Commit Graph
100 Commits
Author SHA1 Message Date
Colby McHenryandClaude Opus 4.6 7e6914ddff feat: Always enable embeddings, remove enableEmbeddings config option
Testing showed semantic search produces significantly better results for
natural language queries that Claude writes. FTS alone often ranks
properties above their parent classes and misses conceptual matches.
Embeddings are now always on — the vector manager is created eagerly,
with model download and embedding generation still happening lazily.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-04-03 10:03:41 -05:00
Colby McHenry 8b5622d346 Remove Sentry telemetry system from CodeGraph
Eliminates anonymous error reporting functionality that was collecting stack traces and error context via Sentry. Removes all telemetry-related code, configuration options, and documentation references.
2026-04-03 09:54:07 -05:00
Colby McHenry 9bb8e96bd4 bump version to 0.6.6 2026-04-01 14:37:38 -05:00
Colby MchenryandGitHub 2de4d1fd4c Merge pull request #73 from colbymchenry/fix/cross-module-resolution
fix: Prevent false cross-module edges in name-based resolution
2026-04-01 14:30:21 -05:00
Colby McHenryandClaude Opus 4.6 584bd94ecc fix: Prevent false cross-module edges in name-based resolution
Name matching was creating false `calls` edges between unrelated modules
in monorepos because `findBestMatch()` had no concept of directory
proximity — functions with common names (e.g. `navigate`) in different
apps scored identically and resolved to whichever came first.

Adds path proximity scoring (shared directory segments) so same-module
candidates strongly win over cross-boundary ones, and lowers confidence
for distant matches so import-based resolution takes precedence.

Closes #67

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-04-01 14:23:13 -05:00
Colby MchenryandGitHub 960bed2253 Merge pull request #72 from colbymchenry/fix/telemetry-opt-out
fix: Add telemetry opt-out for Sentry error reporting
2026-04-01 14:15:08 -05:00
Colby McHenryandClaude Opus 4.6 5a185eb736 fix: Add telemetry opt-out via installer prompt and env var
Sentry error reporting can now be disabled by:
1. Declining during the interactive installer (sets CODEGRAPH_TELEMETRY=off
   in the MCP server config env)
2. Setting CODEGRAPH_TELEMETRY=off in your shell environment

README updated with a Telemetry section documenting what is collected
and how to opt out.

Closes #68

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-04-01 14:14:33 -05:00
Colby McHenry c401a96d17 Merge branch 'main' into fix/telemetry-opt-out 2026-04-01 14:12:28 -05:00
Colby MchenryandGitHub 61a9961bb8 Merge pull request #71 from colbymchenry/fix/installer-global-install-prompt
fix: Prompt before global npm install during installer
2026-04-01 14:12:08 -05:00
Colby McHenryandClaude Opus 4.6 12b0414900 fix: Prompt before global npm install during installer
The installer previously ran `npm install -g` silently without user
consent. Now it asks for confirmation first, explains why the global
install is needed (hooks & MCP server), and gracefully skips if declined.
README updated to document this step.

Closes #69

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-04-01 14:10:01 -05:00
Colby MchenryandGitHub 6647d1c827 Merge pull request #70 from colbymchenry/feat/improved-search-tokenization
feat: Improve search tokenization with camelCase splitting
2026-04-01 13:50:55 -05:00
Colby McHenryandClaude Opus 4.6 0756636bde feat: Improve search tokenization with camelCase splitting and code-aware stop words
extractSearchTerms now splits camelCase, PascalCase, snake_case, and
dot.notation into individual tokens (e.g. "getUserName" → ["user", "name"]).
Stop words expanded with code-specific noise words (code, file, function,
method, class, type, etc.) to improve search precision.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-04-01 13:50:12 -05:00
Colby McHenryandClaude Opus 4.6 8f5f88b813 refactor: Remove AI entry point guessing, use search-driven flow
AI picking the entry point was unreliable. Now:
- Type a symbol name → dropdown shows matches
- Click a result (or Enter to pick first) → traces its call graph depth 3
- The user picks the starting point, the graph does the rest deterministically

