Skip to main content

windbag

PyPI CI License: MIT

A pre-commit linter that catches comments narrating a change — a ticket number, what the code used to do, hedging about whether it works — instead of documenting the constraint that makes the current code correct. Checks Python, JavaScript/TypeScript, Terraform/HCL, Rust, Go, Java, and SQL (including dbt and SQLMesh templates), plus the markup formats that carry comments: YAML, HTML, and Markdown.

What it detects

Rule Severity Flags
TICKET_ID error A ticket ID in a comment (SCA-533). Exempts TODO(SCA-600)-style tracked tasks and security-advisory IDs (CVE-, GHSA-, ...).
HISTORY_NARRATION error "was missing", "used to be", "no longer", "silently swallows", and similar.
HEDGE_LANGUAGE error "should work", "hopefully", "not sure why", "i believe", and similar.
CROSS_FILE_REF warn A pointer to another file/line (handler.py:147). Documentation URLs are exempt.
VERBOSE_COMMENT warn A comment that's long relative to what it documents. Markup files are exempt.
OBVIOUS_COMMENT warn A comment that just restates the line below it (// increment the counter above counter += 1).

error rules fail the check; warn rules are reported but don't block.

Markup files

YAML comments (#) come from the YAML grammar, so a # inside a quoted scalar stays data rather than becoming a comment. HTML and Markdown are checked through <!-- ... -->; in Markdown, anything inside a fenced code block is sample markup, not a comment, and is skipped.

The content rules — TICKET_ID, HISTORY_NARRATION, HEDGE_LANGUAGE, CROSS_FILE_REF — carry the weight here. VERBOSE_COMMENT does not apply: a few lines of explanation above a one-line config key is the idiomatic shape in a config file, not a comment outgrowing its code.

SQL files

.sql files are read as Jinja-templated SQL, which is what dbt and SQLMesh models are. --, /* */, and Jinja {# ... #} comments are all checked. A marker inside a 'string', a "quoted identifier", a $$ ... $$ body, or a {{ ... }} / {% ... %} tag is data the template emits, not a comment. The scanner is dialect-agnostic, so Snowflake, Postgres, BigQuery, and the rest all work; MySQL-style # line comments are the one form it does not read.

A comment is measured against the statement below it: the non-blank lines that follow, through the first one ending in ;.

Install

From PyPI — prebuilt wheels for macOS, Linux, and Windows, no Rust toolchain required:

pip install windbag
# or
uv tool install windbag

Run it without installing anything:

uvx windbag check --all

Building from source instead needs a Rust toolchain. If you don't have one:

curl --proto '=https' --tlsv1.2 -sSf https://sh.rustup.rs | sh
. "$HOME/.cargo/env"    # and add this line to ~/.zshrc

Then, from a checkout:

cargo install --path .

That puts windbag in ~/.cargo/bin, which must be on your PATH. This repo builds as a Python wheel via maturin's bindings = "bin" mode, which just wraps the compiled binary — there's no Python code here, and import windbag doesn't work:

uvx maturin build --release
uvx --from target/wheels/windbag-*.whl windbag check --all

Use

windbag init                  # write windbag.toml with generic defaults
windbag check --staged        # check what's about to be committed
windbag check --all           # check every git-tracked file in the repo
windbag check --json --staged # machine-readable output
windbag check --new-only f.py # only comments on lines the working tree adds over HEAD

When run interactively, bulk --all and --staged checks show progress on stderr. Progress is suppressed for --json, CI, hooks, and other non-terminal callers so their output remains machine-readable.

Pre-commit:

- repo: local
  hooks:
    - id: windbag
      name: windbag
      entry: windbag check --staged
      language: system
      pass_filenames: false
      types_or: [python, javascript, jsx, ts, tsx, terraform, rust, yaml, markdown, html, sql, go, java]

(windbag needs to already be on PATH — language: system doesn't install it for you.)

Claude Code plugin

Pre-commit catches slop after it's written. The plugin catches it as it's written: a PostToolUse hook runs windbag on every file Claude edits and exits non-zero on a violation, so the findings go straight back to Claude as a blocking error and it rewrites the comment before moving on. A SessionStart hook states the rules up front so most edits never trip the linter at all.

