Skip to main content

cgh-classify

Frozen. 0.2.0 is the final release. Its main consumers, the core egress gate's confidentiality labels and the guard, went away with secure mode in cgh 0.15.0, and cgh[plugins] no longer installs it. It still works and still installs by name (pip install cgh-classify), gets no new features, and may be removed from the cgh repository later. cgh-codegen's egress gate still honors a confidential finding when one exists.

Human-trainable confidentiality classification for cgh. You label a few files, a lightweight local model (TF-IDF + naive Bayes, standard library only) generalizes to the rest, and the result lands as confidential findings. Nothing ever leaves the machine.

pip install cgh-classify
cgh classify label payroll.xlsx            # mark confidential
cgh classify label README.md --not         # mark public
cgh classify train                         # fit + sweep the repo
cgh classify review                        # files the model is unsure about
cgh findings --key confidential

How labels and predictions interact

Source Finding written Effect on an egress gate (cgh-codegen)
Human label, confidential confidential = true (block) blocked everywhere
Human label, public confidential = false allowlisted, including strict mode
Model prediction, confidential confidential = true (block) blocked everywhere
Model prediction, public confidential.predicted = false no effect

The asymmetry is deliberate: a model may block on its own say-so (worst case, a false positive costs a summary), but only a human label can clear a file under a strict egress gate (egress = "strict"), where the gate is an allowlist.

Configuration

cgh classify label and cgh classify train write findings when you run them. Classifying every file on each index is opt-in since 0.2.0:

[plugin.classify]
# scan_on_index = false  # re-classify every indexed file
# threshold = 0.7      # predict confidential above this probability
# uncertain_low = 0.35 # review window lower bound
# uncertain_high = 0.65

Your labels are the asset: they live in .codegraph/classify_labels.json, the trained model in .codegraph/classify_model.json, both machine-local and cheap to retrain (cgh classify train is instant on thousands of files).

Metadata

Release files for cgh-classify 0.2.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for cgh-classify 0.2.0
File Size Uploaded
cgh_classify-0.2.0.tar.gz 10.6 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for cgh-classify 0.2.0
File Interpreter ABI Platform
cgh_classify-0.2.0-py3-none-any.whl Python 3 none any Details

Total release size: 20.3 kB

Release files / cgh_classify-0.2.0.tar.gz

Download URL cgh_classify-0.2.0.tar.gz
Size 10.6 kB
Tags Source
SHA-256 checksum
How to use checksums
f01b1d54e0cf74e42a6143c0fe9c278b4fdbb7c1d8f9cbad3376986a56984111
BLAKE2b-256 checksum
How to use checksums
ae05cbb59d4b22be3d4eda2afaa9f92487f51b1161b754a223818b64f2aa7598
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Oct 8, 2026.

Transparency log

Release files / cgh_classify-0.2.0-py3-none-any.whl

Download URL cgh_classify-0.2.0-py3-none-any.whl
Size 9.7 kB
Tags Python 3
SHA-256 checksum
How to use checksums
cbc3e6d89c422762242b062769acd0be90c792d06d6f5161c65ada5c7e9b4796
BLAKE2b-256 checksum
How to use checksums
3861c261a9439381cd604da59adba1332494b7e05d11b00a3dc2f6a69fb25249
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Oct 8, 2026.

Transparency log

Release history Release notifications | RSS feed

This release

0.2.0 This release

2 release files

0.1.3

2 release files

0.1.2

2 release files

0.1.1

2 release files

0.1.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page