No more AI guesswork. Search + graph traversal = reliable flows.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-03-22 17:22:35 -05:00
Colby McHenryandClaude Opus 4.6 dcd4fa397e refactor: Simplify to entry-point + call graph tracing
Completely reworked the explore approach:
- Claude (or keyword search) finds ONE entry point, not a list of symbols
- getCallGraph(entry, depth=3) traces the actual call chain deterministically
- No more AI-guessed symbol lists, bridge passes, or relevance filtering
- Search result clicks also trace the full call graph from that point

The graph data was always accurate — the problem was AI trying to guess
the whole flow. Now AI just finds the starting point, graph does the rest.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-03-22 17:19:23 -05:00
Colby McHenryandClaude Opus 4.6 3d2b38918e refine: Tighten Claude prompt for focused 5-8 node execution paths
Stricter prompt rules: only symbols directly in the execution path,
every symbol must call or be called by the next, no tangential features.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-03-22 16:55:52 -05:00
Colby McHenryandClaude Opus 4.6 2278d3fd6f feat: Flow-oriented exploration with entry point identification
Update Claude prompt to identify the entry point and return symbols in
execution order. The graph now centers on the entry point and auto-opens
its detail panel, giving users a clear starting point to trace the flow.

- Claude returns {entry, flow} instead of flat array
- Entry point is auto-selected and centered on load
- Detail panel opens immediately for the entry point
- Prompt asks for max 8-10 symbols in execution order

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-03-22 16:52:10 -05:00
Colby McHenry 61d43fa26c Merge remote-tracking branch 'origin/main' 2026-03-22 16:50:10 -05:00
Colby McHenryandClaude Opus 4.6 c433e7d1a0 refactor: Trust Claude's seed picks, only add bridge nodes
Instead of expanding all callers/callees of seeds (which pulls in noise
from hub nodes like getSession), now:
1. Find direct edges between Claude's seeds
2. Only add non-seed nodes if they bridge 2+ isolated seeds
3. Cross-connection pass discovers hidden edges between result nodes
4. No more unrelated callers of hub nodes polluting the graph

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-03-22 16:48:55 -05:00
Colby McHenryandClaude Opus 4.6 ba30c74461 feat: Improve visualizer graph quality and UI
- Bridge pass: connect isolated seed nodes that share callees
- Kind labels on nodes (fn, class, comp, etc.) for quick identification
- Quick action buttons in detail panel (Expand Callees, Callers, Call Graph, Impact)
- Wider detail panel (460px) for better code readability
- Multiline node labels showing name + kind

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-03-22 16:46:09 -05:00
Colby McHenryandClaude Opus 4.6 43ea0a40ba feat: Add interactive graph visualization with Claude-powered exploration
Adds `codegraph visualize` command that launches a localhost web UI for
visually exploring code relationships. Users can ask natural language
questions like "how does authentication work?" and see the relevant code
flow rendered as an interactive graph.

Key components:
- Visualizer HTTP server (src/visualizer/server.ts) with REST API
- Single-page frontend with Cytoscape.js graph + highlight.js code preview
- Claude CLI integration for intelligent query interpretation
- Dark theme, right-click context menus, keyboard shortcuts
- Detail panel with source code, callers, callees, hierarchy

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-03-22 16:43:57 -05:00
Colby MchenryandGitHub 3729132b0d Merge pull request #49 from markhu/main
exclude .pio/ folder for Platform.io IoT libs
2026-03-18 22:55:54 -05:00
Colby McHenry 1f715cd6d9 chore: Bump version to 0.6.5 2026-03-18 17:10:59 -05:00
Colby McHenry 5334a0f023 feat: Add codegraph affected command to find test files impacted by changes
Traverses dependency graph to identify which test files depend on changed source files. Supports stdin input for git integration, custom test file patterns, and configurable traversal depth. Useful for targeted test execution in CI/CD pipelines.
2026-03-18 16:31:54 -05:00
Colby MchenryandGitHub d20021a322 Merge pull request #63 from colbymchenry/fix/stale-lock-mcp-retry
fix: Stale lock recovery and MCP init retry
2026-03-18 14:52:59 -05:00
Colby McHenry 3ec4cde542 chore: Reduce stale lock timeout from 10 minutes to 2 minutes 2026-03-18 14:52:20 -05:00
Colby McHenry b964d5909a fix: Stale lock recovery and MCP init retry
Fixes #47 — "database is locked" after crash and MCP "not initialized"
when project IS initialized.

