Skip to content
Permalink

Comparing changes

Choose two branches to see what’s changed or to start a new pull request. If you need to, you can also or learn more about diff comparisons.

Open a pull request

Create a new pull request by comparing changes across two branches. If you need to, you can also . Learn more about diff comparisons here.
base repository: colbymchenry/codegraph
Failed to load repositories. Confirm that selected base ref is valid, then try again.
Loading
base: main
Choose a base ref
...
head repository: pses/codegraph
Failed to load repositories. Confirm that selected head ref is valid, then try again.
Loading
compare: main
Choose a head ref
Checking mergeability… Don’t worry, you can still create the pull request.
  • 15 commits
  • 29 files changed
  • 1 contributor

Commits on Sep 2, 2026

  1. feat: first-class extract-only mode (--extract-only / CODEGRAPH_EXTRA…

    …CT_ONLY): nodes+unresolved_refs, no resolution
    semenovale-cloud committed Sep 2, 2026
    Configuration menu
    Copy the full SHA
    314ac69 View commit details
    Browse the repository at this point in the history
  2. Configuration menu
    Copy the full SHA
    b99be52 View commit details
    Browse the repository at this point in the history
  3. Configuration menu
    Copy the full SHA
    e18303a View commit details
    Browse the repository at this point in the history
  4. Configuration menu
    Copy the full SHA
    8aca507 View commit details
    Browse the repository at this point in the history
  5. Configuration menu
    Copy the full SHA
    6afa935 View commit details
    Browse the repository at this point in the history
  6. Configuration menu
    Copy the full SHA
    5a3bedf View commit details
    Browse the repository at this point in the history
  7. Version

    semenovale-cloud committed Sep 2, 2026
    Configuration menu
    Copy the full SHA
    c3c02b5 View commit details
    Browse the repository at this point in the history
  8. Configuration menu
    Copy the full SHA
    2192218 View commit details
    Browse the repository at this point in the history
  9. fixes

    semenovale-cloud committed Sep 2, 2026
    Configuration menu
    Copy the full SHA
    260be74 View commit details
    Browse the repository at this point in the history

Commits on Sep 4, 2026

  1. feat: edgeTier — one metadata key that always means confidence

    `metadata.tier` is overloaded, and the overload only became load-bearing now
    that a consumer wants to filter the WHOLE edge set by how much to trust an
    edge. On a resolved edge `tier` is the P2A confidence — `high` for an
    import/qualified-name/framework binding, `medium` for a same-repo name match,
    `low` for a cross-repo one. On a cross-tier synthesized edge
    (`resolution/tier-synthesizer.ts`) `tier` is a DIRECTION: `client→server` /
    `server→client`. Both meanings are real and both are read: `src/context`,
    `src/mcp/tools` and the Steps view (`ui-server/api/steps.ts`) all branch on
    the direction spelling by that name, and `edge-repo-tier.test.ts` pins the
    confidence spelling. So the key cannot be reclaimed on either side without
    breaking the other, and a reader holding an arbitrary edge cannot tell which
    of the two it is looking at.
    `edgeTier` carries the same confidence value under a name that never means
    anything else. Purely additive: `tier` is emitted exactly as before, every
    existing reader is untouched, and the new key is what a consumer filters on.
    The REST edges in the next commit stamp `edgeTier` for the same reason — their
    `tier` is already spoken for by the direction.
    semenovale-cloud committed Sep 4, 2026
    Configuration menu
    Copy the full SHA
    c8c2525 View commit details
    Browse the repository at this point in the history
  2. feat: cross-repo REST edges — repo stamps, a confidence tier, SFC + F…

    …astify clients
    
    A user's project groups several repos, and the real coupling between them is
    an HTTP call on one side and a route handler on the other — neither side
    imports the other, so name resolution draws nothing. The `http-client` channel
    of the cross-tier synthesizer already pairs a literal client path with the
    `METHOD path` route node that serves it, and because it runs at RESOLVE time
    over the merged graph, it was already crossing repos. What it was missing is
    everything the per-project layer needs to USE such an edge.
    Repo stamps. `sourceRepo` / `targetRepo` come from `repoOfFilePath` — the same
    `file_path` first-segment derivation `db/repo-scope` scopes queries by, so an
    edge's stamps and the MCP session's boundary can never disagree. `crossRepo`
    marks the pair that spans two repos, which is the set this whole feature
    exists to surface.
    A confidence tier, under `edgeTier` (the previous commit's key; this edge's
    `tier` is already the direction). Never `high`: `high` is reserved for a
    resolver that PINS a declared target through a binding — an import, an FQN, a
    framework registry. An HTTP pairing has no binding. It is textual agreement
    between two strings written independently on either side of a wire, and it
    holds only as long as both stay written that way. `medium` when the client
    wrote the whole path from the root and it aligns with the route template
    segment for segment; `low` when only the TAIL matched because a base URL hid
    the front of the path (`${API}/users` against `GET /api/users`) — the hidden
    prefix could belong to another service entirely.
    Crossing a repo does NOT demote a REST edge, which is deliberately the
    opposite of the rule for a bare-name edge. There, two repos sharing a name is
    evidence of coincidence. Here, client and server in different repos is the
    NORMAL shape of the thing being detected; demoting for it would bury exactly
    the edges the pass is for. Precision is bought elsewhere and was already
    bought: a dynamic URL resolves to nothing, a method the route does not serve
    matches nothing, and a path two routes serve alike is dropped as a tie rather
    than guessed at.
    Two coverage gaps closed, both of which made the channel silent on the stacks
    this is for. `.vue` / `.svelte` / `.astro` files were not scanned at all, so a
    Vue or Svelte frontend produced no client→server edge however plainly it named
    the path — they are now read for the HTTP channel ONLY. The queue and event
    channels stay off for them on purpose: those read decorator, `new Worker(…)`
    and `.on(…)` shapes that an SFC's `<template>` does not contain, and widening
    them would change edges on graphs with no HTTP in them at all, which is the
    one regression this must not introduce. And the express extractor read only
    `app.` / `router.`, so Fastify's own `fastify.get('/x', handler)` declared no
    route node and had nothing to pair with; `fastify` is safe to add where
    `server` is not, because the synthesizer already lists `fastify` among the
    receivers that register routes and can never be a client (SERVER_NAMES) while
    `server` is on its CLIENT_NAMES list.
    `__tests__/http-cross-repo-edges.test.ts` is a fixture pair of repos — a
    frontend whose only link to the API is the path it calls, and an express/
    Fastify service declaring it. It pins the medium-tier whole-path pairing with
    both repo stamps, the low-tier tail match behind a base URL, that no REST edge
    is ever `high`, the two negatives (dynamic URL, method mismatch), the Vue SFC
    and Fastify cases, and two scope properties. Scope safety is not new code:
    `createScopedCodeGraph` drops an edge unless BOTH endpoints resolve to
    in-scope nodes, and a route node in an out-of-scope repo reads back as `null`
    like any other node — so the test asserts a REST edge leaving the scope is
    filtered identically to the cross-repo NAME edge beside it, through
    `getOutgoingEdges`, the batch `getOutgoingEdgesFrom` / `getIncomingEdgesTo`
    behind `codegraph_explore`, and from the server side too, while both repos in
    scope keeps the edge. The last test runs the real pipeline — extract each repo
    under its own root, merge the DBs through the app's explicit column lists,
    resolve over the merge — proving the route node arrives by row-copy and the
    pairing is made on the merged graph, not only when the repos are indexed
    together.
    semenovale-cloud committed Sep 4, 2026
    Configuration menu
    Copy the full SHA
    731bd36 View commit details
    Browse the repository at this point in the history

Commits on Sep 9, 2026

  1. Version

    semenovale-cloud committed Sep 9, 2026
    Configuration menu
    Copy the full SHA
    27e3007 View commit details
    Browse the repository at this point in the history

Commits on Oct 1, 2026

  1. feat: codegraph_node reads yaml/properties with secret values masked

    File mode returned only the key list for a config file and pointed to Read, which an agent with no filesystem tools does not have. It now serves the file with real line numbers; values of secret-named keys, URL passwords, opaque tokens and PEM blocks are replaced by <redacted>, flags and plain values stay visible. Explore and symbol mode keep withholding config source. Version 1.6.0-sesp-004.
    semenovale-cloud committed Oct 1, 2026
    Configuration menu
    Copy the full SHA
    e0ed83f View commit details
    Browse the repository at this point in the history
  2. feat: CODEGRAPH_TRUST_ROOT_LINKS — serve sources through repo links i…

    …n the project root
    
    A merged multi-repo project holds one symlink per repository pointing at its checkout outside the project dir, so every content read escaped the root and was refused (#527): codegraph_node file mode and explore served symbols only. With CODEGRAPH_TRUST_ROOT_LINKS=1 a symlink directly in the root is a source root; a path under it is served while its real path stays inside that link's target. Deeper links and links escaping a repo stay rejected. Version 1.6.0-sesp-005.
    semenovale-cloud committed Oct 1, 2026
    Configuration menu
    Copy the full SHA
    11fed02 View commit details
    Browse the repository at this point in the history
  3. fix: codegraph_node file mode stays under the host's inline result limit

    The file view was budgeted at 38K chars; Copilot CLI spills a larger tool result to a temp file the agent may not be allowed to read back, so a long file came back as a file path. The budget is now 19.5K (20K with the pagination note), like explore's ~25K hardCeiling; longer files paginate with offset/limit. Version 1.6.0-sesp-006.
    semenovale-cloud committed Oct 1, 2026
    Configuration menu
    Copy the full SHA
    aad413b View commit details
    Browse the repository at this point in the history
Loading