Skip to content

About

GitHub Action - Depwire dependency analysis on every PR. Shows impact, health score delta, and arc diagram

Resources

Stars

0 stars

Watchers

0 watching

Forks

Use this GitHub action with your project
Add this Action to an existing workflow or create a new one
View on Marketplace

Repository files navigation

Depwire PR Impact Analysis

GitHub Marketplace GitHub release License: BSL 1.1

Automatically analyze dependency changes, health score delta, and architecture impact on every pull request.

When a developer opens or updates a PR, this action compares the base branch to the PR branch, analyzes the dependency graph, calculates health score changes, and posts a detailed markdown comment with impact analysis — helping teams catch architectural issues before merge.

Depwire PR Comment Example


Quick Start

Create .github/workflows/depwire.yml in your repository:

name: Depwire PR Impact
on:
  pull_request:
    branches: [main]

permissions:
  contents: read
  pull-requests: write

jobs:
  depwire:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v4
        with:
          fetch-depth: 0   # Required for base branch comparison
      
      - uses: actions/setup-node@v4
        with:
          node-version: '20'
      
      - uses: depwire/depwire-action@v1
        with:
          github-token: ${{ secrets.GITHUB_TOKEN }}

That's it! Every PR will now get an automated comment showing:

  • Summary Table — Files, symbols, edges, and health score before/after with deltas
  • Health Score Breakdown — 6 dimensions (Coupling, Cohesion, Circular Deps, God Files, Orphan Files, Depth)
  • Files Changed — Added, removed, modified files with symbol counts
  • Impact Analysis — Risk assessment for each changed file (high/medium/low risk based on connections)
  • New Dependencies — Edges added by the PR

What It Reports

Summary Table

Metric Base PR Delta
Files 45 48 ↑ +3
Symbols 523 589 ↑ +66
Edges 159 178 ↑ +19
Health Score 78/100 (C) 81/100 (B) ↑ +3

Illustrative figures, not from a specific repository.

Health Score Breakdown

6 dimensions with before/after scores and deltas:

  • Coupling — Module interconnection density
  • Cohesion — File focus and responsibility clarity
  • Circular Dependencies — Import cycle detection
  • God Files — Large file detection (high symbol count)
  • Orphan Files — Disconnected code identification
  • Depth — Dependency tree depth analysis

Files Changed

Lists added, removed, and modified files with symbol and edge counts.

Impact Analysis

Risk assessment table showing:

File Risk Connections Reason
src/index.ts ⚠️ High 28 Hub file modified — changes affect 28 connected files
src/auth/oauth.ts ✅ Low 0 New file, no existing dependents

Powered by Depwire

Every comment includes a footer link to Depwire for local CLI usage.


Inputs

Input Description Required Default
github-token GitHub token for posting PR comments Yes ${{ github.token }}
path Path to the project to analyze (relative to repo root) No .
depwire-version Version of depwire-cli to use. Hard-pinned per Action release for reproducibility (see Version pinning policy) No 1.21.2
fail-on-score-drop Fail the action if health score drops by more than this amount No 0
show-diagram Include arc diagram in PR comment (future feature) No true
comment-header Custom header for the PR comment No ## 🔍 Depwire PR Impact Analysis

Outputs

Output Description
health-score Current health score (0-100)
health-grade Current health grade (A-F)
health-delta Change in health score from base branch
files-changed Total number of files added, removed, or modified

Advanced Usage

Fail PR if Health Score Drops

Enforce a minimum health score threshold to block PRs that degrade code quality:

- uses: depwire/depwire-action@v1
  with:
    github-token: ${{ secrets.GITHUB_TOKEN }}
    fail-on-score-drop: 5

If the health score drops by more than 5 points, the action will fail and block the PR merge.

Monorepo: Analyze Specific Package

For monorepos, analyze a specific subdirectory:

- uses: depwire/depwire-action@v1
  with:
    github-token: ${{ secrets.GITHUB_TOKEN }}
    path: packages/backend

Version pinning policy

The depwire-version default is hard-pinned per Action release so that a CLI release can never change your PR checks without a version bump on your side — the same PR always produces the same analysis, and upgrades only happen when you update the Action.