- FileLock: treat locks older than 10 minutes as stale regardless of PID
  status, covering cases where PID was reused or kill signal check fails
- MCP server: log errors from tryInitializeDefault() to stderr instead of
  silently swallowing, so transient open failures are diagnosable
- MCP server: retryInitIfNeeded() properly cleans up failed instances
  before retrying, preventing resource leaks
- CLI: add 'codegraph unlock' command for manual lock file removal
2026-03-18 14:50:25 -05:00
Colby MchenryandGitHub bdbe59b457 Merge pull request #62 from colbymchenry/fix/fk-constraint-empty-names
fix: Prevent FK constraint failure from nodes with empty names
2026-03-18 14:36:16 -05:00
Colby MchenryandGitHub 3ffcac781e Merge pull request #61 from colbymchenry/fix/wasm-oom-lazy-grammars
fix: Lazy grammar loading to prevent V8 WASM OOM on large codebases
2026-03-18 14:36:04 -05:00
Colby McHenry 92631d53d3 fix: Prevent FK constraint failure from nodes with empty names
Fixes #42 — tree-sitter can produce nodes with empty names (e.g. from
complex C/C++ declarators in header files). These nodes were silently
skipped at DB insert time, but their containment edges were still
inserted, causing a FOREIGN KEY constraint violation that crashed
indexing.

Two-layer fix:
- createNode() now returns null for empty names, preventing the node
  and its edges from ever being created (Option A)
- storeExtractionResult() filters edges and unresolved refs to only
  reference nodes that passed validation, as a safety net (Option B)
2026-03-18 14:34:25 -05:00
Colby McHenry 15b5e56322 fix: Lazy grammar loading and quantized embeddings to prevent V8 WASM OOM
Fixes #54 — `codegraph init -i` crashes with "Fatal process out of memory: Zone"
on large codebases because all 16 tree-sitter WASM grammar modules were compiled
upfront by V8, exhausting the WASM Zone allocator.

Changes:
- initGrammars() now only initializes the tree-sitter WASM runtime (Parser.init()),
  no longer eagerly loads all grammar files
- New loadGrammarsForLanguages() loads only grammars for languages actually present
  in the project (e.g. a Dart project loads ~2-3 grammars instead of 16)
- Orchestrator detects needed languages after file scan, before parsing begins
- Embedding pipeline now uses quantized model (~67MB vs ~270MB) to further reduce
  WASM memory pressure when embeddings are enabled
2026-03-18 14:21:54 -05:00
Colby MchenryandGitHub 16db37566d Merge pull request #46 from colbymchenry/fix/serve-stdout-mcp-protocol
fix: Write serve banner to stderr, not stdout
2026-02-20 11:27:31 -06:00
Colby McHenry 7442b27002 fix: Write serve command banner to stderr instead of stdout
The serve command without --mcp prints a help banner. Writing this to
stdout breaks MCP stdio clients (like Cursor) that expect only JSON-RPC
on stdout. Move all banner output to stderr so stdout stays clean.

Fixes #43
2026-02-19 16:02:52 -06:00
Colby MchenryandGitHub 7f516b9308 Merge pull request #45 from colbymchenry/fix/silent-failed-install
fix: Stop silent install failures — always run npm install -g, add preuninstall cleanup
2026-02-19 15:58:51 -06:00
Colby McHenry dff98a638c Bumps version to 0.6.2
Bumps version to 0.6.2 in both package.json and lockfile to align release metadata and prevent silent install failures on fresh installs.
Relates to silent install fix
2026-02-19 15:57:01 -06:00
Colby McHenry a46d6b7487 fix: Always run npm install -g, skip command -v check
command -v codegraph is unreliable inside npx because npx puts a
temporary binary in PATH. The check always passes, so the global
install is always skipped — which is the root cause of #37 and #38.

