Beta
Freemium
Developer Tooling

ManifestGuard Python

Answers the one question before you ship: May I ship? Catch packaging traps, dependency conflicts, and import leaks before CI goes green and a broken wheel hits production.

Gallery

Features

Rein in the AI horse

AI assistants make a repo look finished overnight. Tested blocks vanish, the same logic appears many times, and past a certain file size the model slows down while analysis cost climbs and quality drops. ManifestGuard reports only: complexity budgets and breaks of defined refactoring rules (not a line-count cutoff). Split and correction are for a human or, best case, the AI.

ReportsRefactoring rulesAI

Packaging without surprises

Checks pyproject.toml, setup.py, and requirements.txt for consistency. Finds typical packaging traps before the wheel is built.

pyproject.tomlrequirements.txtEntry points

Dependency and entry checks

Finds broken script targets, undeclared third-party imports, and version conflicts before a user hits a crash.

Entry pointsDependenciesConflicts

Policy enforcement

Apply package allow/block rules and version constraints from plain configuration.

PoliciesRulesConfig

Clean import hygiene (Free)

The free check finds unused, unordered, undeclared, and circular imports before they disturb a release. Commands are in the guides.

FreeImports

Deeper quality signals (Pro)

Unlock complexity, duplication, dummy/placeholder code, and related health metrics.

ComplexityDuplicationCoverage

Honest CI metrics (Pro)

Keeps CI from going green on stale coverage. Deterministic exit codes for the pipeline. Setup is in the guides.

ProCI

Static leak scan (Pro)

ManifestGuard Pro, second test branch — not inside the everyday check: forgotten thread, timer, logger, and QThread patterns in source. Command: check-lifecycle. How to run it is in the guides.

ProLifecycle

Evidence and SBOM reports

Machine-readable reports (SARIF/JSON) and SBOM completeness for audits. SPDX and CycloneDX are standard formats for these inventories.

ReportsSBOMEvidence

QuickFix with backup

Preview supported fixes first. ManifestGuard writes only registered patches after a workspace snapshot and file backups, where the license allows it.

QuickFixBackupSafe apply

Check the project as a system, not just the code.

Classic linters (like ruff) edit your code. Security scanners look for known CVEs. ManifestGuard Python is the quality gate before you ship.

When pyproject.toml does not match the real import tree, script targets go nowhere, or coverage numbers in CI are stale, that usually shows up after release. The everyday ManifestGuard check is for that: packaging, entry points, dependencies, and import hygiene — the quality gate before you ship.

ManifestGuard Pro goes two steps further, and they stay separate. --extended deepens the same check (complexity, honest CI coverage, SBOM). check-lifecycle is a second test branch: leak patterns in the source (threads, timers, loggers). That leak scan is not inside the regular check and not inside --extended.

AI assistants are fast and error-prone. Tested blocks vanish, redundancies multiply, and past a certain file size the model slows down. Bloated code raises analysis cost while quality drops and debugging takes longer. ManifestGuard reports complexity budgets and breaks of defined refactoring rules (not a line-count cutoff). Split and correction are done by a human or, best case, by the AI. Then run the check again until the ship gate is clean.

ManifestGuard Python is the AI dream: find weaknesses in development without GitHub Actions or other expensive test tools, and have them corrected. ManifestGuard reports only. Split and correction follow defined refactoring rules — by a human or, best case, by the AI.

The Community version is the everyday check. ManifestGuard Pro unlocks the deeper analysis, the separate leak scan, machine-readable SBOM/evidence reports, and 2 device activations (laptop + CI). The license is annual with 12 months of updates; after that you can keep using the last entitled version.

Cost of bloated files vs AI analysis

Install, license activation, and every command live in the guides.

Overview

Columns
Manifest & packaging validation
Entry point consistency checks
Dependency analysis
Import hygiene
Custom validation rules
Extended analysis
Coverage for CI
Lifecycle leak scan
SBOM & CVE signals
QuickFix suggestions
QuickFix apply (supported findings + backup)

Licensing

Columns
Community
1
€0
Trial (14 days)
1
€0
Pro
2
€99/year (early access to 2026-12-31), then €149/year

Applies to the purchased version incl. all updates for 1 year from the purchase date.