To track the newest release instead, opt in explicitly:

- uses: depwire/depwire-action@v1
  with:
    github-token: ${{ secrets.GITHUB_TOKEN }}
    depwire-version: 'latest'

Or pin to a different specific version:

- uses: depwire/depwire-action@v1
  with:
    github-token: ${{ secrets.GITHUB_TOKEN }}
    depwire-version: '1.21.2'

CLI 1.21.2 includes the 1.21.1 fix for command injection through git branch names, file names, and revision arguments. Upgrade to Action v1.0.7 when released (or its release commit), and bump any explicit depwire-version pin to 1.21.2, especially for workflows analyzing PRs from forks. Older pins remain unchanged.

Pin drift is surfaced automatically: a weekly scheduled workflow in this repository (cli-staleness-alert) compares the pinned default against the npm latest dist-tag and opens or updates a single tracking issue when they differ by a minor or more. The alert never bumps the pin or publishes anything — upgrades are always a deliberate, reviewed Action release.

When There's Nothing to Analyze

If Depwire finds no supported source files at the configured path — an unsupported language, a docs-only directory, or a monorepo subpath with no code — the action posts a short neutral comment and passes:

Depwire found no supported files at docs/ — nothing to analyze.

No score, grade, or risk badge is reported, and fail-on-score-drop does not trigger, because there is no score to compare. Genuine failures — a broken install, an unreadable repository — still fail the check loudly.

Use Outputs in Subsequent Steps

Access the health score and other metrics in later workflow steps:

- uses: depwire/depwire-action@v1
  id: depwire
  with:
    github-token: ${{ secrets.GITHUB_TOKEN }}

- name: Check health score
  run: |
    echo "Health score: ${{ steps.depwire.outputs.health-score }}"
    echo "Grade: ${{ steps.depwire.outputs.health-grade }}"
    echo "Delta: ${{ steps.depwire.outputs.health-delta }}"
    
    if [ ${{ steps.depwire.outputs.health-delta }} -lt 0 ]; then
      echo "⚠️ Health score decreased!"
    fi

How It Works

  1. Install Depwire CLI — npm install -g depwire-cli
  2. Analyze PR branch — Parse and calculate health score
  3. Checkout base branch — Switch to the target branch (e.g., main)
  4. Analyze base branch — Parse and calculate health score
  5. Compute diff — Compare files, symbols, edges, and health scores
  6. Analyze impact — Flag high-risk changes (files with 20+ connections)
  7. Build markdown comment — Format results as clean tables
  8. Post or update comment — Avoids duplicates by updating existing comments

The action runs depwire parse and depwire health on both branches, computes the delta, and generates a comprehensive report.


What Is Depwire?

Depwire is a dependency intelligence tool for modern codebases.

It parses your code across 16 languages — including TypeScript, JavaScript, Python, Go, Java, Kotlin, Rust, C, C++, C#, PHP, Ruby, Swift and Dart, plus HTML/Angular templates — builds a cross-reference graph, and calculates a health score across 6 dimensions:

  • Coupling — how tightly connected your modules are
  • Cohesion — how focused each file is
  • Circular Dependencies — import cycles that create fragility
  • God Files — oversized files that do too much
  • Orphan Files — disconnected code that may be dead
  • Depth — how many layers deep your dependency tree goes

Depwire is designed for AI coding tools — it gives AI agents the context they need to understand your architecture before making changes.

Local Usage

Install depwire-cli locally to run the same analysis on your machine:

npm install -g depwire-cli

depwire parse .
depwire health .
depwire affected src/auth/index.ts
depwire viz .

See github.com/depwire/depwire for full documentation.


License

This action is licensed under the Business Source License 1.1.

Free for:

  • Personal use
  • Open source projects
  • Companies with <$1M annual revenue

Paid license required for larger commercial use. See depwire.dev/pricing.


Support


Powered by Depwire — install npm install -g depwire-cli for local analysis

About

GitHub Action - Depwire dependency analysis on every PR. Shows impact, health score delta, and arc diagram

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors

Languages