Fix: remove the check entirely, always run npm install -g.
2026-02-19 15:51:03 -06:00
Colby McHenry 67f60b9b2f fix: Use bare codegraph everywhere, add preuninstall cleanup
- Revert configs (MCP, hooks) to use bare `codegraph` command
- Remove all npx references from configs and messaging
- Add preuninstall script that runs on `npm uninstall -g` to clean up
  MCP server, permissions, hooks, and CLAUDE.md section
- Show uninstall instructions in post-install next steps
2026-02-19 15:46:34 -06:00
Colby McHenry 88e1f2df7f fix: Bring back global install attempt with loud failure messaging
Global install is still attempted for bare `codegraph` convenience,
but now verifies the command is actually in PATH after install. If it
fails, users get clear actionable messages instead of silent swallowing.

Configs (MCP server, hooks) always use npx regardless — those never
break even if global install fails.
2026-02-19 15:38:59 -06:00
Colby McHenry 675aab386a fix: Always use npx — stop silent global install failures
Remove the npm install -g attempt from the installer that silently
fails on many systems (permissions, PATH, node version managers).
All configs (MCP server, hooks, next-steps) now always use
npx @colbymchenry/codegraph. Global install offered as an optional tip.

Fixes #37, #38
2026-02-19 15:28:56 -06:00
Colby MchenryandGitHub 3be779f6f6 Merge pull request #41 from omonien/delphi-support
feat: Add Pascal/Delphi support (Tree-sitter & DFM extraction)
2026-02-19 15:00:05 -06:00
Colby MchenryandGitHub 544d193086 Merge branch 'main' into delphi-support 2026-02-19 14:59:53 -06:00
Colby MchenryandGitHub 5d699ab2c5 Merge pull request #40 from ravescovi/fix/sequential-grammar-loading
fix: load WASM grammars sequentially to avoid Node 20+ race condition
2026-02-19 14:52:05 -06:00
Colby McHenry a9148e674e Fix git issue 2026-02-14 02:14:48 -06:00
Colby McHenry 8346440592 Add WASM fallbacks for tree-sitter and SQLite, fix installer
Replace native tree-sitter with web-tree-sitter + tree-sitter-wasms for
universal cross-platform support. Add node-sqlite3-wasm as a fallback
when better-sqlite3 native bindings aren't available. Move better-sqlite3
and sqlite-vss to optionalDependencies so installs never fail.

Fix installer to use npx fallback when global npm install fails, so MCP
config, hooks, and quick-start instructions all work without the bare
codegraph command in PATH.

Fix tests: update schema version expectation, fix db test paths and
method names, extract MAX_OUTPUT_LENGTH as module constant, normalize
Windows path separators in import resolver.
2026-02-14 00:56:15 -06:00
Colby McHenry 429359c25f version bump 2026-02-11 16:12:45 -06:00
Colby McHenry ce504c642a Fix performance issues. 2026-02-11 16:11:50 -06:00
Colby McHenry a7fc5853a2 Exit child processes on windows 2026-02-11 15:15:42 -06:00
Colby McHenry eee081e2a7 detached process 2026-02-11 02:58:59 -06:00
Colby McHenry 09a8d24bd8 version bump 2026-02-10 18:18:51 -06:00
Colby McHenry 4c7827675a Auto stash before merge of "main" and "origin/main" 2026-02-10 18:16:06 -06:00
Colby MchenryandGitHub 7239a6f7d3 Merge pull request #29 from colbymchenry/optimize-reference-resolution
Optimize reference resolution with in-memory caches
2026-02-10 18:15:36 -06:00
Colby McHenry acd9713632 Optimize reference resolution with in-memory caches
The resolving refs phase stalled on large projects (3400+ files, 38k+ nodes)
because matchFuzzy loaded ALL functions/methods/classes per ref, import
mappings were re-extracted per ref, and fileExists hit disk every call.

