docs(changelog): present 0.8.49 changes directly (drop internal packaging note)

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
safishamsi
2026-06-25 10:24:58 +01:00
co-authored by Claude Opus 4.8
parent 6d3c9594e3
commit e4ff54f4e0
-4
View File
@@ -6,10 +6,6 @@ Full release notes with details on each version: [GitHub Releases](https://githu
## 0.8.49 (2026-06-24)
- Fix (packaging): include the new `graphify.extractors` subpackage in the wheel. 0.8.48 added `graphify/extractors/` (the per-language extractor split, #1212) but `[tool.setuptools] packages` listed only `graphify`, so the subpackage was omitted from the built distribution and `graphify extract` raised `ModuleNotFoundError: No module named 'graphify.extractors'` on install. Dev/editable installs and the test suite were unaffected (they import from the source tree), which is why it slipped through. 0.8.48 is yanked; use 0.8.49.
## 0.8.48 (2026-06-24)
- Fix: the `get_community` MCP tool now shows the community name in its header (`Community 12 — Auth & Sessions (8 nodes)`), matching `get_node` and the query-traversal output, which already read the `community_name` attribute `to_json` writes onto every node. `get_community` was the only graph tool still returning a bare numeric id. The name is read from the community's member nodes (they share it), sanitised like every other LLM-derived field, and skipped when it is just the `Community N` placeholder so the header never doubles to `Community 12 — Community 12` (#1448, thanks @rmart1308).
- Security: floor `starlette` at `>=1.3.1` to pick up the fixes for CVE-2026-48818 and CVE-2026-54283 (both resolved by 1.3.1). starlette underpins the HTTP MCP transport (`graphify-mcp` over HTTP / `serve_http`); the stdio transport and CLI are unaffected. It was an undeclared transitive dependency (via `mcp`) that `graphify/serve.py` imports directly, so it is now declared in the `mcp` (and `all`) extras and floored, which protects end users installing `graphifyy[mcp]`, not just the locked dev/CI environment. Lockfile bumped 1.0.0 -> 1.3.1; serve/MCP/HTTP tests pass on the new version (#1391, #1396, thanks @orbisai0security).
- Refactor: begin splitting the monolithic `extract.py` into per-language modules under `graphify/extractors/` (#1212). The `blade`, `elixir`, `razor`, and `zig` extractors plus the shared primitives (`_make_id`, `_file_stem`, `_read_text`, `_LANGUAGE_BUILTIN_GLOBALS`) move into their own files, with `graphify/extractors/base.py` holding the shared pieces and a strict one-way import direction (`extract.py` -> `extractors/`, never the reverse). `extract.py` re-exports the moved names, so every `from graphify.extract import ...` caller and the dispatch table are unchanged. Behavior-neutral lift-and-shift (verified byte-identical), groundwork for moving the remaining languages out. See `graphify/extractors/MIGRATION.md`.