/plugin marketplace add scale-venture-partners/windbag
/plugin install windbag@windbag

The plugin ships the hooks, not the linter, so the binary also has to be on PATH. The SessionStart hook installs it automatically on first use, via whichever of uv tool install windbag, pipx install windbag, or pip install --user windbag it finds first; if none of those are on PATH either, it exits quietly and the PostToolUse hook stays a no-op until windbag shows up some other way. To install it yourself instead — a locked-down machine with no package-manager network access, say — see Install.

To turn it on for everyone working in a given repo, commit this to that repo's .claude/settings.json. Anyone who opens the repo is prompted to trust the marketplace, and the hooks apply from their next session:

{
  "extraKnownMarketplaces": {
    "windbag": {
      "source": { "source": "github", "repo": "scale-venture-partners/windbag" }
    }
  },
  "enabledPlugins": { "windbag@windbag": true }
}

Working on the plugin itself? /plugin marketplace add /path/to/windbag points at a local checkout instead. Either way the install copies plugin/ into ~/.claude/plugins/cache/ — keeping it out of the repo root is what keeps target/ out of the copy. That copy is a snapshot: after editing a hook, reinstall to pick up the change.

The hook needs windbag on PATH (or WINDBAG_BIN set) and jq installed; without either it exits quietly rather than breaking the session.

Env var Effect
WINDBAG_HOOK=off Disable both hooks without uninstalling.
WINDBAG_HOOK_LEVEL=error Block only on error rules; ignore warnings.
WINDBAG_BIN Explicit path to the binary.

Only comments on lines the working tree adds over HEAD are reported, so editing a file doesn't re-litigate comments that were already there. Claude is told not to silence a rule with windbag: ignore on its own — a false positive should surface to you, not get suppressed.

/windbag sweeps the whole repo and fixes what it finds.

Suppress a false positive inline:

# Was missing until v2 (LEGACY-1) — kept for the changelog.  windbag: ignore[TICKET_ID]

Config lives in windbag.toml; see examples/scalevp.toml for narrowing TICKET_ID to a real tracker prefix instead of the generic default.

Examples

main.tf:218  error TICKET_ID          comment references a ticket ID (SCA-533) — that
                                       context belongs in the commit message or PR
                                       description, not the code
main.tf:218  error HISTORY_NARRATION  comment narrates the change ("was missing")
                                       instead of the current state — describe the
                                       constraint, not the history
main.tf:218  warn  VERBOSE_COMMENT    comment block is long relative to what it
                                       documents (7 comment lines, 7.0x the 1 attached
                                       code line(s))
# Was missing entirely (SCA-533): this used to silently no-op.  <- TICKET_ID, HISTORY_NARRATION
value = fetch_value()

# This should work but I'm not sure why it fails sometimes.       <- HEDGE_LANGUAGE
retry(fetch_value)

# increment the counter                                           <- OBVIOUS_COMMENT
counter += 1

# TODO(SCA-600): revisit after Q3 pricing model ships              <- clean, exempt
schedule_followup()

# Sorted DESC because the caller assumes the first row is newest.  <- clean, real WHY
return sorted(items, reverse=True)
# Was missing (SCA-533): the deploy no longer fails.  <- TICKET_ID, HISTORY_NARRATION
steps:
  - checkout

# Pinned because the orb syntax below requires 2.1.   <- clean, real WHY
version: 2.1

In Markdown, a comment shown as sample markup inside a fence is content:

<!-- Was missing (SCA-533): renders wrong without it. -->   <- TICKET_ID, HISTORY_NARRATION

```html
<!-- Was missing (SCA-901): this one is an example. -->     <- clean, inside a fence
```

License

MIT © Scale Venture Partners.

About Scale Venture Partners

Scale Venture Partners

We back the few who can go the distance. Scale Venture Partners partners with early-stage AI companies on the journey from founder-led growth to a go-to-market machine. scalevp.com

Metadata

Release files for windbag 0.2.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for windbag 0.2.0
File Size Uploaded
windbag-0.2.0.tar.gz 91.9 kB Details

Built distributions (wheels)