Add kindCache, lowerNameCache, importMappingCache, and knownFiles set to
warmCaches(). Rewrite matchFuzzy to use O(1) lowercase index lookup instead
of 3x getNodesByKind scans. Cache import mappings per file. Pre-build file
existence set from the index for O(1) fileExists checks.
2026-02-10 18:14:26 -06:00
Colby McHenry df937ceca1 Add site-packages and dist-packages to default exclude patterns
Fixes #28 - Python site-packages directories (e.g.
audio_tools/python/Lib/site-packages/) were not excluded by default,
causing massive index bloat and FOREIGN KEY failures when indexing
large libraries like tensorflow. The FK crash itself was already fixed
via INSERT OR IGNORE, but excluding these directories prevents the
bloat in the first place.
2026-02-10 16:47:13 -06:00
Colby MchenryandGitHub adaff67219 Merge pull request #25 from MO2k4/feat/db-performance-schema-v2
feat: Schema v2 migration + database performance
2026-02-10 16:36:21 -06:00
Colby McHenry 1c023c41cc Remove unused batch methods, dynamic stmt cache, and intent field
- Remove getNodesByIds, getNodesByKinds (zero callers)
- Remove getFileHashMap, getFileSyncMap (zero callers)
- Remove getDynamicStmt cache (only used by removed batch methods)
- Revert getStaleFiles to simple implementation (zero callers, no need to optimize)
- Remove intent field from SearchOptions (never read in search logic)
2026-02-10 16:34:13 -06:00
Colby MchenryandGitHub 04e1f3e122 Merge pull request #24 from MO2k4/security/path-validation-redos
security: Path validation, ReDoS prevention, picomatch
2026-02-10 16:22:39 -06:00
Colby McHenry 98034cc76e Resolve merge conflicts with main
- extraction/index.ts: use picomatch with static import (replacing
  dynamic require) and keep normalizePath for other call sites
- utils.ts: keep normalizePath from main, take PR's PID-based FileLock
2026-02-10 16:21:23 -06:00
Colby MchenryandGitHub e6531c50c0 Merge pull request #26 from MO2k4/feat/search-query-utils
feat: Search query utilities + multi-signal scoring
2026-02-10 16:14:12 -06:00
Colby McHenry a15ad69288 Remove unused detectApiIntent and inferRouteDirectories
Both functions have zero callers — dead code on arrival. Remove them
and their tests (9 tests) to keep the module focused on what's
actually used: search term extraction, path relevance scoring, and
kind bonuses.
2026-02-10 16:05:46 -06:00
Colby MchenryandGitHub e2a95ee9ab Merge pull request #27 from MO2k4/feat/extraction-quality
feat: File nodes, arrow functions, parallel I/O
2026-02-10 16:00:23 -06:00
Colby McHenry 36af284e10 Remove redundant code and deduplicate indexFile
- Remove extractFunctionVariable() and its dispatch (already handled by extractVariable)
- Remove dead getGrammar() export (zero callers)
- Deduplicate indexFile by delegating to indexFileWithContent
- Remove redundant arrow function variable extraction tests (covered by existing suite)
2026-02-10 15:55:43 -06:00
Colby McHenry ce220a573c Resolve merge conflict with main (gitignore + symlink rename)
Keeps the PR's visitedDirs rename and main's gitIgnoredDirs addition.
2026-02-10 15:44:56 -06:00
Colby McHenryandClaude Opus 4.6 62a6cf38fe Fix .gitignore support and Windows path separator bug in scanner
Normalize paths to forward slashes in matchesGlob() and scanDirectory()
so glob exclude patterns work on Windows. Add getGitIgnoredDirectories()
using git ls-files to skip .gitignore'd directories during indexing.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-02-10 04:08:10 -06:00
Colby McHenry 4825661e02 upgrade 2026-02-10 03:49:06 -06:00
Colby McHenryandClaude Opus 4.6 75e9bfca04 Downgrade tree-sitter to 0.21.1 to eliminate all peer dependency warnings
All grammar packages now have compatible peer deps with tree-sitter 0.21.x,
resulting in zero warnings during npm install. Downgraded grammars:
c 0.24.1→0.23.2, php 0.24.2→0.23.11, python 0.23.6→0.23.4,
rust 0.24.0→0.23.1, swift 0.7.1→0.6.0.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-02-10 03:07:39 -06:00
Colby McHenryandClaude Opus 4.6 a4c1d32160 Upgrade tree-sitter-c, php, and rust to versions compatible with tree-sitter 0.22.4
Reduces peer dependency warnings during install by upgrading grammars that
have newer versions accepting ^0.22.x: c 0.23.4→0.24.1, php 0.23.11→0.24.2,
rust 0.23.2→0.24.0. Python 0.23.6 and swift 0.7.1 already compatible.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-02-10 03:01:59 -06:00
Colby McHenryandClaude Opus 4.6 9a122b041b Move tree-sitter grammars to optionalDependencies for Windows compatibility
tree-sitter-kotlin doesn't ship prebuilt binaries for win32-x64, causing
npm install to fail on Windows without Visual Studio. All grammars are now
optional since the runtime already handles missing parsers gracefully.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-02-10 02:51:32 -06:00
Colby McHenryandClaude Opus 4.6 7fe2973e73 Move platform badges to separate row in README
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-02-10 02:29:41 -06:00
Colby McHenry 834ae663e9 readme update 2026-02-10 02:28:26 -06:00
Colby McHenry f5746981bd Merge branch 'svelte-support' 2026-02-10 02:26:54 -06:00
Colby McHenry 2ad03d2f7d updates 2026-02-10 02:26:47 -06:00
Colby MchenryandGitHub 9f431c859b Merge pull request #23 from colbymchenry/svelte-support
Add Svelte language support
2026-02-10 01:38:26 -06:00
Colby McHenryandClaude Opus 4.6 4c983ba082 Add Svelte language support with SvelteKit framework resolver
- Add 'svelte' to Language type, DEFAULT_CONFIG includes, grammars, and config validation
- Add SvelteExtractor that extracts <script> blocks and delegates to TS/JS TreeSitterExtractor
- Add Svelte framework resolver for runes ($state, $derived, $effect, etc.), store auto-subscriptions, SvelteKit module aliases ($app/*, $env/*, $lib/*), and SvelteKit route detection
- Update README to list Svelte and Dart in supported languages

