.2 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/7.0.0 CPython/3.13.14

File hashes

Hashes for refactron-0.4.2-py3-none-any.whl
Algorithm Hash digest
SHA256 97bf6e064aa44503aee0d29216a13c7df7487f2f10d01744cadb0baa3c1a6b9b
MD5 434e64a65ab81b0e67ab4040d62ffaa1
BLAKE2b-256 a5c76313c2220d99e9b1b3516ace2498d7d59acfe15542672a10fb305a36e319

See more details on using hashes here.

Provenance

The following attestation bundles were made for refactron-0.4.2-py3-none-any.whl:

Publisher: release.yml on Refactron-ai/refactron

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page