A linter for architecture, with tiered auto-fixes.
strictcode is a deterministic, non-LLM command-line tool. It scans a codebase with tree-sitter, builds a graph of its modules, callables, and types, and enforces dependency-hygiene, dead-code, import-cycle, and library-boundary rules across Python, Go, and TypeScript/JavaScript. Every finding offers a fix in one of three tiers: guaranteed behavior-preserving (applied automatically and verified by re-extracting the graph), behavior-changing with consent, or suggestion only.
go install github.com/smm-h/strictcode/cmd/strictcode@v0Building needs only Go: the tree-sitter runtime and grammars strictcode parses with are pure Go
(the cgofree translations of the official C sources), so no C compiler is needed and
CGO_ENABLED=0 works. Releases publish no prebuilt binaries.
strictcode analyze . # report findings; exit 1 if any is an error
strictcode analyze . --json # the findings document as JSON
strictcode fix . --preview # list the tier-1 fixes it would apply
strictcode fix . --apply # apply them, verified against the re-extracted graph| Command | Description |
|---|---|
analyze |
Analyze a project or workspace directory and report findings |
fix |
Apply tier-1 (guaranteed behavior-preserving) fixes with post-fix graph re-verification |
| registry | Rule registry artifacts (mint-once IDs and retired-rule records) |
registry rules |
Print every rule strictcode implements, by rule ID, with its strictcode: option (ranking, default, scope, and subject document); with --json the list is the payload |
registry dump |
Write the committed registry dump (rules with their per-language support cells, groups, and retired-rule records) as JSON |
Every rule is an option, strictcode:<rule id>, filed under .strictmetadata/options/: its
default is the rule's severity, and an entry switches it off or to another severity. Declarations
live in strictcode.toml at the analyzed directory: analysis modes, allow lists, suppressions each
with a mandatory reason, the Python tools some rules run, and the strictspec certificate.
The documentation site covers the graph model, every rule, configuration, the support matrix by
language, and the decisions behind the design, including the alternatives that were rejected. Its
source is in .strictmetadata/docs/.
Apache 2.0.