cgh-classify
Frozen. 0.2.0 is the final release. Its main consumers, the core egress gate's confidentiality labels and the guard, went away with secure mode in cgh 0.15.0, and
cgh[plugins]no longer installs it. It still works and still installs by name (pip install cgh-classify), gets no new features, and may be removed from the cgh repository later. cgh-codegen's egress gate still honors aconfidentialfinding when one exists.
Human-trainable confidentiality classification for
cgh. You label a few files, a
lightweight local model (TF-IDF + naive Bayes, standard library only)
generalizes to the rest, and the result lands as confidential
findings. Nothing ever leaves the machine.
pip install cgh-classify
cgh classify label payroll.xlsx # mark confidential
cgh classify label README.md --not # mark public
cgh classify train # fit + sweep the repo
cgh classify review # files the model is unsure about
cgh findings --key confidential
How labels and predictions interact
| Source | Finding written | Effect on an egress gate (cgh-codegen) |
|---|---|---|
| Human label, confidential | confidential = true (block) |
blocked everywhere |
| Human label, public | confidential = false |
allowlisted, including strict mode |
| Model prediction, confidential | confidential = true (block) |
blocked everywhere |
| Model prediction, public | confidential.predicted = false |
no effect |
The asymmetry is deliberate: a model may block on its own say-so
(worst case, a false positive costs a summary), but only a human label
can clear a file under a strict egress gate (egress = "strict"),
where the gate is an allowlist.
Configuration
cgh classify label and cgh classify train write findings when you
run them. Classifying every file on each index is opt-in since 0.2.0:
[plugin.classify]
# scan_on_index = false # re-classify every indexed file
# threshold = 0.7 # predict confidential above this probability
# uncertain_low = 0.35 # review window lower bound
# uncertain_high = 0.65
Your labels are the asset: they live in
.codegraph/classify_labels.json, the trained model in
.codegraph/classify_model.json, both machine-local and cheap to
retrain (cgh classify train is instant on thousands of files).
Metadata
Release files for cgh-classify 0.2.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| cgh_classify-0.2.0.tar.gz | 10.6 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| cgh_classify-0.2.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 20.3 kB
Release files / cgh_classify-0.2.0.tar.gz
| Download URL | cgh_classify-0.2.0.tar.gz |
|---|---|
| Size | 10.6 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
f01b1d54e0cf74e42a6143c0fe9c278b4fdbb7c1d8f9cbad3376986a56984111
|
|
BLAKE2b-256 checksum How to use checksums |
ae05cbb59d4b22be3d4eda2afaa9f92487f51b1161b754a223818b64f2aa7598
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Oct 8, 2026.
Transparency logRelease files / cgh_classify-0.2.0-py3-none-any.whl
| Download URL | cgh_classify-0.2.0-py3-none-any.whl |
|---|---|
| Size | 9.7 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
cbc3e6d89c422762242b062769acd0be90c792d06d6f5161c65ada5c7e9b4796
|
|
BLAKE2b-256 checksum How to use checksums |
3861c261a9439381cd604da59adba1332494b7e05d11b00a3dc2f6a69fb25249
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Oct 8, 2026.
Transparency log