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-02-10 01:32:52 -06:00
Colby MchenryandGitHub c034c50689 Merge pull request #22 from colbymchenry/claude-hooks
Add Claude Code hooks for automatic CodeGraph sync
2026-02-10 01:15:53 -06:00
Colby McHenryandClaude Opus 4.6 f46ba02b87 Add Claude Code hooks for automatic CodeGraph sync
PostToolUse(Edit|Write) marks the project dirty via .codegraph/.dirty,
and Stop syncs only if dirty — batching all edits into one sync per
Claude response. The installer now writes these hooks to settings.json.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-02-10 01:12:43 -06:00
Colby MchenryandGitHub 48cc3a8b66 Merge pull request #21 from colbymchenry/fix/unique-constraint-collision
Fix UNIQUE constraint crash on large C/C++ projects
2026-02-10 00:43:37 -06:00
Colby McHenryandClaude Opus 4.6 c3cf891bf4 Fix UNIQUE constraint crash on large C/C++ projects
Node insertion used plain INSERT which crashes on duplicate IDs.
In large C/C++ projects, tree-sitter can produce duplicate nodes for
the same symbol (e.g. typedef struct where both struct_specifier and
type_definition resolve to the same name/kind/line, or multiple
anonymous constructs on the same line).

- Change nodes INSERT to INSERT OR REPLACE (idempotent, same data)
- Change edges INSERT to INSERT OR IGNORE (skip duplicate edges)

