Map the call sites
Codna builds a dependency and blast-radius graph of the repository from its import patterns. No model call, zero tokens.
An upgrade breaks the build in one place and behaviour in three others. Codna maps every call site for zero tokens, fixes with them in view, and re-runs your tests.
The problem
Codna builds a dependency and blast-radius graph of the repository from its import patterns. No model call, zero tokens. The upgraded package is a node in the graph, so every module that imports it is in the blast radius, and the agent fixes with all of them in view.
How Codna fixes it
Codna builds a dependency and blast-radius graph of the repository from its import patterns. No model call, zero tokens.
The agent receives an evidence bundle scoped to the issue: the suspect files, the call paths, the failing test. Codna prints the raw-to-bundle token size on every run. Every fix reports root cause, confidence, blast radius and regression risk, and passes a risk gate before it is applied or a pull request opens.
Run codna fix --tests --apply and Codna runs your tests in a sandbox and re-fixes until they pass, up to the iteration limit you set. Set fix.test_command in codna.yaml, or pass --test-cmd, when your runner is not pytest. With --open-pr, or through the GitHub App, the pull request states the issue, the root cause, the symbols touched and a confidence score, and asks for review before merging. Codna never merges.
codna fix . --issue "build breaks after upgrading requests to 2.32" --tests --apply
What you get
The blast radius of the upgraded package is the list of modules that import it.
codna review checks dependency claims on package.json, pyproject.toml and friends against npm and PyPI before posting.
Run codna fix --tests --apply and Codna runs your tests in a sandbox and re-fixes until they pass, up to the iteration limit you set. Set fix.test_command in codna.yaml, or pass --test-cmd, when your runner is not pytest.
The proof
Run codna fix with the failing build as the issue, or --tests --apply to let Codna discover the failures. Every fix reports root cause, confidence, blast radius and regression risk, and passes a risk gate before it is applied or a pull request opens.
The import graph names every module that imports the upgraded package. Dynamic imports and reflection are a lower bound.
Your tests are the oracle. --tests --apply re-runs them until they pass, up to the iteration limit you set.
Because the build shows one call site. Codna shows all of them and reports the blast radius.
Yes. codna impact lists the tests a diff can affect across the workspace, offline and for zero tokens.
Install the GitHub App. A red check suite on the pull request is triaged and, when it is a code failure, fixed on the branch. The review also grounds dependency findings against the registries.
Related