Skip to content
CAI
Software that uses CAICheck a score

tirth8205/code-review-graph

56.3

Adequate · 18 September 2026

65k

lines of production code

Python

with TypeScript

1

measurement over time

CAI band scale
CAI lens gauges

What this system is

This system is a code analysis tool that builds and maintains a knowledge graph of codebase dependencies, relationships, and impact zones. It provides a VS Code extension and CLI for visualizing this graph, enabling developers to navigate code structures, analyze the blast radius of changes, and perform semantic searches. The system also includes an evaluation framework to benchmark the efficiency and accuracy of these graph-based workflows against traditional methods.

Features

Initialize Beads AI-native issue tracking in the repository

The \.beads\ directory has been added to set up the Beads issue-tracking system, which stores issues directly in the codebase using a Dolt database. This change introduces a configuration file (\config.yaml\), a README with usage instructions, and a set of Git hooks (\pre-commit\, \pre-push\, \post-checkout\, etc.) that automatically integrate issue updates with the Git workflow. A \.gitignore\ file ensures that runtime artifacts, lock files, and the local SQLite/Dolt data are not committed, while \metadata.json\ defines the project's database backend.

.beads · high confidence

Introduce VS Code backend for CLI interaction, database reading, and file watching

This change adds the core backend infrastructure for the VS Code extension, introducing three new modules in the \code-review-graph-vscode/src/backend\ directory. The \cli.ts\ module provides a \CliWrapper\ class that manages the external \code-review-graph\ CLI, handling installation via \uv\, \pipx\, or \pip\, graph building, updating, embedding, and version detection with appropriate progress notifications. The \sqlite.ts\ module implements a read-only \SqliteReader\ using \better-sqlite3\ to query the graph database, defining typed interfaces for nodes, edges, and stats, while handling ABI mismatches gracefully. The \watcher.ts\ module introduces a \GraphWatcher\ class that monitors the \graph.db\ file for changes using VS Code's file system API, debouncing events to prevent excessive processing.

code-review-graph-vscode/src/backend · high confidence

Introduce VS Code extension for code graph visualization and analysis

The new Code Review Graph VS Code extension allows users to visualize code dependencies, analyze blast radius, and trace function relationships directly within the editor. It provides a Code Graph Explorer tree view, an interactive D3.js visualization, and commands to find callers, callees, and tests. The extension includes an onboarding flow that auto-detects and installs the required Python backend, supports live fuzzy search, and offers settings to customize the graph theme, node limits, and tree view visibility.

code-review-graph-vscode, code-review-graph-vscode/src · high confidence

Introduce VS Code extension views for code graph visualization and navigation

This change adds the core view components for the new VS Code extension, enabling users to explore code dependencies directly within the editor. It introduces a hierarchical tree view that organizes source files, symbols (classes, functions, types), and their relationships (calls, imports, inheritance), alongside a dedicated 'Blast Radius' view to highlight changed and impacted nodes. Additionally, it implements an interactive webview panel for force-directed graph visualization, complete with toolbar controls, theme synchronization, and export capabilities (SVG/PNG), while a status bar item provides real-time feedback on the graph database's freshness and node count.

code-review-graph-vscode/src/views · high confidence

Introduce code\_review\_graph v2.3.8 with context-savings estimation and legacy instruction support

The package is updated to version 2.3.8 and now exposes a new \context\_savings\ module that provides functions to estimate and format token savings for codebase exploration. To ensure smooth upgrades, a new \\_legacy\instructions\ module stores verbatim copies of instruction blocks from previous releases, allowing the system to correctly identify and upgrade managed blocks in user configuration files without guessing boundaries. The package also includes a vendored D3.js v7.9.0 asset for offline graph visualization and adds a \\\main\\_.py\ entry point to allow running the tool via \python -m code\_review\_graph\.

_code\_review\graph · high confidence

Introduce interactive code review graph visualization in VS Code

The VS Code extension now includes a webview-based, D3.js force-directed graph that visualizes code relationships (files, classes, functions, tests, and types) and their interactions (calls, imports, inheritance, etc.). Users can explore the codebase structure with distinct node shapes and colors for different entity kinds, filter edges by type, and navigate the graph using keyboard controls and zoom/pan interactions. The visualization communicates with the extension host to provide context-aware code review insights directly within the editor.

code-review-graph-vscode/src/webview · high confidence

Introduce modular MCP tool package with bounded responses and provenance

The \code\_review\graph/tools\ package has been restructured into a modular layout (\\\init\\_.py\, \\_common.py\, \analysis\_tools.py\, \build.py\, \community\_tools.py\, \context.py\, \docs.py\, \flows\_tools.py\, etc.) exposing 30 MCP tools. This change introduces hard ceilings on response sizes (e.g., 100 hub/bridge nodes, 200 communities, 200 flows) to prevent token exhaustion, and adds graph provenance metadata (build timestamp, branch, commit SHA, and staleness checks) to tool responses. It also standardizes error handling and validation for repository roots and input parameters.

