Graphify-Labs/graphify
48.8
Weak · 26 September 2026
136.6k
lines of production code
Python
primary language
4
measurements over time
What this system is
This system is a code analysis tool that converts source code and documents into knowledge graphs by extracting structural relationships across a wide variety of programming languages. It processes input files to build network graphs, detects community structures, and exports the resulting data to visual HTML reports or graph databases like Neo4j. The project provides modular extractors, regression tests for multi-language support, and worked examples to demonstrate its graphing and querying capabilities.
Features
Add .dockerignore and .gitattributes to improve repository hygiene
The repository now includes a .dockerignore file to exclude development artifacts, caches, and documentation from Docker build contexts, and a .gitattributes file to prevent generated HTML files from skewing the repository's primary language detection on GitHub.
(repo-wide) · high confidence
Added script to generate animated README demo SVG
A new Python script (scripts/gen\_demo\_path.py) generates an animated SVG (docs/demo-path.svg) for the README, visualizing a 'path lights up' demo where a terminal command triggers a graph traversal animation using the brand palette.
scripts · high confidence
Added skillgen expected output files for graphify agent skills
Added expected markdown files for the graphify skill across multiple agent platforms (agents, antigravity, claude, gemini, kiro, vscode, aider, amp, claw). These files define the instructions and usage patterns for the graphify tool, which converts codebases into knowledge graphs. The files include usage instructions, step-by-step guides for installation, file detection, extraction, and querying, as well as platform-specific configurations and rules for using the graphify tool.
tools · high confidence
New worked examples for document pipeline and httpx-like codebases
Added two new reproducible worked examples in the \worked/\ directory to demonstrate the tool's graphing capabilities. The \worked/example/\ example provides a small, self-contained document ingestion and search pipeline (parser, validator, processor, storage, and API modules) with architecture notes, allowing users to trace call relationships and community structures in a linear, multi-module system. The \worked/httpx/\ example provides a synthetic 6-file Python codebase modeled after the httpx HTTP library, featuring a clean layering of exceptions, models, authentication, transport, and client classes, complete with a generated graph report (\GRAPH\_REPORT.md\) and evaluation review (\review.md\) to showcase node/edge extraction, community detection, and surprising connection identification.
worked · high confidence
Removals
Removal of the graphify Python package
The entire \src/graphify\ module has been removed, deleting all associated source files including the core pipeline components (\analyzer\, \ast\_extractor\, \detector\, \exporter\, \graph\_builder\, \models\, \reporter\, \visualizer\) and the package initialization file. This eliminates the library's capability to extract knowledge graphs from code and documents, detect file types, build network graphs, and generate reports or visualizations.
src/graphify · high confidence
Architecture
Language extractors migrated to a modular package structure
The monolithic \graphify/extract.py\ is being split into a new \graphify/extractors\ package, with individual modules created for each supported language (e.g., \bash.py\, \csharp.py\, \cobol.py\). This change introduces a registry (\LANGUAGE\_EXTRACTORS\) and a shared base module (\base.py\) containing common utilities like \\_make\_id\ and \\_file\_stem\. The migration follows a strict 'verbatim move' policy to ensure behavior preservation, with \extract.py\ acting as a facade that re-exports the moved functions so existing importers remain unchanged. A \MIGRATION.md\ guide is provided for porting remaining languages, noting that config-driven extractors (like Python and JavaScript) must be moved as a batch due to shared core dependencies.
graphify/extractors · high confidence
Fixes
Fix graph.html export for large graphs
Resolves a crash or failure when exporting the visualization for large code graphs, ensuring the graph.html output is generated correctly regardless of graph size.
graphify · high confidence
Refactor exporters into modular package and fix HTML export stability and security
The graphify exporters have been reorganized from a single module into a dedicated package (graphify/exporters) with separate modules for base logic, HTML, and graph database exports. This change includes critical fixes for the HTML export: it now prevents vis-network stack overflow crashes on large graphs by seeding node positions, resolves stored XSS vulnerabilities in tooltips and labels via proper HTML entity encoding, and fixes broken neighbor links and hyperedge perimeter rendering. Additionally, a new exporter has been added to push graph data directly to Neo4j and FalkorDB instances.
graphify/exporters · high confidence
Test coverage
Add regression tests for the no\_cluster path replace fallback; Added test fixtures for cross-crate edge inference validation; Expanded test fixtures for multi-language extraction and structural analysis.
Dependencies
Migrate to pyproject.toml and update dependency constraints
The project has migrated its build configuration from requirements.txt to pyproject.toml, establishing a modern dependency structure with a version floor of 0.9.68. This change introduces a comprehensive suite of tree-sitter language extractors (including Python, JavaScript, TypeScript, Go, Rust, Java, C/C++, Ruby, C\#, Kotlin, Scala, PHP, Swift, Lua, Zig, PowerShell, Elixir, ObjC, Julia, Verilog, Fortran, Bash, and JSON) as core dependencies, alongside networkx, numpy, and rapidfuzz. It also defines optional extras for various backends (MCP, Neo4j, FalkorDB, PDF, video, LLM providers) and graph algorithms. The migration includes tightening version constraints for key libraries, such as capping starlette below version 2 to maintain dual-compatibility with the MCP SDK, and raising the floor for pillow to 12.3.0 to address [CVE redacted]. The legacy requirements.txt file has been removed.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.
