Skip to content

build(deps): bump graphifyy from 0.9.70 to 0.9.74 - #18

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/uv/graphifyy-0.9.74
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/uv/graphifyy-0.9.74

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 5, 2026

Copy link
Copy Markdown
Contributor

Bumps graphifyy from 0.9.70 to 0.9.74.

Release notes

Sourced from graphifyy's releases.

v0.9.74

  • Feature: four more language extractors gained structural depth. Ruby paren-less self-sends (do_thing with no receiver or parens) are now captured as calls, with a local-variable/parameter/block-parameter in scope correctly suppressing the call (fail-closed, no fabrication) (#3960, thanks @​rajatnagda45). TypeScript abstract method signatures in an abstract class are now extracted as callable method members and resolve as call targets (#3961, thanks @​rajatnagda45). Scala deferred (abstract) method declarations in traits and abstract classes (def foo: Int, no body) are now extracted as methods (#3962, thanks @​rajatnagda45). C++ a member-function declaration inside a class (void foo();, defined out-of-line) is now classified as a method rather than a field, including pure-virtual, const, operator, and destructor forms; real data members stay fields (#3963, thanks @​rajatnagda45).
  • Fix: a Rust type used before it is declared in the same file now resolves to its local declaration instead of fabricating an external stub; resolution is a two-pass, order-independent scan, and a forward reference whose name collides with another same-id item is kept unresolved (fail-closed) (#3903, #3782, thanks @​Yyunozor).
  • Fix: Rust prelude types (Option, Result, Vec, String, Box, Rc, Arc, HashMap, and friends) no longer accumulate spurious in-degree and surface as god nodes that distort community detection and ranking; they are filtered at extraction time, and a type the file defines itself is kept. Tuple-struct and unit-struct construction (ClientId(id)) is reclassified from a calls edge to a references/constructor edge (#3973, thanks @​liam-mcelhaney122).
  • Fix: an Obsidian-style wikilink to a note whose name contains a dot ([[v1.2 release]], [[note.en]]) now resolves instead of being dropped by a premature extension strip; plain, explicit-extension, anchor, and alias wikilinks are unchanged, a literal indexed file beside the link keeps precedence, and a genuinely missing target is still not fabricated (#3905, #3904, thanks @​Yyunozor).
  • Fix: a constructor call whose target is a same-file annotation stub (a source-less node minted by an earlier annotation or generic-argument reference) is kept for cross-file resolution and binds to the real definition when there is import or namespace/using-scope evidence, instead of being dropped; a genuinely external unresolved name is still not fabricated (#3901, thanks @​bercedev).
  • Fix: the CLI hook-guard that protects graphify's own output directory now resolves paths and checks real containment instead of substring matching, so a sibling directory sharing a name prefix (artifacts/graphify-notes vs artifacts/graphify) is no longer wrongly treated as inside the output dir; symlinks, .., relative paths, and case-insensitive filesystems are handled (#3964, #3959, thanks @​shobhitagnihotri69).
  • Fix: when resolving an import of a workspace package that ships both a source entry and a built dist, the graph now prefers the source file (so edges point at authored code) and falls back to the built artifact only when no source entry exists, generalizing the existing source-over-dist preference from the exports path to the legacy main/module fields (#4000, #3834, thanks @​Adityakk9031).
  • Feature: Verilog header files (.vh) are now detected and extracted through the same tree-sitter-verilog grammar as .v/.sv, so macros, parameters, and modules declared in headers are captured (#3983, thanks @​oleksii-tumanov).
  • Fix: an incremental update no longer drops a hyperedge from an untouched file when a re-extracted file emits a hyperedge with the same id; carried hyperedges are now keyed by (id, source_file) so a same-id edge from a different, unchanged file is preserved while a genuine same-file re-emit still replaces (#3997, #3981, thanks @​Ayushraj06-bit).
  • Feature: Kotlin class-literal references in annotation arguments (@ManyToOne(targetEntity = Customer::class)) are now extracted as attribute references to the referenced type (#3965, #3835, thanks @​hopstreax).
  • Fix: Lua colon-method calls (obj:method(), self:method()) now resolve to the table-qualified method definition; a non-self receiver fails closed with no cross-file member fabrication (#3994, thanks @​rajatnagda45).
  • Feature: Erlang local fun references (fun Name/Arity, as in lists:map(fun helper/1, L)) are now recorded as indirect_call edges to the arity-matched local function; remote fun Mod:Name/Arity and anonymous funs are left as-is, and an undefined or arity-mismatched local fails closed (#3996, thanks @​rajatnagda45).
  • Fix: C# null-conditional member calls (receiver?.Method()) now resolve through the same typed-receiver path as receiver.Method(), including the call-site generic-argument walk; chained and element-access forms fall through to bare-name resolution with no fabrication (#3976, #3797, thanks @​Cintu07).