Table of built distributions (wheels) for windbag 0.2.0
File
windbag-0.2.0-py3-none-win_amd64.whl Python 3 none Windows x86-64 Details
windbag-0.2.0-py3-none-manylinux_2_17_x86_64.manylinux2014_x86_64.whl Python 3 none Linux glibc 2.17+ x86-64 Details
windbag-0.2.0-py3-none-manylinux_2_17_aarch64.manylinux2014_aarch64.whl Python 3 none Linux glibc 2.17+ ARM64 Details
windbag-0.2.0-py3-none-macosx_11_0_arm64.whl Python 3 none macOS 11.0+ ARM64 Details
windbag-0.2.0-py3-none-macosx_10_12_x86_64.whl Python 3 none macOS 10.12+ x86-64 Details

Total release size: 9.4 MB

Release files / windbag-0.2.0.tar.gz

Download URL windbag-0.2.0.tar.gz
Size 91.9 kB
Tags Source
SHA-256 checksum
How to use checksums
548a634fbc32ddd9d296ae0af1b716979d59024a9991ca896fa57b55c920effe
BLAKE2b-256 checksum
How to use checksums
5c36fbedc91c22c9fb602fe2794ba654eb565ed6aa4691c62c6572ccfe119662
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 18, 2026.

Transparency log

Release files / windbag-0.2.0-py3-none-win_amd64.whl

Download URL windbag-0.2.0-py3-none-win_amd64.whl
Size 1.8 MB
Tags Python 3 Windows x86-64
SHA-256 checksum
How to use checksums
229698d6763e00dfb1557718f3a6214c275238d4252e9c2590c20a369bc01533
BLAKE2b-256 checksum
How to use checksums
8d015e9481669145ce81864847577b3e4f823d84406f11c415f75c400d962ef4
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 18, 2026.

Transparency log

Release files / windbag-0.2.0-py3-none-manylinux_2_17_x86_64.manylinux2014_x86_64.whl

Download URL windbag-0.2.0-py3-none-manylinux_2_17_x86_64.manylinux2014_x86_64.whl
Size 2.0 MB
Tags Linux glibc 2.17+ x86-64 Python 3
SHA-256 checksum
How to use checksums
c306b581f8edfe68366cc303437fc37d0f1dfdbf58dd46d5df17462479bbd559
BLAKE2b-256 checksum
How to use checksums
a414ec9a44179022f61b9eabe482fc065f07452b39aa779063ebe67692a5667b
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 18, 2026.

Transparency log

Release files / windbag-0.2.0-py3-none-manylinux_2_17_aarch64.manylinux2014_aarch64.whl

Download URL windbag-0.2.0-py3-none-manylinux_2_17_aarch64.manylinux2014_aarch64.whl
Size 1.9 MB
Tags Linux glibc 2.17+ ARM64 Python 3
SHA-256 checksum
How to use checksums
8661118e6003643ecbedb7ad15d907bee1158341e82e6a5d5695ba718c78bdc1
BLAKE2b-256 checksum
How to use checksums
0219a91b6a7bbb2357ce1ce212bf62eedc1cd21caf3b2a8caa01485936bb7f35
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 18, 2026.

Transparency log

Release files / windbag-0.2.0-py3-none-macosx_11_0_arm64.whl

Download URL windbag-0.2.0-py3-none-macosx_11_0_arm64.whl
Size 1.8 MB
Tags Python 3 macOS 11.0+ ARM64
SHA-256 checksum
How to use checksums
14ae048a3bfdd1155b3c42fa582d708dcab5ae1d8b380564fd3d57f185c51347
BLAKE2b-256 checksum
How to use checksums
6f5ca3fe6671f9b32d96f63f1dcf1bfcd5c59c9bc1aeaec7bbf4f0f44e5f37a7
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 18, 2026.

Transparency log

Release files / windbag-0.2.0-py3-none-macosx_10_12_x86_64.whl

Download URL windbag-0.2.0-py3-none-macosx_10_12_x86_64.whl
Size 1.9 MB
Tags Python 3 macOS 10.12+ x86-64
SHA-256 checksum
How to use checksums
40c0ecad1f73dac94d1d659963251d44c12790899d4c849018be7c82579c3442
BLAKE2b-256 checksum
How to use checksums
106008ca2d6450bda8e5544e4ba868ea10b9ae0fbb05fb3f458944a1defcf5fa
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 18, 2026.

Transparency log

Release history Release notifications | RSS feed

This release

0.2.0 This release

6 release files

0.1.1

6 release files

0.1.0

6 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page