Score
- CAI 41 → 49 (+7.7)
- Rubric changed (rubric-2026.08.15 → rubric-2026.09.15) — scores are not directly comparable.
Lenses
- Code Health 96 → 73 (-22.2)
- Architecture 38 (new)
- Maturity 70 → 59 (-10.7)
- Readiness 15 → 58 (+43.0)
- Security 56 → 80 (+24.4)
- Accessibility 52 (new)
Resolved (34)
- Analyzed solution does not cover the bulk of the repository
- Coverage not measured — test suite did not build
- Disclosure policy has no reporting contact
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- LLM evaluation failed
- Medium: security finding (details withheld)
- Medium: security finding (details withheld)
- Medium: security finding (details withheld)
- …and 14 more
New (798)
- Coverage not measured — no coverage collector is wired up
- Critical CVE: [GHSA redacted] (uv.lock)
- CsharpNameResolver.init (cognitive 29) (graphify/extractors/csharp.py)
- CsharpNameResolver.init (cyclomatic 19) (graphify/extractors/csharp.py)
- Dependency advisory scan runs only on code events
- Dependency hygiene PARTLY measured — Python dependencies read, no exact pin to grade for currency
- Documentation: no architecture or design documentation (docs/translations/README.zh-CN.md)
- Documentation: no usage examples (README.md)
- Duplicated block (10 lines × 2) (graphify/analyze.py)
- Duplicated block (10 lines × 2) (graphify/cache.py)
- Duplicated block (10 lines × 2) (graphify/cluster.py)
- Duplicated block (10 lines × 2) (graphify/exporters/graphdb.py)
- Duplicated block (10 lines × 2) (graphify/extract.py)
- Duplicated block (10 lines × 2) (graphify/extract.py)
- Duplicated block (10 lines × 2) (graphify/extractors/apex.py)
- Duplicated block (10 lines × 2) (graphify/extractors/dm.py)
- Duplicated block (10 lines × 2) (graphify/extractors/erlang.py)
- Duplicated block (10 lines × 2) (graphify/install.py)
- Duplicated block (10 lines × 2) (graphify/symbol_resolution.py)
- Duplicated block (10 lines × 3) (graphify/cli.py)
- …and 778 more
Changes since last survey
- 300 commits — 135 feature/other, 165 fixes
By area
- graphify/extractors — 63 commits
- (root) — 42 commits
- graphify/extract.py — 31 commits
- graphify/build.py — 11 commits
- graphify/watch.py — 11 commits
- graphify/cli.py — 10 commits
- graphify/dedup.py — 8 commits
- graphify/cache.py — 7 commits
- graphify/hooks.py — 7 commits
- graphify/install.py — 5 commits
- graphify/paths.py — 5 commits
- graphify/serve.py — 5 commits
- tests/test_js_destructured_export.py — 5 commits
- tests/test_watch.py — 5 commits
- tests/test_dedup.py — 4 commits
- tests/test_elixir_import_resolution.py — 4 commits
- tools/skillgen — 4 commits
- graphify/main.py — 3 commits
- graphify/detect.py — 3 commits
- graphify/export.py — 3 commits
Notable commits
- fix: Add a regression test for a genuinely external module reference
- fix: Add a regression test for the PHP JS id collision edge drop
- fix: Add a regression test for the god node guard on a duplicate name
- fix: Add a regression test for the god node guard on the fallback
- fix: Add a regression test for the issue's own repro
- fix: Add a regression test for the qualified only fallback
- fix: Add a regression test for the stray source_location gate
- fix: Add a regression test for unexported require destructures
- fix: Add an end to end regression test for the reporter's exact repro
- fix: Add end to end regression test for the issue own repro shape
- fix: Add regression test for an ambiguous basename staying skipped
- fix: Add regression test for dangling edge pruning consistency
- fix: Add regression test for defines_id on a non Latin path
- fix: Add regression test for non Latin segments in id prefixes
- fix: Add regression test for stale sidecar cohesion recomputation
- fix: Add regression test for the clustered path replace fallback
- fix: Add regression test for the no_cluster path replace fallback
- fix: Add regression test for the stale sidecar html export path
- fix: Add regression test for unscoped callers with no allowlist
- fix: Add regression tests executing Step 1 with a hostile substituted path
- …and 280 more
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
Graphify-Labs/graphify was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 26 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit 4000de15466588ec3ee32f9e10a587ca97d3b8a5 — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-a15879f6f801.