Recipe catalog / change-risk
Grade change risk
How risky is change to ship, given context, on a five-level rubric?
You need to size the risk of a described code change before choosing reviewers, test depth, rollout strategy, or approval requirements.
Explore this recipe interactively ยท Source and implementation guide
Use change-risk in TypeScript
Install with npm install jev-recipes. Requires Node.js 22.9 or newer and ES modules. Set TYPESAFE_API_KEY in your server environment for live calls, which send input to TypeSafe and use API quota. See the installation guide.
import { changeRisk } from 'jev-recipes/change-risk';
const result = await changeRisk({
"change": "Replace the session-token validation in the auth middleware with the new JWT verifier, and drop the fallback to the legacy cookie session for all API routes.",
"context": "The middleware runs on every authenticated request. About 5% of active users still hold legacy cookie sessions.",
"minConfidence": 0.8
});
console.log(result);
Input contract
| Field | Type | Needed |
|---|---|---|
| change | string | Required |
| context | string | Optional |
| minConfidence | number | Optional |
Full input and result schemas
{
"input": {
"$schema": "https://json-schema.org/draft/2020-12/schema",
"type": "object",
"properties": {
"change": {
"type": "string"
},
"context": {
"type": "string"
},
"minConfidence": {
"type": "number",
"minimum": 0,
"maximum": 1
}
},
"required": [
"change"
]
},
"result": {
"$schema": "https://json-schema.org/draft/2020-12/schema",
"type": "object",
"properties": {
"model": {
"type": "string"
},
"usage": {
"type": "object",
"properties": {
"input_tokens": {
"type": "integer",
"minimum": 0,
"maximum": 9007199254740991
},
"output_tokens": {
"type": "integer",
"minimum": 0,
"maximum": 9007199254740991
}
},
"required": [
"input_tokens",
"output_tokens"
],
"additionalProperties": false
},
"status": {
"type": "string",
"enum": [
"ready",
"review"
]
},
"score": {
"type": "number",
"minimum": 0
},
"level": {
"type": "integer",
"minimum": 0,
"maximum": 9007199254740991
},
"confidence": {
"type": "number",
"minimum": 0,
"maximum": 1
},
"probabilities": {
"type": "object",
"propertyNames": {
"type": "string"
},
"additionalProperties": {
"type": "number",
"minimum": 0,
"maximum": 1
}
},
"risk": {
"type": "string",
"enum": [
"negligible",
"low",
"moderate",
"high",
"critical"
]
}
},
"required": [
"model",
"usage",
"status",
"score",
"level",
"confidence",
"probabilities",
"risk"
],
"additionalProperties": false
}
}Saved example result
This hand-authored response demonstrates the contract. It is not a model accuracy measurement. Run it without an API key: npx jev-recipes demo change-risk.
{
"model": "demo-fixture",
"usage": {
"input_tokens": 0,
"output_tokens": 0
},
"status": "ready",
"score": 2.9,
"level": 3,
"confidence": 0.8,
"probabilities": {
"0": 0,
"1": 0.02,
"2": 0.12,
"3": 0.8,
"4": 0.06
},
"risk": "high"
}
Evaluation evidence
No verified live accuracy measurement is available. Evaluate representative cases before using this decision in your workflow.
Use the evaluation guide to measure this decision on your own labeled cases.
Limitations
- Grades the change as described, not the actual diff. An incomplete or misleading description produces a misleading grade.
- Does not verify test coverage or rollback tooling. Map levels to review and rollout policies in application code.
Related recipes
- task-complexity: Use task-complexity to grade how hard the work is, rather than how dangerous shipping it is.
- action-scope: Use action-scope to check whether a change stays within the work that was requested.