More language-structure coverage, resolution/dedup correctness, and a security fix for the git-hook installer.
- Feature: four more language extractors gained type coverage from @rajatnagda45 — Zig tagged-union variants (
union(enum)) emit a node per variant with acase_ofedge (#4050), C++unionspecifiers are extracted as class-like type nodes with their members (#4052), VB.NET enum members link viacase_ofinstead ofcontains(which also stops a member named like a type binding as a constructor) (#4054), and Pascal enumerated types and their values are extracted (#4056). - Feature: three Scala type-reference fixes shipped together earlier in the day are followed here by @Faisal-Fayaz's extractor hardening — graphify now stops walking JSON Schema files as config manifests, keyed on a
$schemadeclaration plus a structural marker ($defs/definitions/$id) so real manifests that merely reference a schema are unaffected (#4048, #2255). - Fix: Elixir
import/usecall scoping is now per-module rather than per-file, so an unqualified call in one module no longer resolves against another module's imports in the same file (#4058, refines #4015). - Fix: track calls to external Python modules — a
module.func()call to a plainly-imported dependency now records acallsedge to that module, fail-closed (receiver-shadowing and non-unique bindings are skipped, builtins and unresolved locals are never fabricated) (#4043, #3793, thanks @oleksii-tumanov). - Fix: Svelte files now feed only their
<script>blocks to the AST pass (masking the template and style, preserving line numbers), so the markup no longer produces a parse error that dropped every symbol (#3984, #3928, thanks @Agnik47). - Fix: PHP language constructs (
isset,empty,list,eval, ...) no longer bind as calls to a user method that happens to share the name (#3975, #3830, thanks @Cintu07). - Fix: an unresolved base class whose only same-named definition lives in another language is kept unresolved instead of binding across languages; same-language cross-file inheritance still resolves (#4068, thanks @SrijanSriv).
- Fix: unstamped document nodes with the same heading in different files are no longer merged together during dedup; same-file document twins still merge (#4065, thanks @SrijanSriv).
- Fix:
graphify pathand the MCPshortest_pathtool resolve apath::symbolor raw node-id endpoint to the exact node before falling back to fuzzy scoring, and refuse an ambiguous endpoint instead of silently picking one (#3935, #3913, thanks @bercedev). - Fix: cross-repo resolver confidence scores are snapped to the canonical INFERRED rubric (a label-only change; no edge is added, dropped, or reclassified) (#4046, #4045, thanks @DeepanshuPal).
- Fix:
graphifyno longer indexes its own installed skill folders and whole-written rule/hook files when scanning a project, keyed on the exact install locations so a user's owngraphify-named folder is not skipped (#4062, #4057, thanks @Mpasha17). - Fix: the suggested questions in the analysis output are diversified across signal types with a round-robin, so one category no longer crowds out the others (#3972, #3849, thanks @azizur100389).
- Security:
graphify hook installrefuses acore.hooksPaththat resolves outside the repository (resolving both sides, symlink-safe), falling back to the in-repo.git/hooksinstead of writing an executable outside the checkout; legitimate in-repo custom hook paths, linked worktrees, and submodules still work (#3919, #3869, CWE-22, thanks @nothariharan). - Chore: the PyPI package page now points Homepage at graphify.com and adds a Documentation link to docs.graphify.com; Repository and Issues stay on GitHub (#4069, thanks @SyedFahad7).