_code\_review\graph/tools · high confidence

New CI automation and diagnostic scripts for release safety and import integrity

This change introduces several new Python scripts to the \scripts/\ directory to improve CI reliability, security, and developer diagnostics. \auto\_promote.py\ and \promotion\_gate.py\ implement a daily, automated promotion gate that merges \staging\ to \testing\ only when specific, dynamically-read required checks pass, with strict validation to prevent merging foreign pull requests or unsafe branches. \audit\_python\_imports.py\ adds a new integrity check that re-resolves Python imports using the \ast\ module to detect dangling edges, case-sensitivity mismatches, and incorrect relative import targets in the code-review graph. Additionally, \diagnose\_pypi\_connectivity.py\ provides a diagnostic tool for users to verify PyPI/HTTPS connectivity, and \smoke\_google\_embeddings.py\ validates the Google embedding provider setup. \render\_pr\_comment.py\ is also included to format risk-scored PR comments with repo-relative paths.

scripts · high confidence

New diagram assets and generation tooling for context-savings documentation

Added a new VHS tape script (context-savings-demo.tape) and a Python generator (generate\_diagrams.py) to produce Excalidraw-based diagrams. The new demo script visualizes the estimated context\_savings metric introduced in v2.3.4+, specifically demonstrating the detect-changes and update CLI surfaces with the --verify flag. The generator script creates static diagram assets, including a 'Before vs After' comparison showing token usage reduction (125,022 vs 1,986 tokens) and impact detection recall, which are used to support the updated documentation and README.

diagrams · high confidence

New evaluation framework for benchmarking code-review-graph workflows

The \code\_review\_graph/eval\ package introduces a dedicated evaluation framework to measure and report on the performance of graph-based code review workflows. It provides scoring metrics for token efficiency, Mean Reciprocal Rank (MRR), and precision/recall, alongside a runner that orchestrates benchmarks across real repositories. Users can now generate detailed markdown reports and CSV outputs to track metrics like token savings, search quality, and build performance across five key workflows: review, architecture, debug, onboarding, and pre-merge checks.

_code\_review\graph/eval · high confidence

VS Code extension adds code graph navigation, impact analysis, and SCM decorations

The VS Code extension now provides core code-review capabilities directly in the editor. Users can navigate the code graph by finding callers and tests for the symbol under the cursor, or performing a live-filtered search for functions, classes, and files. The extension also analyzes the blast radius of staged and unstaged changes to show which files are impacted, and adds visual badges to the Explorer and SCM views to indicate whether changed files are in the impact zone or have test coverage.

code-review-graph-vscode/src/features · high confidence

Removals

Removal of server codebase components

The server module files (\_\init\\.py, \\main\\_.py, graph.py, incremental.py, main.py, parser.py, and tools.py) have been deleted, removing the MCP server implementation, SQLite-backed knowledge graph storage, Tree-sitter code parsing logic, and associated tool definitions from this location.

server · high confidence

Behavioural changes

New evaluation benchmarks for agent baselines, search quality, and incremental fidelity

The evaluation framework now includes a suite of new benchmarks in the \code\_review\_graph/eval/benchmarks\ module. An agent baseline benchmark compares a realistic grep-and-read approach against the graph query cost to measure efficiency gains. Search quality is now measured using Mean Reciprocal Rank (MRR), and multi-hop retrieval tests the two-step chain of semantic search followed by graph traversal. Impact accuracy now supports an 'honest' co-change ground truth mode (excluding the seed file) alongside the previous graph-derived mode, and failure semantics have been corrected so that errors are excluded from aggregates rather than producing fake perfect scores. Additionally, new benchmarks track build performance (flow and community detection timing), token efficiency, and incremental fidelity (verifying that incremental updates match clean rebuilds across all database tables).