v0.9.73

  • Feature: enum members are now extracted as nodes with case_of edges in four more languages — Rust enum variants (#3938), Zig enum members (#3940), C++ enum/enum class enumerators including nested enums (#3939), and Scala 3 enum cases plus their methods (#3937) — all thanks @​rajatnagda45.
  • Fix: Java calls to inherited methods and super.method() now resolve to the declaring ancestor (walking the inherits chain, nearest declaration wins), instead of dangling; an unknown/external or ambiguous ancestor fails closed (#3932, thanks @​janwaleed09).
  • Fix: semantic extraction warns once when a file exceeds the 20,000-character cap and is truncated, instead of silently dropping the tail (#3923, #3773, thanks @​AK-Lmn).
  • Feature: Solidity file-level free functions (Solidity 0.7+, declared outside any contract) and their calls are now extracted (#3906, thanks @​rajatnagda45).
  • Fix: VB.NET type/module-qualified calls (MyModule.DoThing(), MyClass.SharedMethod()) resolve to the target method; value-receiver and MyBase. calls fail closed (#3909, thanks @​rajatnagda45).
  • Fix: Astro files are parsed correctly — only the frontmatter and <script> blocks are fed to the AST pass (the HTML template no longer produces parse errors), with line numbers preserved (#3902, thanks @​Bosken85).
  • Fix: the "surprising connections" cross-repo/directory bonus now matches the reason it prints — two files at the scan root no longer falsely score as crossing repos (#3934, thanks @​neo1777).
  • Fix: under --exclude-hubs, a node whose only neighbours are excluded hubs is kept with its hub's community instead of being severed into a singleton; the default path is unchanged (#3933, thanks @​neo1777).
  • Perf: the Neo4j/FalkorDB --push path creates a per-label id index before the node upsert loop, fixing the throughput collapse on large graphs (#3957, thanks @​Yi-111-a).
  • Fix: community labeling keeps the labels it already named when a nested retry fails to parse, instead of discarding the whole batch (#3956, thanks @​Vikram-Lex).
  • Fix: graphify hook status reports hooks written by an older release as out of date (run graphify hook install to refresh) (#3951, #3771, thanks @​bercedev).
  • Fix: a Rust virtual-workspace-root Cargo.toml (only [workspace], no [package]) is treated as skipped-by-design rather than warned as zero-node (#3930, #3910, thanks @​Adityakk9031).
  • Fix: when the instructions file (CLAUDE.md etc.) is a symlink, install reports the real target it wrote to, and uninstall keeps the symlink (strips only the graphify section) instead of deleting the link (#3950, #3953, #3805, thanks @​bercedev).

v0.9.72

  • Feature: after a package upgrade, graphify refreshes stale installed skills automatically (the SKILL.md + references sidecar it manages) so the version-mismatch warning no longer requires a manual graphify install. It runs on any non-install CLI command when a skill is stale, backs up local edits to SKILL.md.bak, never touches your marker-bounded CLAUDE.md/AGENTS.md/GEMINI.md sections, and can be disabled with GRAPHIFY_NO_AUTO_REFRESH=1 (#3895, #1805, thanks @​bercedev).
  • Fix: graph.html's Node Info panel now shows the real Type/Source/Community for each node instead of "Type: unknown / Source: -" (the panel read field names that did not match the emitted node schema); aggregated community nodes show a member count (#3918, #3914, thanks @​hopstreax).
  • Fix: a Kotlin class property that is both annotated and has an inferred type (@Volatile var x = 0) no longer crashes extraction with an UnboundLocalError that dropped the whole file (#3915, thanks @​nothariharan; #3899, thanks @​harshaygadekar; #3884).
  • Fix: SQL DDL that appears before a PostgreSQL DO $$ ... $$ block is now extracted — the block node the parser produces for that span is walked instead of skipped (#3900, thanks @​bercedev).
  • Fix: Razor extracts C# members from @functions { } blocks (classic Razor Pages/MVC), not only Blazor @code { } blocks (#3908, thanks @​rajatnagda45).
  • Feature: Blade templates now link a view to the layout it @extends (#3907, thanks @​rajatnagda45).
  • Fix: resolving an imported module name no longer binds to a same-named contained symbol (a class/module member); only genuine top-level module/file nodes are considered (#3898, #3887, thanks @​harshaygadekar).
  • Fix: docx sidecar conversion now keeps tables in their document position (instead of dumping them after all prose) and reads all text, including tracked insertions, content controls, and text boxes, by walking the document body in order (#3833, thanks @​L4XB).
  • Fix: label/signature sidecars are now published atomically and in a safe order (labels before signatures), so an interrupted rebuild can no longer leave stale community labels for a clustering that no longer exists (#3853, thanks @​shashank-100).
  • Fix: the markdown wikilink index respects .graphifyignore/.gitignore/--exclude and resolves an article-named index without overwriting the generated index.md hub — two independent wiki/markdown fixes (#3818, thanks @​breken-ai; escaped-alias parsing [[target\|alias]] #3772, thanks @​zagushka).
  • Fix: the community listing in GRAPH_REPORT.md reuses the shared real-node filter, so rationale/concept nodes no longer inflate a community's node count or leak into the listing (#3836, #3794, thanks @​ayushcodes10).
  • Fix: extraction now warns once (not per file) when a PDF is encountered but the pdf extra (pypdf) is not installed, instead of silently producing no text (#3710, #3702, thanks @​shobhitagnihotri69).
  • Chore: graphify / graphify --help now shows the logo banner and a link to the hosted platform at app.graphify.com.

