Graft vs ripwire

Graft is much bigger: 9.7k stars against 2.4k. Over the days we have tracked them Graft moved +2150.1% and ripwire +165.1%, so Graft is growing faster right now.

Neither one leads on the six capability axes, so the choice comes down to which of them fits the way you already work.

Stars and commit dates come from our own daily tracking. The six axes are read off each project's documentation by our review pipeline, so they describe what a project says about itself, not what we measured in its code.

Where they stand today

Persists a deterministic, human-readable context graph as markdown files inside the repo (no embeddings or external index), so agents can follow real files and share an up-to-date code understanding via git.

Stars
9.7k
Tracked growth
+2150.1%
Maturity
●●●●●
Last commit
9m ago
Language
TypeScript
License
MIT
Cost to run
Your API key; provider billing applies.

A zero-dependency, fully local CLI that produces a ranked, token-budgeted call-graph and blast-radius map with disclosed uncertainty and deterministic results, avoiding index servers and heavy token costs.

Stars
2.4k
Tracked growth
+165.1%
Maturity
●●●●●
Last commit
2d ago
Language
C++
License
Apache-2.0
Cost to run
Free, local binary
0%+2150%70 tracked days
NanoNets/Graftredhat-et/ripwire

Six axes, head to head

Each axis runs 0 to 5. The label under a score is what that project's own docs claim, not a category average.

AxisGraftripwire
Context depth
How much of your codebase it sees before it answers: the open diff, the diff plus related files, or the whole repository.
●●●●●
Whole-repo graph
●●●●●
Whole-repo analysis
Noise control
How it keeps output volume down — severity thresholds, deduplication, incremental runs over new commits only.
●●●●●
Ranking & checks
●●●●●
Confidence & disclosure
Customization
How far it bends to your team: custom rules, prompts, style guides, per-path config.
●●●●●
Config & flags
●●●●●
CLI options & grammars
Privacy
Whether your code stays on your own infrastructure: fully local, self-hostable, or cloud API only.
●●●●●
Self-hostable
●●●●●
Fully local
Model freedom
Whether you can point it at any provider, or it is wired to one.
●●●●●
Bring-your-key
●●●●●
Provider-agnostic
Setup ease
What it takes to get a first useful run out of it.
●●●●●
One-command init
●●●●●
One-line install

Which one to pick

Pick Graft if…

Easy setup — one-command init builds a local, versionable code-graph and wires directly into coding agents (Claude Code et al.) to cut tokens, tool calls, and latency.

Runs in cli, ide, coding-agent-plugin, ci. Works with byok, openai, anthropic.

Pick ripwire if…

Privacy-first — run a single self-contained binary offline to get a ranked, token-efficient map of your repo without sending code to the cloud.

Runs in cli, coding-agent-plugin. Works with byok.

What people want from each one

Questions people ask

Is Graft better than ripwire?

Neither one leads on the six capability axes, so the choice comes down to which of them fits the way you already work. Graft is worth picking when easy setup — one-command init builds a local, versionable code-graph and wires directly into coding agents (Claude Code et al.) to cut tokens, tool calls, and latency.

Which of Graft and ripwire keeps my code private?

Graft: Self-hostable (4/5). ripwire: Fully local (5/5).

What does each one cost to run?

Graft: Your API key; provider billing applies.. ripwire: Free, local binary.

Full profiles: NanoNets/Graft and redhat-et/ripwire. Everything else in Codebase context.