Safi
d23ae1774d
v2: hypergraph support - hyperedges in graph.json, shaded regions in HTML, report section
2026-04-05 23:18:25 +01:00
Safi
0f11f6a32d
v2: confidence scores on INFERRED edges, avg shown in report
2026-04-05 23:06:07 +01:00
Safi
a1be5abb24
refactor: dead imports, node_community helper, split to_html and call_tool
...
- Remove unused shutil (cache.py), sys (ingest.py), inline import os (detect.py)
- Extract _node_community_map() helper - was copy-pasted 8 times across analyze.py + export.py
- Split to_html() 285-line monolith into _html_styles() + _html_script() + thin orchestrator
- Split serve.py call_tool() if/elif chain into per-tool handler functions + dispatch table
- Extract _find_node() helper shared across get_node and get_neighbors handlers
All 231 tests pass.
2026-04-05 14:01:55 +01:00
Safi
8708333484
feat: vis.js HTML graph, token reduction benchmark, repo cleanup
...
- Replace pyvis with custom vis.js renderer: node size by degree,
click-to-inspect panel with clickable neighbors, search box,
community filter, physics clustering by community
- HTML graph generated by default on every run (no --html flag needed)
- Token reduction benchmark auto-runs after every /graphify on corpora >5k words
- Fix 292 edge warnings: silently skip stdlib/external edges in build.py
- Fix build() to merge extractions before building (cross-extraction edges were dropped)
- Add 5 HTML renderer tests (223 total)
- Remove unnecessary files: lib/, tests/eval_attention.py, misplaced eval reports
- Add graphify-out/ and .graphify_*.json to .gitignore
- Bump version to 0.1.4, remove pyvis dependency
- README: token reduction as top-level selling point, vis.js in tech stack,
graph.html in output listing, correct test count and install command
2026-04-05 00:20:56 +01:00
Safi
a7d1969f02
docs: update surprising connections description, test count
...
style: replace all em dashes with hyphens
fix: explain hidden .graphify/ folder in skill output and README
fix: rename .graphify/ to graphify-out/ so output is visible by default
2026-04-05 00:20:56 +01:00
Safi
a7f910667d
feat: GraphML export (--graphml flag) for Gephi and yEd
2026-04-05 00:20:56 +01:00
Safi
41e4e3576a
security: SSRF protection, HTML escaping, path guards, encoding hardening
...
- graphify/security.py (new): centralised security module
- validate_url(): blocks file://, ftp://, data:, any non-http/https scheme
- _NoFileRedirectHandler: re-validates redirect targets, blocks file:// redirects
- safe_fetch(): streams response, 50MB hard cap, non-2xx raises, timeout
- safe_fetch_text(): safe_fetch + UTF-8 decode with errors=replace
- validate_graph_path(): resolves path, requires inside .graphify/, base must exist
- sanitize_label(): strip control chars, cap 256, html.escape() — mirrors
code-review-graph's _sanitize_name pattern
- graphify/ingest.py: _fetch_html() and _download_binary() now use safe_fetch*;
ingest() validates URL scheme and wraps network calls in try/except;
YAML frontmatter: newlines stripped from question before embedding
- graphify/extract.py: all 33 bare .decode() → .decode("utf-8", errors="replace")
— non-UTF-8 source files degrade gracefully instead of crashing extraction
- graphify/export.py: sanitize_label() on all node labels and edge titles
before pyvis embeds them in HTML output
- graphify/serve.py: _load_graph() validates graph_path via validate_graph_path()
and wraps JSONDecodeError with recovery message; sanitize_label() on MCP
text output
- graphify/detect.py: os.walk(..., followlinks=False) made explicit
- SECURITY.md (new): threat model, mitigations table, reporting process
- tests/test_security.py (new): 20 tests covering all security.py functions
2026-04-04 18:56:38 +01:00
Safi
e7a03a0539
feat: cache, multi-language extraction, MCP, memory feedback
...
call-graph INFERRED edges, multi-language semantic extraction, SHA256 cache,
MCP stdio server with shortest_path, Q&A memory feedback loop
2026-04-04 18:56:38 +01:00
Safi
ce47198be1
feat: Claude Code skill, Obsidian vault, install, tests
...
skill.md with full pipeline steps, Obsidian as default output (canvas, tags,
dataview, graph colors), two-command install, 71 tests, .gitignore, deps
2026-04-04 18:53:43 +01:00