Skip to main content

Code Property Graph

PyPI version License: MIT

Code Property Graphs — Joern/Semgrep extraction, AI vulnerability enrichment, risk scoring.

This package depends on AWS GraphRAG Toolkit (graphrag-toolkit-lexical-graph) for graph storage, vector indexing, and retrieval.

Installation

pip install graphrag-codeproperty-graph

Dependencies

  • graphrag-document-graph>=3.1.1 — Document graph infrastructure (typed nodes, Cypher builders, multi-tenancy)
  • boto3>=1.28.0 — AWS SDK for S3 manifest storage and service integrations

Dependency Chain

graphrag-codeproperty-graph
└── graphrag-document-graph>=3.0.8
    └── graphrag-toolkit-lexical-graph>=3.18.0  (AWS foundation)
        ├── Neptune graph storage
        ├── OpenSearch Serverless vector indexing
        └── Entity resolution & retrieval

Quick Start

from codeproperty_graph import CPGService

# Only writes changed/added method subtrees to Neptune
service = CPGService(bucket="graphrag-artifacts-705909755305")

result = await service.ingest(
    repo="my-service",
    job_id="build-456",
    tenant_id="tenant_abc123",
    nodes_data=joern_nodes,
    edges_data=joern_edges,
    nodes_path="s3://bucket/cpg-exports/my-service/build-456/nodes.json",
    edges_path="s3://bucket/cpg-exports/my-service/build-456/edges.json",
    graph_store=neptune_store,
    write_fn=batch_write_function,
    remove_fn=remove_method_subgraph,  # optional: surgical deletion
)

# result: {"status": "SKIPPED"} — no changes
# result: {"status": "INGESTED", "delta": "+5 -2 ~3 =150",
#           "filtered_nodes": 47, "total_nodes": 5123}

DeltaIngestor — Full Artifact Pipeline

from codeproperty_graph import DeltaIngestor

# Full pipeline: graph + vectors + summaries + code slices
ingestor = DeltaIngestor(bucket="graphrag-artifacts-705909755305")

result = await ingestor.ingest(
    repo="my-service",
    job_id="build-456",
    tenant_id="tenant_abc123",
    nodes_data=joern_nodes,
    edges_data=joern_edges,
    nodes_path="s3://bucket/cpg-exports/my-service/build-456/nodes.json",
    edges_path="s3://bucket/cpg-exports/my-service/build-456/edges.json",
    graph_store=neptune_store,
    write_fn=batch_write_function,
)

# result: {"status": "SKIPPED"} or {"status": "INGESTED", "delta": "+5 -2 ~3 =150"}

Graph Diff — Compare CPG States

from codeproperty_graph import GraphDiff, CPGNode

# Compare current vs previous code analysis
diff = GraphDiff.compare(
    current_nodes=current_cpg_nodes,
    previous_nodes=previous_cpg_nodes,
)

print(f"Added: {len(diff.added)}")
print(f"Removed: {len(diff.removed)}")
print(f"Modified: {len(diff.modified)}")
print(f"Unchanged: {len(diff.unchanged)}")

Manifest Management

from codeproperty_graph import ManifestManager

# Track CPG state per repository in S3
manager = ManifestManager(bucket="graphrag-artifacts-705909755305")

# Save manifest after successful ingestion
await manager.save(repo="my-service", job_id="build-456", signatures=method_signatures)

# Load previous manifest for diff comparison
previous = await manager.load(repo="my-service")

Package Structure

src/codeproperty_graph/
├── __init__.py           # Public API (30 exports)
├── models.py             # CPGNode, CPGEdge, Manifest, VectorRecord, SummaryRecord, CodeSliceRecord
├── schema.py             # Full Joern CPG schema (20 node types, 14 edge types)
├── graph_diff.py         # Compare two CPG states by method signature
├── manifest_manager.py   # S3-backed state tracking with optimistic locking
├── delta_ingestor.py     # Full artifact pipeline orchestration
├── cpg_service.py        # Node-level delta filtering (only write changed methods)
├── tenant_ops.py         # Lifecycle management (delete_tenant, delete_domain)
├── artifact_reader.py    # S3 artifact reading and parsing
├── artifact_validator.py # Schema compliance validation
├── graph_loader.py       # Neptune batch write with retry cascade
├── vector_loader.py      # OpenSearch Serverless vector ingestion
├── summary_overlay.py    # LLM summaries → Neptune node properties
├── code_slice_store.py   # Source evidence → Neptune node properties
└── graphson_converter.py # GraphSON format conversion

