Skip to content

About

Statischer Python-Code-Analyser mit Tkinter-GUI: findet ungenutzte Imports, tote Definitionen und ähnliche Code-Blöcke via AST-Analyse. Kein pip install nötig.

Topics

Resources

Code of conduct

Contributing

Security policy

Stars

1 star

Watchers

0 watching

Forks

Latest commit

 

History

106 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

MethodenAnalyser — Static Python analysis across a spectrum of methods

Version 3.0.2 CI Status Tests 100% Green Verified 2026-10-08 Level 1 SBOM: Plain Text Python 3.10-3.13 Cross-Platform GUI Desktop + CLI + PWA Zero Dependencies 100% Local-First / Zero-Egress Security SLA & Non-Elevation Statutory § 521 BGB Code Style: Ruff License: MIT Ecosystem: dev-bricks Umbrella: open-bricks LLM Ready

MethodenAnalyser

Static Python code analyzer with a local Tkinter GUI: detects unused imports, dead definitions, and similar code blocks using AST analysis.

English | Deutsch


1. Features • 2. Architecture Topology • 3. Personas • 4. Installation • 5. GUI Walkthrough • 6. Headless CLI • 7. Reversible Auto-Fix • 8. Web Companion • 9. Comparison • 10. Dual Mermaid • 11. Governance • 12. Exit Codes • 13. Development & Tests • 14. Level 1 SBOM • 15. Ecosystem • 16. Security & Privacy • 17. Statutory Notice • 18. License

Tip

For LLM agents, automated tools, and context-aware indexing, a canonical RAG index is provided at llms.txt.


Quick Navigation

  1. Value Proposition & Features · 2. Four-View Architectural Topology · 3. Target Personas & Discoverability · 4. Installation & Quickstart · 5. Desktop GUI & Workflow Walkthrough · 6. Headless CLI & Automation · 7. Reversible Auto-Fix & Backup Lifecycle · 8. Local Web Companion & PWA Helper · 9. 10-Dimension Comparative Matrix · 10. Dual Mermaid Diagrams · 11. Governance & 10 Runtime Invariants · 12. Exit Codes & JSON Schema · 13. Testing, Verification & CI Hardening · 14. Level 1 SBOM & Third-Party Licenses · 15. Sibling Ecosystem & Partner Matrix · 16. Security Policy & Zero-Egress · 17. Statutory Notice (§ 521 BGB) · 18. License & Open-Source Umbrella

1. Value Proposition & Features

MethodenAnalyser provides instant, zero-setup static Python code intelligence. Built 100% on Python's Abstract Syntax Tree (ast), it inspects files and multi-package trees for unused imports, unreferenced functions, duplicate blocks, and structural metrics—completely offline and without third-party runtime dependencies.

Feature Description
AST Analysis Precise static code analysis powered purely by Python's Abstract Syntax Tree (ast.parse)
Import Tracking Detects active, unused, duplicate, relative, and scope-bound imports with PEP 695 type alias support
Method Catalog Lists all functions, methods, async routines, and classes in a structured hierarchical layout
Duplicate Detection Finds similar code blocks using Python's difflib.SequenceMatcher with a configurable threshold
Framework Awareness Recognizes implicit registrations in Tkinter, PyQt, requests, asyncio, Flask, and standard event loops
Callback Recognition Accurately identifies callback functions and GUI command bindings as actively used
Multi-File Scan Recursively analyzes entire Python repositories and multi-package trees
Desktop GUI Clean, accessible Tkinter desktop interface with live status bar, accessible tooltips, and WCAG 2.1 AA shortcuts
Reversible Auto-Fix Rechecks current source after confirmation and removes only approved imports that remain unused, with .bak backups; preserves neighboring statements and validates the resulting syntax
Multi-Language UI Native support for 6 languages (de, en, es, zh, ja, ru) in GUI, CLI, and Web helper
Zero Dependencies Built 100% on the Python Standard Library; requires zero external packages at runtime

2. Four-View Architectural Topology & Structural Model

MethodenAnalyser follows a clear, multi-layered architectural topology where every tier projects specific invariants:

+====================================================================================================================+
|                 METHODENANALYSER -- FOUR-VIEW ARCHITECTURAL TOPOLOGY (LOCAL-FIRST & ZERO-EGRESS)                   |
+====================================================================================================================+
| [VIEW 1: USER & INTERFACE ARCHITECTURE -- DESKTOP GUI, CLI & LOCAL PWA COMPANION]                                  |
|  * Interactive Desktop GUI (Tkinter): File & Project AST analysis, live metrics bar, accessible tooltips, keys     |
|  * Headless Automation CLI: Flags --file, --project, --stdin, --json-output, --lang (de, en, es, zh, ja, ru)       |
|  * Local Web Companion (PWA): Zero-CDN vanilla HTML/JS/CSS, offline Service Worker, loopback-only 127.0.0.1:8765    |
|  * Unprivileged User-Mode [INV-SECURITY-02]: Strict RunAsInvoker non-elevation, zero admin/root requirements       |
|  * Loopback Boundary [INV-ISOLATION-05]: Strict loopback binding; LAN test mode (--host 0.0.0.0) requires flag     |
+--------------------------------------------------------------------------------------------------------------------+
                                                          |
                                                          v
+--------------------------------------------------------------------------------------------------------------------+
| [VIEW 2: AST ENGINE, LEXICAL TRAVERSAL & CODE DUPLICATE DETECTOR]                                                  |
|  * Inert Static AST Parsing [INV-AST-03]: Pure ast.parse(); inspected files/modules are NEVER executed or imported|
|  * Lossless Multi-Encoding [INV-ENCODING-04]: UTF-8 primary with Latin-1 fallback; preserves UTF-8 BOM & umlauts   |
|  * Import & Scope Tracker: Scope bindings, relative imports, dunders (__all__), future-imports, PEP 695 type params|
|  * Framework Awareness: Automatically recognizes Tkinter, PyQt, requests, asyncio, Flask & event loop bindings     |
|  * Code Similarity Engine: difflib.SequenceMatcher block tokenization with configurable threshold (SIMILARITY=0.8)  |
|  * Safe ZIP Ingestion [INV-TRAVERSAL-06]: Anti-path-traversal (..), entry count limits & byte bounds on ZIP uploads|
+--------------------------------------------------------------------------------------------------------------------+
                                                          |
                                                          v
+--------------------------------------------------------------------------------------------------------------------+
| [VIEW 3: REVERSIBLE AUTO-FIX ENGINE & ATOMIC EXPORT PIPELINE]                                                      |
|  * Reversible Auto-Fix [INV-AUTOFIX-07]: Re-checks current AST, requires user confirm, generates atomic .bak/.bak.N|
|  * Atomic Flushed Writes: Flushes changes to temporary files before atomic file replacement, preventing corruption |
|  * Export Collision Guard: methodenanalyser-report-v1.json rejects target overwrite of analyzed source files       |
|  * Exclusive Publication: Multi-run project reports preserve previous outputs; hard-link checks for collision guard|
|  * Cross-Platform Parity [INV-PLATFORM-08]: 100% Python Standard Library verified on Windows, Ubuntu, macOS 26     |
+--------------------------------------------------------------------------------------------------------------------+
                                                          |
                                                          v
+--------------------------------------------------------------------------------------------------------------------+
| [VIEW 4: SECURITY, RUNASINVOKER PRIVACY PERIMETER & GOVERNANCE]                                                    |
|  * 100% Local-First & Zero Network Egress [INV-LOCAL-01]: Zero telemetry, zero external network sockets, zero CDNs |
|  * Multi-Host Lock & Sync Defense [INV-SYNC-09]: Rejects LOCK.* files (Fail-Closed); ignores cloud sync conflicts |
|  * Level 1 SBOM Text Companion: Plain-text inventory THIRD_PARTY_LICENSES.txt; 100% zero-copyleft permissive stack |
|  * Statutory Disclaimer (§ 521 BGB): Gratuitous open-source donation liability limited to intent & gross negligence|
|  * Security & Vulnerability SLA [INV-SLA-10]: Committed 48h initial response SLA & 5-day triage (security@...)    |
+====================================================================================================================+

3. Target Personas & Discoverability

Target Personas

  • [PERSONA-01] Python Refactoring Engineers & Code Quality Leads:

    • Context: Developers managing large Python legacy systems or preparing major architectural overhauls.
    • Pain Point: Linters either overwhelm with style warnings or miss unused functions that are referenced only as string names or implicit callbacks.
    • How MethodenAnalyser Solves It: Precision AST analysis separating active definitions from dead code, framework-aware callback tracking, and safe, reversible import removal.
  • [PERSONA-02] Air-Gapped & Security-Sensitive Developers:

    • Context: Engineers working in defense, healthcare, banking, or isolated corporate environments.
    • Pain Point: Cloud-based code analysis tools and heavy npm/pip dependency trees introduce massive supply-chain and data-exfiltration attack vectors.
    • How MethodenAnalyser Solves It: Zero external runtime dependencies (100% standard library), zero outbound network egress (INV-LOCAL-01), and unprivileged execution (RunAsInvoker / INV-SECURITY-02).
  • [PERSONA-03] CI/CD Automation Engineers & Toolchain Authors:

    • Context: DevOps engineers building automated quality gates and pull request verification pipelines.
    • Pain Point: Fragile CLI tools with unpredictable exit codes and unstructured stdout reports break pipeline scripts.
    • How MethodenAnalyser Solves It: Headless CLI with strict, deterministic exit codes (0, 1, 2, 3) and standardized methodenanalyser-report-v1.json reports with atomic publication.
  • [PERSONA-04] Educators, Students & Python Practitioners:

    • Context: Instructors and learners exploring Python syntax, method structures, and code modularity.
    • Pain Point: Complex linters like flake8 or pylint require extensive configuration files (.flake8, pylintrc) just to produce readable summaries.
    • How MethodenAnalyser Solves It: One-click portable GUI with accessible shortcuts, visual method hierarchy views, duplicate block highlight, and 6-language localization.

High-Intent Search Queries

Language High-Intent Search Queries
English (EN) python static code analyzer tkinter gui · unused imports detector python ast · local python code quality checker no dependencies · python dead code finder gui windows · ast-based python code analyzer portable · python import tracker unused definitions finder · code similarity detector python local · zero dependency python code analyzer
German (DE) statischer python code analyser mit gui · python ungenutzte imports finden ast · python toter code finder offline · code duplikate finden python difflib · python quellcode qualitaetspruefung ohne dependencies · tkinter python methoden analysieren · python ast analyse tool lokal · reversibler python import autofix

4. Installation & Quickstart

MethodenAnalyser requires no external runtime dependencies. Only a standard Python 3.10+ installation is required.

# Clone the repository
git clone https://github.com/dev-bricks/MethodenAnalyser.git
cd MethodenAnalyser

# Launch the desktop application
python MethodenAnalyser3.py

On Windows, you can also launch the tool immediately by double-clicking START.bat.

Runtime uses strictly the Python Standard Library. For running automated tests or building standalone executables, development requirements are specified in requirements-dev.txt; build boundaries are documented in BUILD.md.


5. Desktop GUI & Workflow Walkthrough

MethodenAnalyser Main Window

The desktop user interface displaying file-based analysis results and structural metrics.

Desktop Workflows

  1. Analyze a Single File:

    • Launch the application: python MethodenAnalyser3.py or double-click START.bat.
    • Click Analyze File (Alt+D / Ctrl+O) and choose a .py file.
    • Inspect active vs. unused imports, method hierarchies, and duplicate blocks.
  2. Analyze a Complete Project Folder:

    • Click Analyze Project (Alt+P / Ctrl+Shift+O) and select any project directory.
    • The engine recursively traverses the tree, pruning ignored folders (.git, .venv, node_modules).
    • An aggregated project report with overall metrics is generated.
  3. Accessible Navigation & Shortcuts:

    • Full WCAG 2.1 AA keyboard support: access the accessible shortcuts dialog with F1.
    • Context menu (Right-Click or App-Key) on the output area allows copying, saving reports, or clearing output.
    • Language switching directly via the menu bar (&Sprache / &Language).

6. Headless CLI & Automation

MethodenAnalyser runs completely headless for terminal scripts, pre-commit hooks, and CI/CD pipelines:

# Analyze a single file in the terminal
python MethodenAnalyser3.py --file path/to/file.py

# Analyze an entire project directory recursively
python MethodenAnalyser3.py --project path/to/project

# Analyze a file and export findings to JSON
python MethodenAnalyser3.py --file path/to/file.py --json-output

# Analyze via stdin and pipe output to a JSON file
type path\to\file.py | python MethodenAnalyser3.py --stdin --json-output snippet.json

# Render CLI output in a specific language (de, en, es, zh, ja, ru)
python MethodenAnalyser3.py --lang en --file path/to/file.py

The --json-output flag exports a machine-readable report named methodenanalyser-report-v1.json (or a custom name). Report specifications are defined in EXPORTFORMAT.md. Export targets that match an analyzed source file (including symlinks and hardlinks) are strictly rejected before writing, preventing source file overwrites.


