Repository navigation
Comparing changes
Open a pull request
base repository: colbymchenry/codegraph
base: main
head repository: pses/codegraph
compare: main
- 15 commits
- 29 files changed
- 1 contributor
Commits on Sep 2, 2026
-
feat: first-class extract-only mode (--extract-only / CODEGRAPH_EXTRA…
…CT_ONLY): nodes+unresolved_refs, no resolution
Configuration menu - View commit details
-
Copy full SHA for 314ac69 - Browse repository at this point
Copy the full SHA 314ac69View commit details -
feat: stamp edges with source/target repo + confidence tier (keep cro…
…ss-repo name edges)
Configuration menu - View commit details
-
Copy full SHA for b99be52 - Browse repository at this point
Copy the full SHA b99be52View commit details -
Configuration menu - View commit details
-
Copy full SHA for e18303a - Browse repository at this point
Copy the full SHA e18303aView commit details -
Configuration menu - View commit details
-
Copy full SHA for 8aca507 - Browse repository at this point
Copy the full SHA 8aca507View commit details -
Configuration menu - View commit details
-
Copy full SHA for 6afa935 - Browse repository at this point
Copy the full SHA 6afa935View commit details -
feat: 'resolve' command — resolve references over an already-extracte…
…d DB (no re-extract)
Configuration menu - View commit details
-
Copy full SHA for 5a3bedf - Browse repository at this point
Copy the full SHA 5a3bedfView commit details -
Configuration menu - View commit details
-
Copy full SHA for c3c02b5 - Browse repository at this point
Copy the full SHA c3c02b5View commit details -
Configuration menu - View commit details
-
Copy full SHA for 2192218 - Browse repository at this point
Copy the full SHA 2192218View commit details -
Configuration menu - View commit details
-
Copy full SHA for 260be74 - Browse repository at this point
Copy the full SHA 260be74View commit details
Commits on Sep 4, 2026
-
feat: edgeTier — one metadata key that always means confidence
`metadata.tier` is overloaded, and the overload only became load-bearing now that a consumer wants to filter the WHOLE edge set by how much to trust an edge. On a resolved edge `tier` is the P2A confidence — `high` for an import/qualified-name/framework binding, `medium` for a same-repo name match, `low` for a cross-repo one. On a cross-tier synthesized edge (`resolution/tier-synthesizer.ts`) `tier` is a DIRECTION: `client→server` / `server→client`. Both meanings are real and both are read: `src/context`, `src/mcp/tools` and the Steps view (`ui-server/api/steps.ts`) all branch on the direction spelling by that name, and `edge-repo-tier.test.ts` pins the confidence spelling. So the key cannot be reclaimed on either side without breaking the other, and a reader holding an arbitrary edge cannot tell which of the two it is looking at. `edgeTier` carries the same confidence value under a name that never means anything else. Purely additive: `tier` is emitted exactly as before, every existing reader is untouched, and the new key is what a consumer filters on. The REST edges in the next commit stamp `edgeTier` for the same reason — their `tier` is already spoken for by the direction.
Configuration menu - View commit details
-
Copy full SHA for c8c2525 - Browse repository at this point
Copy the full SHA c8c2525View commit details -
feat: cross-repo REST edges — repo stamps, a confidence tier, SFC + F…
…astify clients A user's project groups several repos, and the real coupling between them is an HTTP call on one side and a route handler on the other — neither side imports the other, so name resolution draws nothing. The `http-client` channel of the cross-tier synthesizer already pairs a literal client path with the `METHOD path` route node that serves it, and because it runs at RESOLVE time over the merged graph, it was already crossing repos. What it was missing is everything the per-project layer needs to USE such an edge. Repo stamps. `sourceRepo` / `targetRepo` come from `repoOfFilePath` — the same `file_path` first-segment derivation `db/repo-scope` scopes queries by, so an edge's stamps and the MCP session's boundary can never disagree. `crossRepo` marks the pair that spans two repos, which is the set this whole feature exists to surface. A confidence tier, under `edgeTier` (the previous commit's key; this edge's `tier` is already the direction). Never `high`: `high` is reserved for a resolver that PINS a declared target through a binding — an import, an FQN, a framework registry. An HTTP pairing has no binding. It is textual agreement between two strings written independently on either side of a wire, and it holds only as long as both stay written that way. `medium` when the client wrote the whole path from the root and it aligns with the route template segment for segment; `low` when only the TAIL matched because a base URL hid the front of the path (`${API}/users` against `GET /api/users`) — the hidden prefix could belong to another service entirely. Crossing a repo does NOT demote a REST edge, which is deliberately the opposite of the rule for a bare-name edge. There, two repos sharing