You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Graphify local repository-context provider for v1.4.1
Problem
Code Mower has a provider-neutral private-context packet and delivery path, but repository structure still comes from ordinary agent inspection. Graphify may improve dependency, impact, and related-test discovery. A preliminary evaluation also shows material risks: it can scan untracked working-copy content, its graph does not bind itself to a Git revision/build time, and broad natural-language results can be noisy. Support must begin with evidence and an immutable local boundary.
Outcome
Complete #876 as a bounded adopt/defer spike. If adopted, provide an optional local Graphify connection that builds a deterministic code-only graph from an immutable tracked-file checkout, records Code Mower-owned revision provenance, performs explicit refreshes, returns bounded cited packet evidence, and delivers the same packet to Claude, Codex, and Devin. No hosted Graphify, model-backed semantic extraction, hooks, watcher, shared HTTP MCP server, or default dependency is introduced.
Evaluate the official Graphify-Labs package from an exact reviewed version and hash. Use a fixed public Code Mower commit and a small synthetic fixture; cap tracked files, time, graph bytes, and response bytes. Run code-only extraction with query logging disabled, no provider API keys, no installation hooks, no network during extraction/query, and graph state outside the repository. Compare graph answers with rg/ordinary inspection for callers, dependents, related tests, cross-module paths, configuration coupling, blast radius, and exact-text negative controls.
Adopt only if no out-of-scope/private file is indexed, every citation remains inside the immutable checkout, at least 90% of line citations resolve, truncation/completeness is explicit, and useful incremental relationships appear on at least half the graph-suited questions. Otherwise record a defer decision and close the epic without runtime integration.
Revision and privacy contract
Code Mower owns code_mower.graphifyBuild.v1: full source commit and tree SHA, Graphify version/options, build time, tracked-file census/digest, graph digest/bytes, and completeness. Artifacts are immutable per repository/revision/options. Every read rechecks permissions, schema, digest, and requested revision. Required stale/unknown context blocks dependent work; optional context degrades explicitly. Graph content, local paths, queries, citations, and hashes remain local. CodeMower.com receives only explicitly allowlisted provider/state/count/timing metadata.
Dependencies
G1/G2 are complete. G3 #914 is active in draft #982 and uses the shared context-recipient contract. G4 #915 requires #914 and the fully completed stabilization epic #979, including #965/#967/#976 and all remaining stabilization children; Devin release #912 is already complete.
Publish and qualify Graphify v1.4.1 before Board #952, or record an explicit evidence-backed deferral in #915 and this epic. No automatic deferral or change of release order is authorized by delay. Slack implementation may proceed independently; final Slack acceptance waits for released Board. Stabilization #979 runs alongside this epic without coupling #914 to takeover work.
#915 records the exact release commit, all post-v1.4.0 fixes included in the wheel/sdist (including #935/#973 if present), published installation, no-provider fallback, Board observation, ingest receipt, and separately observed aggregate freshness. Missing settlement remains unavailable. #974 tracks the previously accepted upload's freshness without replaying it. Final roadmap #900 requires fresh aggregate evidence by v1.5.0.
Part of roadmap #900.
Graphify local repository-context provider for v1.4.1
Problem
Code Mower has a provider-neutral private-context packet and delivery path, but repository structure still comes from ordinary agent inspection. Graphify may improve dependency, impact, and related-test discovery. A preliminary evaluation also shows material risks: it can scan untracked working-copy content, its graph does not bind itself to a Git revision/build time, and broad natural-language results can be noisy. Support must begin with evidence and an immutable local boundary.
Outcome
Complete #876 as a bounded adopt/defer spike. If adopted, provide an optional local Graphify connection that builds a deterministic code-only graph from an immutable tracked-file checkout, records Code Mower-owned revision provenance, performs explicit refreshes, returns bounded cited packet evidence, and delivers the same packet to Claude, Codex, and Devin. No hosted Graphify, model-backed semantic extraction, hooks, watcher, shared HTTP MCP server, or default dependency is introduced.
Delivery sequence
Spike contract
Evaluate the official Graphify-Labs package from an exact reviewed version and hash. Use a fixed public Code Mower commit and a small synthetic fixture; cap tracked files, time, graph bytes, and response bytes. Run code-only extraction with query logging disabled, no provider API keys, no installation hooks, no network during extraction/query, and graph state outside the repository. Compare graph answers with
rg/ordinary inspection for callers, dependents, related tests, cross-module paths, configuration coupling, blast radius, and exact-text negative controls.Adopt only if no out-of-scope/private file is indexed, every citation remains inside the immutable checkout, at least 90% of line citations resolve, truncation/completeness is explicit, and useful incremental relationships appear on at least half the graph-suited questions. Otherwise record a defer decision and close the epic without runtime integration.
Revision and privacy contract
Code Mower owns
code_mower.graphifyBuild.v1: full source commit and tree SHA, Graphify version/options, build time, tracked-file census/digest, graph digest/bytes, and completeness. Artifacts are immutable per repository/revision/options. Every read rechecks permissions, schema, digest, and requested revision. Required stale/unknown context blocks dependent work; optional context degrades explicitly. Graph content, local paths, queries, citations, and hashes remain local. CodeMower.com receives only explicitly allowlisted provider/state/count/timing metadata.Dependencies
G1/G2 are complete. G3 #914 is active in draft #982 and uses the shared context-recipient contract. G4 #915 requires #914 and the fully completed stabilization epic #979, including #965/#967/#976 and all remaining stabilization children; Devin release #912 is already complete.
Publish and qualify Graphify v1.4.1 before Board #952, or record an explicit evidence-backed deferral in #915 and this epic. No automatic deferral or change of release order is authorized by delay. Slack implementation may proceed independently; final Slack acceptance waits for released Board. Stabilization #979 runs alongside this epic without coupling #914 to takeover work.
Scorecard
Definition of done
Delivery checklist
Completion PR map and release evidence
#914 → draft OSS query/packet PR #982 (actual builder Code Mower Claude, independent Code Mower Codex); #915 → one planned OSS release PR (planned builder Code Mower Codex, independent eligible peer review). #914 is active; #915 remains a planned assignment. Existing #924/#926 remain completed foundation evidence.
#915 records the exact release commit, all post-v1.4.0 fixes included in the wheel/sdist (including #935/#973 if present), published installation, no-provider fallback, Board observation, ingest receipt, and separately observed aggregate freshness. Missing settlement remains unavailable. #974 tracks the previously accepted upload's freshness without replaying it. Final roadmap #900 requires fresh aggregate evidence by v1.5.0.