_code\_review\graph/eval/benchmarks · high confidence

Updated benchmark results for impact accuracy, multi-hop retrieval, and token efficiency

The evaluation suite has been refreshed with new benchmark data for May 25 and August 2, 2026, covering impact accuracy, multi-hop retrieval, and token efficiency across repositories including code-review-graph, express, fastapi, flask, gin, and httpx. The impact accuracy metrics now include a 'co-change' ground truth mode (excluding the seed file) alongside the existing 'graph-derived' mode, providing a more granular view of prediction precision. Additionally, the multi-hop retrieval benchmarks have been expanded to include new natural language query tasks for several frameworks, and token efficiency ratios have been recalculated to reflect current model performance.

evaluate · high confidence

Updated hook configuration to use new event types and integrate code-review-graph

The hooks configuration has been updated to replace the deprecated PostEdit and PostGit events with SessionStart and PostToolUse. A new SessionStart hook now runs at the beginning of every session to check for the existence of the code-review-graph knowledge graph and provide guidance to the user on using graph-based tools (such as semantic search and impact radius) instead of manual file scanning. Additionally, PostToolUse hooks now automatically build the graph when entering a new worktree and update it after code edits or bash commands, ensuring the graph stays in sync with the codebase.

hooks · high confidence

Test coverage

Added tests for the SqliteReader module; Expanded test fixtures for multi-language parser coverage; Test infrastructure for deterministic builds and isolated environments.

Dependencies

VS Code extension and Python core dependency updates

The VS Code extension (code-review-graph-vscode) now uses a new package-lock.json and package.json, pinning dependencies like d3, better-sqlite3, and Azure SDKs, and targeting VS Code 1.85.0. The Python core (pyproject.toml) bumps the version to 2.3.8, lowers the minimum Python requirement to 3.10, and updates key dependencies: fastmcp is upgraded to \>=3.2.4,\<4 to address [CVE redacted]/62801/66416 and fix Windows stdio EOF bugs, mcp is updated to \>=1.0.0,\<3, and upper bounds are added to tree-sitter, networkx, watchdog, and other libraries to prevent breaking changes from next major releases.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Baseline

  • First survey — no prior run to compare against. CAI 56.

Lenses

  • Code Health 43
  • Architecture 99
  • Maturity 75
  • Readiness 58
  • Security 73

Changes since last survey

  • 300 commits — 155 feature/other, 145 fixes

By area

  • (repo) — 136 commits
  • (root) — 53 commits
  • code_review_graph/parser.py — 16 commits
  • code_review_graph/incremental.py — 15 commits
  • code_review_graph/tools — 12 commits
  • code_review_graph/graph.py — 10 commits
  • code_review_graph/cli.py — 9 commits
  • code_review_graph/changes.py — 6 commits
  • code_review_graph/skills.py — 4 commits
  • .github/workflows — 3 commits
  • code-review-graph-vscode/src — 3 commits
  • code_review_graph/daemon_cli.py — 2 commits
  • code_review_graph/eval — 2 commits
  • code_review_graph/search.py — 2 commits
  • docs/superpowers — 2 commits
  • tests/fixtures — 2 commits
  • tests/test_action_e2e.py — 2 commits
  • code_review_graph/build_state.py — 1 commit
  • code_review_graph/daemon.py — 1 commit
  • code_review_graph/docs — 1 commit

Notable commits

  • fix: Integrate PR #810: fix(parser): load C/C++/Bash probes with parent language-pack path (#807)
  • fix: Integrate PR #810: fix(parser): load C/C++/Bash probes with parent language-pack path (#807)
  • fix: Integrate PR #847: fix(review): use merge-base for branch diffs
  • fix: Integrate PR #860: fix(incremental): reconcile reverted file content
  • fix: Integrate PR #870: fix(graph): survive malformed extra JSON in get_all_files
  • fix: Integrate PR #928: fix: read source files as UTF-8 regardless of system locale
  • fix: Integrate PR #952: fix: refresh graph freshness after no-op updates
  • fix: Integrate PR #955: fix(parser): extract Python aliased module imports
  • fix: Integrate PR #959: fix(watch): drop events on paths the OS cannot stat
  • fix: Integrate PR #960: fix(graph): accept dotted Python module imports as endpoint evidence (#903)
  • fix: Integrate PR #962: fix(embeddings): enumerate nodes independently of stored paths
  • fix: Integrate PR #966: fix(query): caveat ambiguous bare-name inheritor candidates
  • fix: Integrate PR #969: fix(query): include unresolved bare-name targets in references_to
  • fix: Merge branch 'main' into agent/fix-go-selector-call-targets
  • fix: Merge branch 'main' into agent/fix-windows-daemon-stop
  • fix: Merge branch 'main' into fix/812-purge-orphan-file-rows
  • fix: Merge branch 'main' into fix/cli-affected-flows-relative-paths
  • fix: Merge branch 'main' into fix/dotted-stem-relative-import-resolution
  • fix: Merge branch 'main' into fix/google-embeddings-packaging
  • fix: Merge branch 'main' into fix/keyword-argument-callback-refs
  • …and 280 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

tirth8205/code-review-graph was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 18 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit d34f6fbfb7383c6c5a8d0a764ff120e4834214d3 — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-5d04157a340d.