v0.9.71

  • Feature: SQL CREATE TRIGGER statements are now extracted and linked to their table (ON <table>), including OR REPLACE/OR ALTER, INSTEAD OF, and procedural BEGIN…END bodies that previously landed in a parser-error node and were dropped (#3863, thanks @​rajatnagda45).

... (truncated)

Changelog

Sourced from graphifyy's changelog.

0.9.74 (2026-10-02)

  • Feature: four more language extractors gained structural depth. Ruby paren-less self-sends (do_thing with no receiver or parens) are now captured as calls, with a local-variable/parameter/block-parameter in scope correctly suppressing the call (fail-closed, no fabrication) (#3960, thanks @​rajatnagda45). TypeScript abstract method signatures in an abstract class are now extracted as callable method members and resolve as call targets (#3961, thanks @​rajatnagda45). Scala deferred (abstract) method declarations in traits and abstract classes (def foo: Int, no body) are now extracted as methods (#3962, thanks @​rajatnagda45). C++ a member-function declaration inside a class (void foo();, defined out-of-line) is now classified as a method rather than a field, including pure-virtual, const, operator, and destructor forms; real data members stay fields (#3963, thanks @​rajatnagda45).
  • Fix: a Rust type used before it is declared in the same file now resolves to its local declaration instead of fabricating an external stub; resolution is a two-pass, order-independent scan, and a forward reference whose name collides with another same-id item is kept unresolved (fail-closed) (#3903, #3782, thanks @​Yyunozor).
  • Fix: Rust prelude types (Option, Result, Vec, String, Box, Rc, Arc, HashMap, and friends) no longer accumulate spurious in-degree and surface as god nodes that distort community detection and ranking; they are filtered at extraction time, and a type the file defines itself is kept. Tuple-struct and unit-struct construction (ClientId(id)) is reclassified from a calls edge to a references/constructor edge (#3973, thanks @​liam-mcelhaney122).
  • Fix: an Obsidian-style wikilink to a note whose name contains a dot ([[v1.2 release]], [[note.en]]) now resolves instead of being dropped by a premature extension strip; plain, explicit-extension, anchor, and alias wikilinks are unchanged, a literal indexed file beside the link keeps precedence, and a genuinely missing target is still not fabricated (#3905, #3904, thanks @​Yyunozor).
  • Fix: a constructor call whose target is a same-file annotation stub (a source-less node minted by an earlier annotation or generic-argument reference) is kept for cross-file resolution and binds to the real definition when there is import or namespace/using-scope evidence, instead of being dropped; a genuinely external unresolved name is still not fabricated (#3901, thanks @​bercedev).
  • Fix: the CLI hook-guard that protects graphify's own output directory now resolves paths and checks real containment instead of substring matching, so a sibling directory sharing a name prefix (artifacts/graphify-notes vs artifacts/graphify) is no longer wrongly treated as inside the output dir; symlinks, .., relative paths, and case-insensitive filesystems are handled (#3964, #3959, thanks @​shobhitagnihotri69).
  • Fix: when resolving an import of a workspace package that ships both a source entry and a built dist, the graph now prefers the source file (so edges point at authored code) and falls back to the built artifact only when no source entry exists, generalizing the existing source-over-dist preference from the exports path to the legacy main/module fields (#4000, #3834, thanks @​Adityakk9031).
  • Feature: Verilog header files (.vh) are now detected and extracted through the same tree-sitter-verilog grammar as .v/.sv, so macros, parameters, and modules declared in headers are captured (#3983, thanks @​oleksii-tumanov).
  • Fix: an incremental update no longer drops a hyperedge from an untouched file when a re-extracted file emits a hyperedge with the same id; carried hyperedges are now keyed by (id, source_file) so a same-id edge from a different, unchanged file is preserved while a genuine same-file re-emit still replaces (#3997, #3981, thanks @​Ayushraj06-bit).
  • Feature: Kotlin class-literal references in annotation arguments (@ManyToOne(targetEntity = Customer::class)) are now extracted as attribute references to the referenced type (#3965, #3835, thanks @​hopstreax).
  • Fix: Lua colon-method calls (obj:method(), self:method()) now resolve to the table-qualified method definition; a non-self receiver fails closed with no cross-file member fabrication (#3994, thanks @​rajatnagda45).
  • Feature: Erlang local fun references (fun Name/Arity, as in lists:map(fun helper/1, L)) are now recorded as indirect_call edges to the arity-matched local function; remote fun Mod:Name/Arity and anonymous funs are left as-is, and an undefined or arity-mismatched local fails closed (#3996, thanks @​rajatnagda45).
  • Fix: C# null-conditional member calls (receiver?.Method()) now resolve through the same typed-receiver path as receiver.Method(), including the call-site generic-argument walk; chained and element-access forms fall through to bare-name resolution with no fabrication (#3976, #3797, thanks @​Cintu07).