a name is evidence of coincidence. Here, client and server in different repos is the NORMAL shape of the thing being detected; demoting for it would bury exactly the edges the pass is for. Precision is bought elsewhere and was already bought: a dynamic URL resolves to nothing, a method the route does not serve matches nothing, and a path two routes serve alike is dropped as a tie rather than guessed at. Two coverage gaps closed, both of which made the channel silent on the stacks this is for. `.vue` / `.svelte` / `.astro` files were not scanned at all, so a Vue or Svelte frontend produced no client→server edge however plainly it named the path — they are now read for the HTTP channel ONLY. The queue and event channels stay off for them on purpose: those read decorator, `new Worker(…)` and `.on(…)` shapes that an SFC's `<template>` does not contain, and widening them would change edges on graphs with no HTTP in them at all, which is the one regression this must not introduce. And the express extractor read only `app.` / `router.`, so Fastify's own `fastify.get('/x', handler)` declared no route node and had nothing to pair with; `fastify` is safe to add where `server` is not, because the synthesizer already lists `fastify` among the receivers that register routes and can never be a client (SERVER_NAMES) while `server` is on its CLIENT_NAMES list. `__tests__/http-cross-repo-edges.test.ts` is a fixture pair of repos — a frontend whose only link to the API is the path it calls, and an express/ Fastify service declaring it. It pins the medium-tier whole-path pairing with both repo stamps, the low-tier tail match behind a base URL, that no REST edge is ever `high`, the two negatives (dynamic URL, method mismatch), the Vue SFC and Fastify cases, and two scope properties. Scope safety is not new code: `createScopedCodeGraph` drops an edge unless BOTH endpoints resolve to in-scope nodes, and a route node in an out-of-scope repo reads back as `null` like any other node — so the test asserts a REST edge leaving the scope is filtered identically to the cross-repo NAME edge beside it, through `getOutgoingEdges`, the batch `getOutgoingEdgesFrom` / `getIncomingEdgesTo` behind `codegraph_explore`, and from the server side too, while both repos in scope keeps the edge. The last test runs the real pipeline — extract each repo under its own root, merge the DBs through the app's explicit column lists, resolve over the merge — proving the route node arrives by row-copy and the pairing is made on the merged graph, not only when the repos are indexed together.Configuration menu - View commit details
-
Copy full SHA for 731bd36 - Browse repository at this point
Copy the full SHA 731bd36View commit details
Commits on Sep 9, 2026
-
Configuration menu - View commit details
-
Copy full SHA for 27e3007 - Browse repository at this point
Copy the full SHA 27e3007View commit details
Commits on Oct 1, 2026
-
feat: codegraph_node reads yaml/properties with secret values masked
File mode returned only the key list for a config file and pointed to Read, which an agent with no filesystem tools does not have. It now serves the file with real line numbers; values of secret-named keys, URL passwords, opaque tokens and PEM blocks are replaced by <redacted>, flags and plain values stay visible. Explore and symbol mode keep withholding config source. Version 1.6.0-sesp-004.
Configuration menu - View commit details
-
Copy full SHA for e0ed83f - Browse repository at this point
Copy the full SHA e0ed83fView commit details -
feat: CODEGRAPH_TRUST_ROOT_LINKS — serve sources through repo links i…
…n the project root A merged multi-repo project holds one symlink per repository pointing at its checkout outside the project dir, so every content read escaped the root and was refused (#527): codegraph_node file mode and explore served symbols only. With CODEGRAPH_TRUST_ROOT_LINKS=1 a symlink directly in the root is a source root; a path under it is served while its real path stays inside that link's target. Deeper links and links escaping a repo stay rejected. Version 1.6.0-sesp-005.
Configuration menu - View commit details
-
Copy full SHA for 11fed02 - Browse repository at this point
Copy the full SHA 11fed02View commit details -
fix: codegraph_node file mode stays under the host's inline result limit
The file view was budgeted at 38K chars; Copilot CLI spills a larger tool result to a temp file the agent may not be allowed to read back, so a long file came back as a file path. The budget is now 19.5K (20K with the pagination note), like explore's ~25K hardCeiling; longer files paginate with offset/limit. Version 1.6.0-sesp-006.
Configuration menu - View commit details
-
Copy full SHA for aad413b - Browse repository at this point
Copy the full SHA aad413bView commit details
This comparison is taking too long to generate.
Unfortunately it looks like we can’t render this comparison for you right now. It might be too big, or there might be something weird with your repository.
You can try running this command locally to see the comparison on your machine:
git diff main...main