curl --request GET \
--url https://api.example.com/api/v1/repositories/{repo_id}/impact \
--header 'X-API-Key: <api-key>'import requests
url = "https://api.example.com/api/v1/repositories/{repo_id}/impact"
headers = {"X-API-Key": "<api-key>"}
response = requests.get(url, headers=headers)
print(response.text)const options = {method: 'GET', headers: {'X-API-Key': '<api-key>'}};
fetch('https://api.example.com/api/v1/repositories/{repo_id}/impact', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.example.com/api/v1/repositories/{repo_id}/impact",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "GET",
CURLOPT_HTTPHEADER => [
"X-API-Key: <api-key>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"net/http"
"io"
)
func main() {
url := "https://api.example.com/api/v1/repositories/{repo_id}/impact"
req, _ := http.NewRequest("GET", url, nil)
req.Header.Add("X-API-Key", "<api-key>")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.get("https://api.example.com/api/v1/repositories/{repo_id}/impact")
.header("X-API-Key", "<api-key>")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.example.com/api/v1/repositories/{repo_id}/impact")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Get.new(url)
request["X-API-Key"] = '<api-key>'
response = http.request(request)
puts response.read_body{
"affected_repositories": [
{
"confidence": 123,
"depth": 123,
"full_path": "<string>",
"id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"name": "<string>"
}
],
"applied_min_confidence": 123,
"excluded_by_confidence": 123,
"max_depth_reached": 123,
"source_repository": {},
"total_affected": 123
}{
"detail": [
{
"loc": [
"<string>"
],
"msg": "<string>",
"type": "<string>",
"ctx": {},
"input": "<unknown>"
}
]
}Transitive downstream blast radius (repo-level BFS). NOT file-path scoped — accepts only `max_depth` + `min_confidence`.
Get the full downstream impact of changing this repository.
Returns all repositories that depend on this one, directly or transitively,
up to max_depth hops away. Use this before publishing a breaking change.
Repo-level scope, not file-scoped. This endpoint computes a BFS over
repo-to-repo dependency edges; it does not trace specific files, jobs,
or symbols within the source repo. There is no path, paths,
file, or job query parameter — agents asking “who consumes file X
in repo Y” should call /repositories/{id}/dependents and then grep the
consumer repos directly, since per-file edges aren’t stored in the graph.
GitHub Actions are the exception: every /dependents row carries the full
uses: path in raw_reference (e.g.
grafana/shared-workflows/actions/send-slack-message), so “who uses action
or reusable workflow X” is answered by filtering those rows, no grep needed.
Unknown query parameters are silently ignored by FastAPI, which can mask
hallucinated filter names — if a filter doesn’t appear in this signature,
it’s not honoured.
For artifact-level consumers (who pulls Docker image / Helm chart /
Terraform module X and at what version), use /artifacts/{id}/consumers
instead — that endpoint is version-aware.
Confidence. Traversal follows only edges at or above min_confidence,
which defaults to 0.4: every reference a machine could act on, excluding only
the tier that means a human reads it (prose, templates, generated blobs). The
floor that was applied is echoed as applied_min_confidence, the repos it
removed are counted in excluded_by_confidence so a truncated answer is
never silent, and each affected repo carries the confidence of the weakest
edge on the strongest chain that reached it — so a stricter blast radius is a
filter over this response, not a second request.
curl --request GET \
--url https://api.example.com/api/v1/repositories/{repo_id}/impact \
--header 'X-API-Key: <api-key>'import requests
url = "https://api.example.com/api/v1/repositories/{repo_id}/impact"
headers = {"X-API-Key": "<api-key>"}
response = requests.get(url, headers=headers)
print(response.text)const options = {method: 'GET', headers: {'X-API-Key': '<api-key>'}};
fetch('https://api.example.com/api/v1/repositories/{repo_id}/impact', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.example.com/api/v1/repositories/{repo_id}/impact",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "GET",
CURLOPT_HTTPHEADER => [
"X-API-Key: <api-key>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"net/http"
"io"
)
func main() {
url := "https://api.example.com/api/v1/repositories/{repo_id}/impact"
req, _ := http.NewRequest("GET", url, nil)
req.Header.Add("X-API-Key", "<api-key>")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.get("https://api.example.com/api/v1/repositories/{repo_id}/impact")
.header("X-API-Key", "<api-key>")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.example.com/api/v1/repositories/{repo_id}/impact")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Get.new(url)
request["X-API-Key"] = '<api-key>'
response = http.request(request)
puts response.read_body{
"affected_repositories": [
{
"confidence": 123,
"depth": 123,
"full_path": "<string>",
"id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"name": "<string>"
}
],
"applied_min_confidence": 123,
"excluded_by_confidence": 123,
"max_depth_reached": 123,
"source_repository": {},
"total_affected": 123
}{
"detail": [
{
"loc": [
"<string>"
],
"msg": "<string>",
"type": "<string>",
"ctx": {},
"input": "<unknown>"
}
]
}Authorizations
Headers
Path Parameters
Query Parameters
Maximum BFS depth (hops from the source repo). Range 1–20, default 10.
1 <= x <= 20Minimum edge confidence to traverse, between 0.0 and 1.0. The default 0.4 admits every reference a machine could act on — deterministic parser edges (0.9–1.0), resolver matches (0.65–0.95), heuristic references in build and CI files, package manifests and fetch commands (0.85), and references in files the classifier does not recognise (0.6–0.7), which mean 'unclassified', not 'unlikely'. It excludes only references a human reads rather than a machine executes: prose, HTML templates, generated blobs and ignore files (0.3). Pass 0.8 to restrict the answer to deterministic and build-file evidence only, or 0.0 to include everything. The value actually applied is echoed in the response, and each affected repository carries the confidence of the weakest edge on the strongest path that reached it, so a stricter answer can be recovered by filtering the response without a second request.
0 <= x <= 1Cookies
Response
Successful Response
Full downstream impact of changing a repository.
Show child attributes
Show child attributes
The confidence floor actually used for this traversal, whether it came from the min_confidence query parameter or the server default. Echoed so a caller can tell a filtered answer from a complete one.
Repositories that depend on the source repo only through edges below applied_min_confidence, and so are absent from affected_repositories. Added to total_affected this is the unfiltered blast radius; pass a lower min_confidence to see them.