0.9.73 (2026-09-30)

  • Feature: enum members are now extracted as nodes with case_of edges in four more languages — Rust enum variants (#3938), Zig enum members (#3940), C++ enum/enum class enumerators including nested enums (#3939), and Scala 3 enum cases plus their methods (#3937) — all thanks @​rajatnagda45.
  • Fix: Java calls to inherited methods and super.method() now resolve to the declaring ancestor (walking the inherits chain, nearest declaration wins), instead of dangling; an unknown/external or ambiguous ancestor fails closed (#3932, thanks @​janwaleed09).
  • Fix: semantic extraction warns once when a file exceeds the 20,000-character cap and is truncated, instead of silently dropping the tail (#3923, #3773, thanks @​AK-Lmn).
  • Feature: Solidity file-level free functions (Solidity 0.7+, declared outside any contract) and their calls are now extracted (#3906, thanks @​rajatnagda45).
  • Fix: VB.NET type/module-qualified calls (MyModule.DoThing(), MyClass.SharedMethod()) resolve to the target method; value-receiver and MyBase. calls fail closed (#3909, thanks @​rajatnagda45).
  • Fix: Astro files are parsed correctly — only the frontmatter and <script> blocks are fed to the AST pass (the HTML template no longer produces parse errors), with line numbers preserved (#3902, thanks @​Bosken85).
  • Fix: the "surprising connections" cross-repo/directory bonus now matches the reason it prints — two files at the scan root no longer falsely score as crossing repos (#3934, thanks @​neo1777).
  • Fix: under --exclude-hubs, a node whose only neighbours are excluded hubs is kept with its hub's community instead of being severed into a singleton; the default path is unchanged (#3933, thanks @​neo1777).
  • Perf: the Neo4j/FalkorDB --push path creates a per-label id index before the node upsert loop, fixing the throughput collapse on large graphs (#3957, thanks @​Yi-111-a).
  • Fix: community labeling keeps the labels it already named when a nested retry fails to parse, instead of discarding the whole batch (#3956, thanks @​Vikram-Lex).
  • Fix: graphify hook status reports hooks written by an older release as out of date (run graphify hook install to refresh) (#3951, #3771, thanks @​bercedev).
  • Fix: a Rust virtual-workspace-root Cargo.toml (only [workspace], no [package]) is treated as skipped-by-design rather than warned as zero-node (#3930, #3910, thanks @​Adityakk9031).
  • Fix: when the instructions file (CLAUDE.md etc.) is a symlink, install reports the real target it wrote to, and uninstall keeps the symlink (strips only the graphify section) instead of deleting the link (#3950, #3953, #3805, thanks @​bercedev).

