Skip to main content

Code Property Graph

PyPI version License: MIT

Code Property Graphs — Joern/Semgrep extraction, AI vulnerability enrichment, risk scoring.

This package depends on AWS GraphRAG Toolkit (graphrag-toolkit-lexical-graph) for graph storage, vector indexing, and retrieval.

Installation

pip install graphrag-codeproperty-graph

Dependencies

  • graphrag-document-graph>=3.0.8 — Document graph infrastructure (typed nodes, Cypher builders, multi-tenancy)

This package does not depend on bona.

Dependency Chain

graphrag-codeproperty-graph
└── graphrag-document-graph>=3.0.8
    └── graphrag-toolkit-lexical-graph>=3.18.0  (AWS foundation)
        ├── Neptune graph storage
        ├── OpenSearch Serverless vector indexing
        └── Entity resolution & retrieval

Quick Start

Python API Example

from codeproperty_graph import DeltaIngestor, CPGNode, CPGEdge, GraphDiff

# Delta ingestion — only writes to Neptune when code actually changed
ingestor = DeltaIngestor(bucket="graphrag-artifacts-705909755305")

result = await ingestor.ingest(
    repo="my-service",
    job_id="build-456",
    tenant_id="tenant_abc123",
    nodes_data=joern_nodes,
    edges_data=joern_edges,
    nodes_path="s3://bucket/cpg-exports/my-service/build-456/nodes.json",
    edges_path="s3://bucket/cpg-exports/my-service/build-456/edges.json",
    graph_store=neptune_store,
    write_fn=batch_write_function,
)

# result: {"status": "SKIPPED"} or {"status": "INGESTED", "delta": "+5 -2 ~3 =150"}

Graph Diff — Compare CPG States

from codeproperty_graph import GraphDiff, CPGNode

# Compare current vs previous code analysis
diff = GraphDiff.compare(
    current_nodes=current_cpg_nodes,
    previous_nodes=previous_cpg_nodes,
)

print(f"Added: {len(diff.added)}")
print(f"Removed: {len(diff.removed)}")
print(f"Modified: {len(diff.modified)}")
print(f"Unchanged: {len(diff.unchanged)}")

Manifest Management

from codeproperty_graph import ManifestManager

# Track CPG state per repository in S3
manager = ManifestManager(bucket="graphrag-artifacts-705909755305")

# Save manifest after successful ingestion
await manager.save(repo="my-service", job_id="build-456", signatures=method_signatures)

# Load previous manifest for diff comparison
previous = await manager.load(repo="my-service")

Package Structure

src/codeproperty_graph/
├── __init__.py           # Public API: CPGNode, CPGEdge, DeltaIngestor, etc.
├── models.py             # CPGNode, CPGEdge, Manifest — Joern-specific types
├── graph_diff.py         # Compare two CPG states by method signature
├── manifest_manager.py   # S3-backed state tracking per repository
├── delta_ingestor.py     # Skip-or-replace orchestration with tenant purge
└── tenant_ops.py         # Clean lifecycle management (delete_tenant)

Integration

Architecture Stack

┌─────────────────────────────────────────────────────┐
│         codeproperty-graph (this package)            │
│  Joern/Semgrep CPG, delta ingestion, risk scoring   │
├─────────────────────────────────────────────────────┤
│              document-graph                          │
│  Node, Edge, CypherBuilder, PipelineExecutor        │
│  Multi-tenancy, batch operations                    │
├─────────────────────────────────────────────────────┤
│     graphrag-toolkit-lexical-graph (foundation)     │
│  GraphStore, Neptune writer, AOSS writer            │
│  Lexical indexing, entity resolution, retrieval     │
└─────────────────────────────────────────────────────┘

Delta Logic

  1. Joern exports CPG → nodes.json + edges.json
  2. Extract METHOD node signatures: {full_name: hash}
  3. Compare against previous manifest in S3
  4. If identical → SKIP (no Neptune writes, saves cost)
  5. If changed → INGEST full graph under new tenant, purge old tenant, update manifest

With Document Graph

Code Property Graph uses document-graph for typed property graph primitives:

# document-graph provides the graph write infrastructure
from graphrag_toolkit.document_graph.graph_build.cypher_builder import CypherBuilder
from graphrag_toolkit.document_graph import Node, Edge

# codeproperty-graph adds CPG-specific semantics on top
from codeproperty_graph import CPGNode, CPGEdge

Contributing

See CONTRIBUTING.md for development setup, testing, and PR guidelines.

License

MIT — see LICENSE for details.

See NOTICE for third-party acknowledgments.

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

graphrag_codeproperty_graph-0.5.0.tar.gz (77.9 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

graphrag_codeproperty_graph-0.5.0-py3-none-any.whl (40.8 kB view details)

Uploaded Python 3

File details

Details for the file graphrag_codeproperty_graph-0.5.0.tar.gz.

File metadata

File hashes

Hashes for graphrag_codeproperty_graph-0.5.0.tar.gz
Algorithm Hash digest
SHA256 c023ebcea8abe0a62deeb12f823f6b555c093aa5d3617dd73d7792a5810c1796
MD5 fb0135e363bbef38c34e8a0a03406f36
BLAKE2b-256 aa408ad8dd8cd3c0ea9118dc767d858a7a84966ca3a3effd66e9958dbab4ae83

See more details on using hashes here.

File details

Details for the file graphrag_codeproperty_graph-0.5.0-py3-none-any.whl.

File metadata

File hashes

Hashes for graphrag_codeproperty_graph-0.5.0-py3-none-any.whl
Algorithm Hash digest
SHA256 cc05c34b22ebf8e39cef8da6d2c2b306b4c96a40ea07e5b8d4991903af505c56
MD5 d5eed3d63ae7e70049e6dd896a81786f
BLAKE2b-256 18e1b3ab3d8ea894fb599b69fdab3888abaa27a874c3f518825b46c721eb28ef

See more details on using hashes here.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page