Integration

Architecture Stack

┌─────────────────────────────────────────────────────┐
│         codeproperty-graph (this package)            │
│  Joern/Semgrep CPG, delta ingestion, risk scoring   │
├─────────────────────────────────────────────────────┤
│              document-graph                          │
│  Node, Edge, CypherBuilder, PipelineExecutor        │
│  Multi-tenancy, batch operations                    │
├─────────────────────────────────────────────────────┤
│     graphrag-toolkit-lexical-graph (foundation)     │
│  GraphStore, Neptune writer, AOSS writer            │
│  Lexical indexing, entity resolution, retrieval     │
└─────────────────────────────────────────────────────┘

Delta Logic

  1. Joern exports CPG → nodes.json + edges.json
  2. Extract METHOD node signatures: {full_name: hash}
  3. Compare against previous manifest in S3
  4. If identical → SKIP (no Neptune writes, saves cost)
  5. If changed → CPGService filters to changed methods only:
    • Identify added/modified METHOD nodes via GraphDiff.compare()
    • Walk AST edges to collect child nodes of changed methods
    • Filter edges to changed subgraph
    • Write only the delta (60-90% fewer Neptune writes)
    • Surgically remove deleted method subgraphs
    • Update manifest with full current state

With Document Graph

Code Property Graph uses document-graph for typed property graph primitives:

# document-graph provides the graph write infrastructure
from graphrag_toolkit.document_graph.graph_build.cypher_builder import CypherBuilder
from graphrag_toolkit.document_graph import Node, Edge

# codeproperty-graph adds CPG-specific semantics on top
from codeproperty_graph import CPGNode, CPGEdge

Contributing

See CONTRIBUTING.md for development setup, testing, and PR guidelines.

License

MIT — see LICENSE for details.

See NOTICE for third-party acknowledgments.

Metadata

Release files for graphrag-codeproperty-graph 0.5.2

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for graphrag-codeproperty-graph 0.5.2
File Size Uploaded
graphrag_codeproperty_graph-0.5.2.tar.gz 81.6 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for graphrag-codeproperty-graph 0.5.2
File Interpreter ABI Platform
graphrag_codeproperty_graph-0.5.2-py3-none-any.whl Python 3 none any Details

Total release size: 123.3 kB

Release files / graphrag_codeproperty_graph-0.5.2.tar.gz

Download URL graphrag_codeproperty_graph-0.5.2.tar.gz
Size 81.6 kB
Tags Source
SHA-256 checksum
How to use checksums
2dc7eaf8c480dfa67229609cf47ef4032dc2c50977da5fe055e9dbd374a166eb
BLAKE2b-256 checksum
How to use checksums
12ee7321c087d0b4a26d311d83fcca2bacbcd5ebcf6eeeacb4f392f3ae7ddcba
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.13.14

Release files / graphrag_codeproperty_graph-0.5.2-py3-none-any.whl

Download URL graphrag_codeproperty_graph-0.5.2-py3-none-any.whl
Size 41.7 kB
Tags Python 3
SHA-256 checksum
How to use checksums
038ffa9ebe8bcef16b42e4afa003d60b69d97540b1dc61cec53b6f2e890636eb
BLAKE2b-256 checksum
How to use checksums
09888ce997df5fcd876d4c905c30ca07e73f99d9aaab2792cfc9a21fce20a1d4
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.13.14

Release history Release notifications | RSS feed

0.5.3

2 release files

This release

0.5.2 This release

2 release files

0.5.1

2 release files

0.5.0

2 release files

0.4.5

2 release files

0.4.4

2 release files

0.4.3

2 release files

0.1.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page