0.9.72 (2026-09-29)

  • Feature: after a package upgrade, graphify refreshes stale installed skills automatically (the SKILL.md + references sidecar it manages) so the version-mismatch warning no longer requires a manual graphify install. It runs on any non-install CLI command when a skill is stale, backs up local edits to SKILL.md.bak, never touches your marker-bounded CLAUDE.md/AGENTS.md/GEMINI.md sections, and can be disabled with GRAPHIFY_NO_AUTO_REFRESH=1 (#3895, #1805, thanks @​bercedev).
  • Fix: graph.html's Node Info panel now shows the real Type/Source/Community for each node instead of "Type: unknown / Source: -" (the panel read field names that did not match the emitted node schema); aggregated community nodes show a member count (#3918, #3914, thanks @​hopstreax).
  • Fix: a Kotlin class property that is both annotated and has an inferred type (@Volatile var x = 0) no longer crashes extraction with an UnboundLocalError that dropped the whole file (#3915, thanks @​nothariharan; #3899, thanks @​harshaygadekar; #3884).
  • Fix: SQL DDL that appears before a PostgreSQL DO $$ ... $$ block is now extracted — the block node the parser produces for that span is walked instead of skipped (#3900, thanks @​bercedev).
  • Fix: Razor extracts C# members from @functions { } blocks (classic Razor Pages/MVC), not only Blazor @code { } blocks (#3908, thanks @​rajatnagda45).
  • Feature: Blade templates now link a view to the layout it @extends (#3907, thanks @​rajatnagda45).
  • Fix: resolving an imported module name no longer binds to a same-named contained symbol (a class/module member); only genuine top-level module/file nodes are considered (#3898, #3887, thanks @​harshaygadekar).
  • Fix: docx sidecar conversion now keeps tables in their document position (instead of dumping them after all prose) and reads all text, including tracked insertions, content controls, and text boxes, by walking the document body in order (#3833, thanks @​L4XB).
  • Fix: label/signature sidecars are now published atomically and in a safe order (labels before signatures), so an interrupted rebuild can no longer leave stale community labels for a clustering that no longer exists (#3853, thanks @​shashank-100).
  • Fix: the markdown wikilink index respects .graphifyignore/.gitignore/--exclude and resolves an article-named index without overwriting the generated index.md hub — two independent wiki/markdown fixes (#3818, thanks @​breken-ai; escaped-alias parsing [[target\|alias]] #3772, thanks @​zagushka).
  • Fix: the community listing in GRAPH_REPORT.md reuses the shared real-node filter, so rationale/concept nodes no longer inflate a community's node count or leak into the listing (#3836, #3794, thanks @​ayushcodes10).
  • Fix: extraction now warns once (not per file) when a PDF is encountered but the pdf extra (pypdf) is not installed, instead of silently producing no text (#3710, #3702, thanks @​shobhitagnihotri69).
  • Chore: graphify / graphify --help now shows the logo banner and a link to the hosted platform at app.graphify.com.

0.9.71 (2026-09-28)

... (truncated)

Commits
  • e10df08 release: 0.9.74
  • f99a21b fix(build): keep a same-id hyperedge from an untouched file on update
  • 4315c60 feat(extract): include Verilog header files
  • 038954a fix(markdown): resolve wikilinks to note names that contain a dot (#3904)
  • 81b0391 fix(resolution): prefer source entry over built dist in workspace packages (#...
  • 8e5649f fix(cli): resolve hook-guard output paths instead of substring matching (#3959)
  • b676462 fix(extract): keep constructor calls that hit a same-file annotation stub
  • 01a687c refactor(rust): keep the builtin-type set language-local
  • 7f1d45d fix(rust): stop prelude types becoming god nodes and label constructors
  • 4babf7b fix(rust): keep a forward reference unresolved when its type id collides with...
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [graphifyy](https://github.com/Graphify-Labs/graphify) from 0.9.70 to 0.9.74.
- [Release notes](https://github.com/Graphify-Labs/graphify/releases)
- [Changelog](https://github.com/Graphify-Labs/graphify/blob/v8/CHANGELOG.md)
- [Commits](Graphify-Labs/graphify@v0.9.70...v0.9.74)

---
updated-dependencies:
- dependency-name: graphifyy
  dependency-version: 0.9.74
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python:uv Pull requests that update python:uv code labels Oct 5, 2026
@dependabot
dependabot Bot requested a review from doronp as a code owner October 5, 2026 18:46
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python:uv Pull requests that update python:uv code labels Oct 5, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file python:uv Pull requests that update python:uv code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants