Same code in.
Same findings out.
Static analysis that maps your whole JavaScript, TypeScript or Python project and reports only what it can prove, with the chain of evidence attached. Native Rust. No model decides.
- v0.4.0
- v0.3.0
- 23
- JS, TS, Python
Snowbros Atlas analyze run 1 root: /work/acme-web files scanned: 512 cache: 0 reused, 512 parsed frameworks: Next.js 15.1.0, React 19.0.0 HIGH Server-only module imported by a client component [next/server-only-in-client] at src/components/Dashboard.tsx, confidence: certain x 1 finding: 1 High health: 92/100 (security 100, architecture 85)
Evidence chain
Same input, same output
src/components/Dashboard.tsx"use client"src/lib/metrics.tsimported by Dashboardsrc/lib/db.tsimports "server-only"
Per-file linters can’t see project structure. Atlas can.
Deterministic by construction
No AI, no timestamps, no network. Same code and config in, same findings out, the warm-cache run is byte-identical to a cold one, enforced by tests.
Milliseconds, not minutes
A native Rust binary with an incremental cache: ~270 ms cold and ~34 ms after a one-file change on a 500-file repo. Fast enough to run on every save.
Evidence, not vibes
Every finding carries the chain that produced it and a confidence level. Anything the resolver can't prove is labeled unresolved, never guessed.
Whole-project graph
Symbol, import, and file graphs with cycle detection and dead-file reachability, plus a Next.js project model and a React semantic model. The structural problems per-file linters can't see.
Meets you everywhere
Terminal, JSON, SARIF for GitHub code scanning, self-contained HTML, and Markdown, with a health scorecard, a built-in LSP, and a first-party VS Code extension.
Fixes it can prove
The auto-fix engine applies guarded, idempotent edits for unused deps and env vars. Files that drifted since analysis are skipped, never clobbered.
One deterministic pipeline, cache-accelerated.
Scanner
ignore-aware walk
Tree-sitter
parse · cached
Atlas IR
typed facts
Semantic Engine
resolve · model
Symbol Graph
symbols · imports · files
Rule Engine
23 rules · evidence-first
Auto Fix
guarded edits
CLI
sb · snowbros
LSP
editor diagnostics
Outputs
terminal · json · sarif · html · md
Warm output is byte-identical to a cold run, the cache can skip work, never change results. Read the architecture
One engine. Multiple languages.
Every language lowers into one shared semantic IR, so a rule is written once and runs everywhere it applies, never a if language == branch buried in a detector. Import cycles, dead files, unresolved imports, and the cross-language complexity/large-function rule already run on Python and the JavaScript/TypeScript family alike. Python ships at preview maturity.
Languages
Frameworks
It understands the Next.js project model.
App Router, Pages Router, and mixed setups, with the routing conventions, special files, and server/client boundaries resolved into a real model, not guessed by filename.
A semantic model for React (M1).
Component detection
Function and arrow components resolved from the semantic model, not string matching.
Hook detection
Built-in and custom hooks identified by call enclosure and naming predicate.
JSX analysis
JSX and TSX parsed and understood as part of the component graph.
Async client component rule
Flags `async` components in client boundaries, a real runtime hazard.
Hook misuse detection
Catches hooks called outside a component or hook, against the rules of hooks.
Component naming
Enforces PascalCase component and use-prefixed hook naming conventions.
Run it alongside your linter, not instead of it.
| Capability | Atlas | ESLint | Knip | dep-cruiser |
|---|---|---|---|---|
| Whole-project semantic graph | Yes | Per-file | Partial | Yes |
| Circular imports (cycle listed) | Yes | Plugin | No | Yes |
| Dead files / unused exports | Yes | No | Yes | Partial |
| Next.js server/client boundary | Yes | Partial | No | No |
| Deterministic, evidence-first | Yes | Mostly | Mostly | Mostly |
| SARIF · LSP · watch · scorecard | Yes | LSP only | No | No |
| Runtime | Native | Node | Node | Node |
One line to try it. No account, no config.
npm (global)
npm install -g @snowbros/atlasnpm, no install needed
npx snowbros analyzeHomebrew (macOS, Linux)
brew install snowbros-labs/tap/snowbros-atlasCargo
cargo install snowbros-atlas --lockedFirst-class VS Code support.
Published on the VS Code Marketplace (v0.3.0). The extension wraps the built-in language server, so findings stream into native diagnostics in real time as you save, severities mapped to Errors, Warnings, Hints, with click-to-navigate. Analyze, explain a rule, open an HTML report, or check the health score without leaving the editor.

One analysis, every format you need.
Terminal
colored, human-readable summary
JSON
canonical, machine-readable report
SARIF
GitHub code scanning integration
HTML
self-contained health report
Markdown
drop into PRs and docs
Fast enough to run on every save.
270ms
500-file project, release build
43ms
byte-identical to a cold run
34ms
incremental, watch mode
Measured on real repositories (zod, axios, fastify). See the dogfood reports
Where Atlas is going.
Shipped
- Multi-language foundation (shared IR)
- Python frontend + resolver
- First cross-language rule (large-function)
Next
- More languages: Go, Rust, Java
- More cross-language rules from real reports
- Rule maturity gating (nursery)
Later
- Interprocedural analysis
- Pattern rule engine (no Rust)
- OSV vulnerability data
Questions, answered.
Is it a linter? Do I replace ESLint or Biome?
No. Atlas works one layer up, on whole-project structure, the import graph, framework boundaries, and manifest. Run it alongside your linter, not instead of it.
Does it use AI?
No. Atlas is deterministic by design: the same codebase and config always produce the same findings, each backed by an evidence chain. No model decides whether an issue exists.
Which languages are supported?
The JavaScript/TypeScript family (.js/.jsx/.ts/.tsx and their .mjs/.cjs variants) and Python (.py). Both lower into one shared semantic IR, so language-neutral rules, import cycles, dead files, unresolved imports, and function complexity, run on either without special-casing. Python ships at preview maturity; Go, Rust, and Java are next on the roadmap.
Will it slow down or break my CI?
It is native-fast, and `sb analyze --ci` is a single exit-code gate. Because Atlas finds more over time, pin the version and use snowbros.toml thresholds to control what fails the build.
Map your project in one command.
Run it on your repository now. If a finding is wrong, open an issue: that is how the rules get better.