Skip to content

graphify

v0.8.49 Security

This release includes 2 security fixes for security teams reviewing exposed deployments.

Published 1mo RAG & Retrieval
✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 2 known CVEs

Topics

antigravity claude-code codex gemini graphrag knowledge-graph
+5 more
leiden openclaw llm skills tree-sitter

Affected surfaces

deps

Summary

AI summary

Floor starlette at >=1.3.1 to fix CVE-2026-48818 and CVE-2026-54283.

Full changelog

graphify 0.8.49

Fixes

  • get_community MCP tool now shows the community name in its header (Community 12 — Auth & Sessions (8 nodes)), matching get_node / query output; skipped when it is only the Community N placeholder so it never doubles (#1448, thanks @rmart1308).
  • graphify reflect no longer duplicates "known dead ends" / "corrections" lines when the same Q&A is saved more than once (dedup by question, most recent wins).
  • Work-memory works without the git hook: the skill runs graphify reflect --if-stale at the start of graph work, so a skill-only install still refreshes LESSONS.md. --if-stale no-ops when the file is already newer than every input, so the post-commit hook is an optimization rather than a requirement.

Security

  • Floor starlette at >=1.3.1 for CVE-2026-48818 and CVE-2026-54283 (both resolved by 1.3.1). starlette underpins the HTTP MCP transport (graphify-mcp over HTTP); stdio and the CLI are unaffected. Now declared in the mcp/all extras and floored so end users installing graphifyy[mcp] are covered, not just the dev lock (#1391, #1396, thanks @orbisai0security).

Refactor / Performance

  • Begin splitting extract.py into per-language modules under graphify/extractors/ (blade, elixir, razor, zig + shared base.py), behavior-neutral, with extract.py re-exporting the moved names so all callers and the dispatch table are unchanged (#1212, thanks @TheFedaikin).
  • Parallel community labeling: cluster-only / label take --max-concurrency and --batch-size; ollama/claude-cli stay serial unless opted in (#1390).

Install: uv tool install graphifyy==0.8.49

Security Fixes

  • CVE-2026-48818 — floor starlette >=1.3.1 in mcp/all extras
  • CVE-2026-54283 — floor starlette >=1.3.1 in mcp/all extras

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track graphify

Get notified when new releases ship.

Sign up free

About graphify

AI coding assistant skill (Claude Code, Codex, OpenCode, Cursor, Gemini CLI, OpenClaw, Factory Droid, Trae). Turn any folder of code, docs, papers, images, videos, or YouTube links into a queryable knowledge graph

All releases →

Related context

Earlier breaking changes

  • v0.8.18 Breaks Java `extends` edges; they are renamed to `inherits`. Update queries filtering on `relation="extends"` for Java nodes.

Beta — feedback welcome: [email protected]