The node ID is sha256(filePath:kind:name:line) which already uses full
relative paths, so cross-directory collisions are not the issue.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-02-10 00:40:18 -06:00
Colby McHenryandClaude Opus 4.6 f03524f1c8 Move sqlite-vss to optionalDependencies, remove tree-sitter-liquid
sqlite-vss fails to compile on Windows — moving it to optional lets
install succeed while the code already falls back to brute-force
vector search. tree-sitter-liquid is removed entirely as it has ABI
incompatibility with tree-sitter 0.22+ and Liquid is handled by the
built-in regex extractor.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-02-10 00:36:56 -06:00
Colby McHenry d3ba9868df WIP on security-hardening 2026-02-10 00:29:22 -06:00
Colby MchenryandGitHub 5e2d3d6d75 Merge pull request #20 from colbymchenry/pr-19
Port quality improvements from PR #15
2026-02-10 00:23:02 -06:00
Colby McHenryandClaude Opus 4.6 c8c7785626 Add tests for PR #19 improvements (Phases 3-5)
Covers arrow function extraction, best-candidate resolution, graph
traversal direction fix, MCP symbol disambiguation, output truncation,
CLI uninit command, and more. Tests requiring better-sqlite3 native
bindings are conditionally skipped.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-02-10 00:19:48 -06:00
Colby McHenryandClaude Opus 4.6 ab5f9a03ef Improve MCP tool symbol disambiguation and output truncation
- Add findSymbol() helper that prefers exact name matches and notes
  alternatives when multiple symbols share the same name
- Add output truncation (15K char cap) to prevent context window bloat
- Apply to callers, callees, impact, node, search, and files tools

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-02-10 00:05:56 -06:00
Colby McHenryandClaude Opus 4.6 9ea4be3c24 Add CLI uninit command to remove CodeGraph from a project
Exposes the existing uninitialize() method via `codegraph uninit [path]`.
Includes confirmation prompt (skippable with --force) before deleting
the .codegraph/ directory.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-02-10 00:02:52 -06:00
Colby McHenryandClaude Opus 4.6 94c8d5ccaa Port extraction quality improvements from PR #15
- Fix arrow function extraction: explicitly call extractFunction() for
  arrow functions/function expressions in variable declarations instead
  of silently skipping them (all 6 arrow function tests now pass)
- Best-candidate resolution: collect candidates from all strategies and
  return highest confidence match instead of first match
- Fix graph traversal 'both' direction: correctly determine next node
  for mixed incoming/outgoing edges in BFS and DFS

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-02-09 23:55:00 -06:00
Colby McHenryandClaude Opus 4.6 d80900f653 Port performance improvements from PR #15
- SQLite performance pragmas: synchronous=NORMAL, 64MB cache,
  memory temp store, 256MB mmap (safe with WAL mode)
- Batch insert for unresolved refs: single transaction instead of
  N individual inserts per file
- Symbol caching (warmCaches): pre-load all nodes into memory maps
  before resolution, eliminating repeated SQLite queries per ref
- Async file I/O: fs.stat/readFile in indexFile() are now non-blocking
- Denormalize filePath/language onto UnresolvedReference: avoids N
  node lookups during resolution, with schema migration v2

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-02-09 23:45:34 -06:00
Colby McHenryandClaude Opus 4.6 e07250ed60 Port bug fixes and stability improvements from PR #15
- Fix Float32Array embedder bug: was creating zero-filled array instead
  of copying data from TypedArray-like objects
- Fix VSS search query: use subquery pattern so LIMIT applies before JOIN
- Pin tree-sitter versions: remove caret ranges for ABI stability, add
  overrides to lock tree-sitter core at 0.22.4
- Lazy grammar loading: load native bindings on first use per language
  instead of all at startup, so one missing grammar doesn't affect others
- Remove stale src/extraction/queries copy from copy-assets script

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-02-09 23:40:37 -06:00
Colby MchenryandGitHub 082513b566 Merge pull request #19 from colbymchenry/security-hardening
Security hardening: path validation, input clamping, safe JSON, file locking
2026-02-09 23:25:04 -06:00
Colby McHenryandClaude Opus 4.6 41c49ce83d Add security hardening test suite (28 tests)
Tests cover all security utilities introduced in the previous commit:
- validatePathWithinRoot: path traversal prevention (7 tests)
- safeJsonParse: corrupted JSON fallback handling (6 tests)
- clamp: input range clamping (5 tests)
- FileLock: cross-process file locking (7 tests)
- Atomic config writes: temp file + rename pattern (3 tests)

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-02-09 23:21:36 -06:00
Colby McHenryandClaude Opus 4.6 932c567d18 Security hardening: path validation, input clamping, safe JSON, file locking
Implements security improvements inspired by PR #16 (credit: MO2k4):

- Add validatePathWithinRoot() to prevent path traversal attacks in
  extraction and context building
- Clamp MCP tool inputs (limit, depth, maxDepth) to sane ranges
- Use atomic writes (temp file + rename) for config saves
- Add symlink cycle detection in directory scanning to prevent infinite loops
- Replace all JSON.parse calls in db/queries.ts with safeJsonParse fallbacks
  to handle corrupted database metadata gracefully
- Add cross-process FileLock for DB write operations (indexAll, indexFiles,
  sync) to prevent concurrent writes from CLI, MCP server, and git hooks
- Remove unused path import from context/index.ts

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-02-09 23:18:40 -06:00
Colby McHenryandClaude Opus 4.6 38fac1ff28 Merge PR #18: Fix arrow function/export indexing + type alias extraction
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-02-09 22:36:26 -06:00
Colby McHenry d0ee6f7fc4 Enhances code extraction and project indexing
Adds support for Dart and Liquid languages with tree-sitter parsing.
Improves accuracy of code symbol extraction for existing languages.
Indexes project files to enhance code navigation features.
Migrates build system to facilitate code contributions.
Removes git hook functionality.
Integrates Sentry for error tracking and reporting.
Enhances project initialization and configuration loading.
2026-02-09 22:18:59 -06:00
Colby McHenryandClaude Opus 4.5 f0ddfccf47 Skip global install if codegraph command already exists
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
2026-01-21 13:40:29 -06:00
Colby McHenryandClaude Opus 4.5 553f623fe1 Bump version to 0.3.0
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
2026-01-21 13:30:08 -06:00
Colby McHenryandClaude Opus 4.5 3ad4d5b35d Download embedding model to ~/.codegraph/models on install
The nomic-ai model is now downloaded during npm install via a postinstall
script and stored globally in ~/.codegraph/models (shared across projects)
instead of per-project in .codegraph/models.

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
2026-01-21 13:29:03 -06:00
Colby McHenryandClaude Opus 4.5 3c2022375a Bump version to 0.2.9 and update npm description
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
2026-01-20 15:03:55 -06:00
Colby McHenryandClaude Opus 4.5 14c0d5ae88 Include README.md in npm package
- Add README.md to files array so it appears on npmjs.com
- Bump version to 0.2.8

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
2026-01-20 03:23:40 -06:00
Colby McHenryandClaude Opus 4.5 214ea0dbb0 Update README to clarify installer auto-configures CLAUDE.md
- Add note that installer updates ~/.claude/CLAUDE.md in Quick Start
- Rename "Recommended: Add Global Instructions" to "Global Instructions Reference"
- Clarify that instructions are added automatically, shown for reference
- Bump version to 0.2.7

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
2026-01-20 03:21:15 -06:00
Colby McHenry 4308a96079 MIT license 2026-01-20 02:17:42 -06:00
Colby McHenryandClaude Opus 4.5 47af81aee7 Remove codegraph_explore tool in favor of native Explore agents
The hybrid approach (Claude's native Explore agents using codegraph tools)
is more effective than a custom explore tool because Explore agents already
know what format the main session needs.

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
2026-01-19 21:14:52 -06:00
Colby McHenryandClaude Opus 4.5 a4ddedb197 Add Liquid template language support for Shopify themes
- Add 'liquid' to Language type and default include patterns
- Create LiquidExtractor with regex-based extraction (tree-sitter-liquid has ABI issues)
- Extract render/include/section references as component nodes
- Extract schema blocks as constant nodes with parsed names
- Extract assign statements as variable nodes
- Create file relationship edges for snippet/section references

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
2026-01-19 15:59:40 -06:00
Colby McHenryandClaude Opus 4.5 8d1fb680e5 Installer now creates/updates CLAUDE.md with CodeGraph instructions
- Added claude-md-template.ts with the instructions template
- Installer writes to ~/.claude/CLAUDE.md (global) or ./.claude/CLAUDE.md (local)
- Smart detection: updates existing CodeGraph section or appends if not found
- Uses HTML comment markers for reliable section replacement on upgrades

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
2026-01-19 15:30:13 -06:00