7. Reversible Auto-Fix & Backup Lifecycle

The Auto-Fix feature (Alt+F) safely removes unused imports from analyzed Python sources:

  1. Explicit User Confirmation: Auto-Fix requires manual confirmation and presents a review of detected unused imports.
  2. Current AST Recheck: The engine re-parses the source file on disk immediately prior to modification to detect any concurrent edits. If the source changed, the operation aborts safely.
  3. Byte-Exact Atomic Backup: Creates an atomic backup (.bak, .bak.1, .bak.2, …) using same-directory hard links or atomic copy. Existing backups are never overwritten.
  4. Neighbor Preservation: Preserves surrounding comments, neighboring statements on the same line, and ensures required pass statements remain when a block body becomes empty.
  5. Syntax Verification: The sanitized code is verified via ast.parse() before writing. Only syntactically valid code is written.
  6. Atomic Replacement: Changes are written and flushed to a temporary file, then atomically replaced to ensure file integrity. Original encoding (including UTF-8 BOM), newline conventions, and permissions are preserved.

8. Local Web Companion & PWA Helper

For browser-based analysis of code snippets, single files, or small ZIP archives, launch the local helper:

python webapp/server.py

Or double-click START_WEBAPP.bat on Windows. The server runs at http://127.0.0.1:8765/ by default:

  • Pure Vanilla Architecture: Zero external JavaScript libraries, zero npm dependencies, zero remote CDNs.
  • Offline PWA Capabilities: Operates as a Progressive Web App (PWA) with a local service worker, client-side draft saving, and multi-resolution icons (mobile_icons/).
  • Strict Loopback Boundary [INV-ISOLATION-05]: Binds strictly to 127.0.0.1.
  • Explicit LAN Test Mode: For previewing across local devices, start with --host 0.0.0.0 --port 8765. This deliberate LAN test mode uses local HTTP without authentication or TLS. Use it only on a trusted private network; it is neither a cloud service nor a mobile product line. For further details, consult WEBAPP.md.

9. 10-Dimension Comparative Matrix vs. Existing Linters

Technical Dimension / Invariant MethodenAnalyser (dev-bricks) pylint flake8 vulture radon
1. Unused Import Tracking Yes (PEP 695 & Scope aware) Yes Partial (F401) Yes No
2. Unused Definition & Dead Code Yes (Methods, classes, async) Partial No Yes No
3. Code Similarity Detection Yes (difflib.SequenceMatcher) No No No No
4. Framework & Callback Awareness Yes (Tkinter, PyQt, Flask, etc.) Partial No Partial No
5. Interactive Desktop GUI (Tkinter) Yes (Native desktop + A11y) No No No No
6. Reversible Auto-Fix with .bak Yes (Atomic & syntax-checked) No No No No
7. Zero Runtime Dependencies (stdlib) Yes (100% Python Standard Library) No (Many deps) No (Many deps) No No
8. 100% Offline / Zero-Egress Yes (INV-LOCAL-01) Yes Yes Yes Yes
9. Native Multi-Language UI (6 langs) Yes (de, en, es, zh, ja, ru) No No No No
10. RunAsInvoker Non-Elevation Guarantee Yes (INV-SECURITY-02) Yes Yes Yes Yes

10. Dual Mermaid Diagrams

Architecture & Analysis Flow

flowchart TD
    subgraph Input["📥 Input Layer"]
        CLI["CLI Interface (--file, --project, --stdin)"]
        GUI["Tkinter Desktop GUI"]
        WebHelper["Local Web Companion (Fast & Offline PWA)"]
    end

    subgraph Core["⚙️ AST Analysis Engine"]
        Parser["Python ast.parse() & Safe Encoding Fallback (UTF-8 / Latin-1)"]
        Imports["Import & Namespace Tracker (Unused, Dunders, Future-Imports, PEP 695)"]
        Methods["Method & Class Cataloger"]
        Duplicates["SequenceMatcher Code-Similarity Engine"]
        Dynamic["Dynamic Attribute Chain & Reflection Inspector"]
        Scope["Import Scope & Typo Detector"]
    end

    subgraph Output["📤 Output & Export Formats"]
        GUISummary["Interactive GUI Results & Reversible Auto-Fix"]
        CLIText["Structured Terminal Report & Exit Codes"]
        JSONExport["methodenanalyser-report-v1.json (CI/CD Ready)"]
        BrowserUI["Web UI Inspection Dashboard"]
    end

    Input --> Parser
    Parser --> Imports & Methods & Duplicates & Dynamic & Scope
    Imports & Methods & Duplicates & Dynamic & Scope --> Output
Loading

End-to-End Analysis Lifecycle

sequenceDiagram
    autonumber
    actor Developer as Developer / CI Agent
    participant CLI as CLI / Desktop GUI / Webapp
    participant Engine as AST Engine (MethodenAnalyser3)
    participant Tracker as Import & Scope Tracker
    participant Diff as Duplicates (SequenceMatcher)
    participant Report as JSON / GUI / Text Formatter
    actor Target as Target Source Code (.py)

    Developer->>CLI: Launch analysis (--file / --project / GUI select)
    CLI->>Engine: Pass target paths / project root
    loop For each Python file
        Engine->>Target: Read file content (UTF-8 with Latin-1 fallback)
        Target-->>Engine: Raw code string
        Engine->>Engine: ast.parse(code, filename)
        Engine->>Tracker: Traverse AST nodes (Import, ImportFrom, Definitions)
        Tracker->>Tracker: Resolve scope bindings, PEP 695 type params & unused imports
        Engine->>Diff: Extract code block token hashes
        Diff->>Diff: SequenceMatcher comparison against similarity threshold
    end
    Engine->>Report: Aggregate metrics, unused imports, dead code, duplicates
    Report-->>CLI: Structured results (Exit Code / GUI View / JSON report)
    opt User triggers Auto-Fix
        Developer->>CLI: Confirm removal of unused imports
        CLI->>Target: Write atomic backup copy (.bak)
        CLI->>Target: Write sanitized Python source
        Target-->>Developer: Updated source code with clean imports
    end
Loading

11. Governance & 10 Runtime Invariants

MethodenAnalyser enforces 10 strict architectural, runtime, and security invariants:

Invariant Title Specification & Enforcement
INV-LOCAL-01 100% Local-First & Zero-Egress Zero outbound network calls, telemetry, analytics, or background phoning home. Source code and analysis metrics never leave the workstation.
INV-SECURITY-02 Non-Elevation / RunAsInvoker Runs entirely in standard unprivileged user space. Never requires or requests administrative, root, or elevated privileges.
INV-AST-03 Inert Static AST Parsing Analyzes code exclusively via Python's standard ast.parse(). Target files and module names are never dynamically imported (__import__ / exec).
INV-ENCODING-04 Lossless Multi-Encoding Resilience Default UTF-8 reading with automatic Latin-1 fallback. Never corrupts original character encodings, UTF-8 BOMs, or German umlauts.
INV-ISOLATION-05 Loopback Web Companion Isolation Local helper companion binds strictly to 127.0.0.1 by default. Deliberate --host 0.0.0.0 LAN test mode requires explicit user configuration.
INV-TRAVERSAL-06 Anti-Path-Traversal & ZIP Safety Web companion rejects path traversal (..), bounds member counts, and enforces maximum archive byte limits to prevent ZIP bombs.
INV-AUTOFIX-07 Reversible Auto-Fix with Backup Auto-Fix requires explicit confirmation, rechecks current source usage and publishes a byte-exact backup without replacing existing copies (.bak, .bak.1, …), then atomically replaces the source from a flushed temporary file. Detected source changes abort the write; encoding (including a UTF-8 BOM), newline style and file mode are retained.
INV-PLATFORM-08 Multi-Platform Parity 100% standard library core verified across Windows Server 2025, Ubuntu Linux, and macOS 26.
INV-SYNC-09 Cloud-Sync & Multi-Agent Lock Safety Fails closed on lock detection (LOCK.*), ignores cloud sync conflict files (*-conflict-*), preventing concurrency races.
INV-SLA-10 48h Security SLA & 5-Day Triage Strict vulnerability commitment: 48-hour initial response SLA and 5-business-day triage commitment with coordinated disclosure.

12. Exit Codes & JSON Schema Specification

For CI/CD scripts and automated quality gates, the tool returns deterministic exit codes:

  • 0 = Analysis succeeded, no issues or findings detected.
  • 1 = Syntax error, invalid CLI arguments, or analysis abort.
  • 2 = Analysis succeeded, but findings (unused imports, dead definitions, code duplicates) were detected.
  • 3 = Project analysis completed, but some individual files failed to parse.

JSON Report Format (methodenanalyser-report-v1.json)

{
  "schema_version": "methodenanalyser-report-v1",
  "generated_at": "2026-10-08T13:45:00Z",
  "tool_version": "3.0.2",
  "summary": {
    "total_files": 12,
    "total_lines": 3450,
    "total_functions": 84,
    "total_classes": 14,
    "unused_imports_count": 3,
    "unused_definitions_count": 1,
    "duplicate_blocks_count": 0
  },
  "files": []
}

Full schema specifications are documented in EXPORTFORMAT.md.


13. Testing, Verification & CI Hardening

Repository Hygiene

  • GitHub Remote: dev-bricks/MethodenAnalyser
  • The public hygiene baseline is a named commit or tag, not a permanent snapshot claim in this README. Before a release or handoff, run: git branch --show-current, git rev-list --left-right --count master...origin/master, and git status --short --ignored.
  • The expected gate is branch master, 0 0 ahead/behind for the named baseline, and a clean tree.
  • Before committing: run git status --short, execute a secret scan, and verify local compilation using python -m py_compile MethodenAnalyser3.py manage_translations.py translator.py.

Automated Test Suite

# Verify syntax across all modules
python -m compileall -q .

# Run static linter
ruff check .

# Execute full automated test suite
pytest -ra -v

GitHub Actions runs these smoke tests on every push. The runner labels are pinned to current migration targets (windows-2025-vs2026 and macos-26) to validate the same images that GitHub moves windows-latest and macos-latest toward.


14. Level 1 SBOM & Third-Party Licenses Companion

MethodenAnalyser requires zero external runtime packages. All core functionality is provided directly by the Python Standard Library (ast, tkinter, difflib, json, pathlib, http.server, etc.).

A canonical Level 1 Software Bill of Materials (SBOM) companion is maintained in both plain-text and markdown:


15. Sibling Ecosystem & Partner Matrix

MethodenAnalyser is part of the dev-bricks developer suite and the open-bricks umbrella of modular, offline-first utilities:

Tool Organization Description
DevCenter dev-bricks Central developer hub and automated workflow coordinator
CodeBox dev-bricks Local-first extensible IDE with declarative plugin architecture
MethodenAnalyser dev-bricks Static Python code and method analyzer with local GUI & CLI
CareCenter-for-Codex dev-bricks System hygiene and health center for AI agent setups
app-rotator dev-bricks Desktop focus and application rotation manager
lock-master ellmos-ai Cross-process lock and concurrency safety system
clutch ellmos-ai Local LLM orchestration, model routing, and prompt execution
assistant-core ellmos-ai Thread-safe persistence and message store backbone
decision-clicker ellmos-ai Local-first governance and decision ledger
policy-registry ellmos-ai Declarative policy enforcement and verification engine
ellmos-codecommander-mcp ellmos-ai MCP server for AST refactoring and code intelligence
ellmos-filecommander-mcp ellmos-ai MCP server for safe local file operations
ExplorerPro file-bricks Modern tabbed file manager with duplicate detection
ProFiler file-bricks High-performance document categorizer with PII redaction
FormularErstellen doc-bricks Deterministic schema-driven form and survey creator
open-bricks open-bricks The open umbrella ecosystem coordinating local-first developer tools

16. Security Policy, RunAsInvoker & Zero-Egress

Security and data sovereignty are foundational requirements:

  • Local-First & Zero Network Egress [INV-LOCAL-01]: 100% offline analysis. No analytics, tracking, or network calls.
  • Unprivileged User Mode [INV-SECURITY-02]: Runs strictly as RunAsInvoker. Never requires or requests administrative privileges.
  • Inert Static Execution [INV-AST-03]: Inspected code is strictly parsed into an AST; code is never executed or dynamically imported.
  • Vulnerability Response Commitment [INV-SLA-10]: Initial acknowledgement within 48 hours; triage within 5 business days.
  • Reporting Channels:

See the full SECURITY.md for detailed policies in English and German.


17. Statutory Notice (§ 521 BGB Gefälligkeitsrecht)

This project is a gratuitous open-source donation ("unentgeltliche Open-Source-Schenkung" under German Civil Code §§ 516 ff. BGB). Under German law (§ 521 BGB), liability is limited to intent and gross negligence. The standard MIT License disclaimer applies globally.

Use at your own risk. No support guarantees, no warranty for fitness for a particular purpose or error-free operation.


18. License & Open-Source Umbrella

This project is open-source software licensed under the MIT License.

MethodenAnalyser is proudly part of the open-bricks umbrella initiative for modular, sovereign, and privacy-respecting software tools.

About

Statischer Python-Code-Analyser mit Tkinter-GUI: findet ungenutzte Imports, tote Definitionen und ähnliche Code-Blöcke via AST-Analyse. Kein pip install nötig.

Topics

Resources

Code of conduct

Contributing

Security policy

Stars

1 star

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors

Languages