Skip to content

Raise Codacy grade from B to A #23

Description

@petercorke

pgraph's Codacy grade is B (74), with 75 open issues as of 2026-10-04. The rvc-ecosystem target is A, and the README now shows the grade badge (#22).

Most of the count comes from a few patterns. A handful of the remaining items are real code problems.

Bulk noise (fixing these clears most of the count)

  • 50× pyflakes F405/F403 in tests/test_graph.py: from pgraph import *. Replace it with explicit imports (UGraph, DGraph, UVertex, DVertex, Edge).
  • 11× Bandit B101 (assert) in src/pgraph/PGraph.py. These are assert x is not None lines used to narrow types for mypy, not to validate input. Decide between excluding B101 for src/ in .codacy.yml (with a comment, like bdsim does for tests) and replacing them with explicit checks that raise.

Real code issues in src/pgraph/PGraph.py

  • Duplicate __repr__ (PyLint E0102, line ~823 redefines line ~96). The first definition is dead code; a NOTE comment and # type: ignore[no-redef] acknowledge it. Delete the dead one.
  • Mutable default arguments in plot() (W0102): vopt: dict = {}, eopt: dict = {}, text: dict | bool = {}. Change them to None and create the dict inside the function.
  • subprocess.run("dot -Tpdf", shell=True, ...) (Bandit B602/B607/B404, line ~1353). Pass an argument list with shell=False, resolve dot with shutil.which, and give a clear error if Graphviz isn't installed. This removes the B602/B607 findings properly; B404 (importing subprocess at all) may still need a justified exclusion.

Outside the package

  • posegraph.py in the repo root (3× W0622 redefining len, 1× E1111): it's a stray script. Move it to examples/ and fix it, or delete it.
  • examples/create_json.py: bare except: pass (W0702/B110).
  • GitHub Actions not pinned to a commit SHA (3× Semgrep, ci.yml, dependabot-auto-merge.yml). Pin them to SHAs (dependabot keeps pinned SHAs up to date), or exclude the rule consistently across the ecosystem, whichever the other repos do.

Noticed in passing

  • build/lib/pgraph/ (2 files) is committed to git: stale build output. Remove it and make sure build/ is in .gitignore.
  • scipy is listed in pyproject.toml dependencies but is never imported. It arrived with the setup.py → pyproject.toml migration (977675c) and wasn't in the old setup.py. Remove it from the dependencies, along with the "powered by SciPy" README badge added in docs: restructure README top section to standard ecosystem layout #4.

🤖 Generated with Claude Code

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    tech-debtKnown technical debt / deferred cleanup, not a live bug

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions