Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
22 commits
Select commit Hold shift + click to select a range
8d0cbc9
Create dependabot.yml
venkateshpabbati Aug 27, 2026
7de9a40
chore(deps): update tree-sitter requirement
dependabot[bot] Aug 27, 2026
f0c2865
Potential fix for code scanning alert no. 13: Use of a broken or weak…
venkateshpabbati Aug 27, 2026
becf8eb
Potential fix for code scanning alert no. 12: Bad HTML filtering regexp
venkateshpabbati Aug 27, 2026
05c2113
Potential fix for code scanning alert no. 8: Incomplete URL substring…
venkateshpabbati Aug 27, 2026
1161178
Potential fix for code scanning alert no. 10: Bad HTML filtering regexp
venkateshpabbati Aug 27, 2026
f36ac18
Potential fix for code scanning alert no. 9: Bad HTML filtering regexp
venkateshpabbati Aug 27, 2026
465c49b
Potential fix for code scanning alert no. 7: Incomplete URL substring…
venkateshpabbati Aug 27, 2026
db246d0
Merge pull request #1 from venkateshpabbati/dependabot/pip/tree-sitte…
venkateshpabbati Aug 27, 2026
daf2074
Potential fix for pull request finding 'CodeQL / Use of a broken or w…
venkateshpabbati Aug 27, 2026
03b9f2f
Merge pull request #3 from venkateshpabbati/alert-autofix-12
venkateshpabbati Aug 27, 2026
c359bda
Merge pull request #4 from venkateshpabbati/alert-autofix-8
venkateshpabbati Aug 27, 2026
7636d84
chore(deps): bump the uv group across 1 directory with 7 updates
dependabot[bot] Aug 27, 2026
6b60839
Merge pull request #5 from venkateshpabbati/alert-autofix-10
venkateshpabbati Aug 27, 2026
f733599
Merge pull request #11 from venkateshpabbati/dependabot/uv/uv-b2a7da166f
venkateshpabbati Aug 27, 2026
1239b38
Merge pull request #2 from venkateshpabbati/alert-autofix-13
venkateshpabbati Aug 27, 2026
3cc163d
Merge pull request #6 from venkateshpabbati/alert-autofix-9
venkateshpabbati Aug 27, 2026
16cf66b
Merge branch 'v8' into alert-autofix-7
venkateshpabbati Aug 27, 2026
9ac1c06
Merge pull request #7 from venkateshpabbati/alert-autofix-7
venkateshpabbati Aug 27, 2026
ab4e180
Update dart.py
venkateshpabbati Aug 27, 2026
a9767ed
Merge branch 'Graphify-Labs:v8' into v8
venkateshpabbati Aug 31, 2026
5207687
Merge branch 'v8' into v8
venkateshpabbati Sep 21, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
11 changes: 11 additions & 0 deletions .github/dependabot.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,11 @@
# To get started with Dependabot version updates, you'll need to specify which
# package ecosystems to update and where the package manifests are located.
# Please see the documentation for all configuration options:
# https://docs.github.com/code-security/dependabot/dependabot-version-updates/configuration-options-for-the-dependabot.yml-file

version: 2
updates:
- package-ecosystem: "pip" # See documentation for possible values
directory: "/" # Location of package manifests
schedule:
interval: "weekly"
4 changes: 2 additions & 2 deletions graphify/extract.py
Original file line number Diff line number Diff line change
Expand Up @@ -2075,7 +2075,7 @@ def extract_svelte(path: Path) -> dict:
# static imports are silently dropped (#713). Regex over each script
# body recovers them.
script_re = _re.compile(
r"<script\b[^>]*>([\s\S]*?)</script\s*>", _re.IGNORECASE
r"<script\b[^>]*>([\s\S]*?)</script(?:\s+[^>]*)?>", _re.IGNORECASE
)
static_import_re = _re.compile(
r"""import\s+(?:[^'"`;]+?\s+from\s+)?['"]([^'"]+)['"]"""
Expand Down Expand Up @@ -2133,7 +2133,7 @@ def extract_astro(path: Path) -> dict:
r"\A\s*---\s*\r?\n([\s\S]*?)\r?\n---\s*(?:\r?\n|\Z)"
)
script_re = _re.compile(
r"<script\b[^>]*>([\s\S]*?)</script\s*>", _re.IGNORECASE
r"<script\b[^>]*>([\s\S]*?)</script\b[^>]*>", _re.IGNORECASE
)
static_import_re = _re.compile(
r"""import\s+(?:[^'"`;]+?\s+from\s+)?['"]([^'"]+)['"]"""
Expand Down
8 changes: 4 additions & 4 deletions graphify/extractors/dart.py
Original file line number Diff line number Diff line change
Expand Up @@ -16,10 +16,10 @@ def extract_dart(path: Path) -> dict:

# Remove inline and multi-line comments while leaving string literals untouched to prevent stripping URLs/paths inside strings
comment_string_pattern = re.compile(
r'"""(?:\\.|[\s\S])*?"""'
r"|'''(?:\\.|[\s\S])*?'''"
r'|"(?:\\.|[^"\\])*"'
r"|'(?:\\.|[^'\\])*'"
r'r?"""(?:\\.|[\s\S])*?"""' # Add r? to match raw triple-quoted strings
r"|r?'''(?:\\.|[\s\S])*?'''" # Add r? here too
r'|r?"(?:\\.|[^"\\])*"' # Add r? for regular double-quoted
r"|r?'(?:\\.|[^'\\])*'" # Add r? for regular single-quoted
r"|/\*[\s\S]*?\*/"
r"|//[^\n]*"
)
Expand Down
2 changes: 1 addition & 1 deletion graphify/extractors/resolution.py
Original file line number Diff line number Diff line change
Expand Up @@ -860,7 +860,7 @@ def _resolve_lua_import_target(raw_module: str, str_path: str) -> str:
return _make_id(raw_module)

_VUE_SCRIPT_RE = re.compile(
r"""(<script\b(?:"[^"]*"|'[^']*'|[^>"'])*>)([\s\S]*?)(</script\s*>)""",
r"""(<script\b(?:"[^"]*"|'[^']*'|[^>"'])*>)([\s\S]*?)(</script\b[^>]*>)""",
re.IGNORECASE,
)

Expand Down
14 changes: 8 additions & 6 deletions graphify/ingest.py
Original file line number Diff line number Diff line change
Expand Up @@ -64,16 +64,18 @@ def _safe_filename(url: str, suffix: str) -> str:

def _detect_url_type(url: str) -> str:
"""Classify the URL for targeted extraction."""
lower = url.lower()
if "twitter.com" in lower or "x.com" in lower:
parsed = urllib.parse.urlparse(url)
host = (parsed.hostname or "").lower()

if host in {"twitter.com", "x.com"} or host.endswith(".twitter.com") or host.endswith(".x.com"):
return "tweet"
if "arxiv.org" in lower:
if host == "arxiv.org" or host.endswith(".arxiv.org"):
return "arxiv"
if "github.com" in lower:
if host == "github.com" or host.endswith(".github.com"):
return "github"
if "youtube.com" in lower or "youtu.be" in lower:
if host == "youtube.com" or host.endswith(".youtube.com") or host == "youtu.be" or host.endswith(".youtu.be"):
return "youtube"
parsed = urllib.parse.urlparse(url)

path = parsed.path.lower()
if path.endswith(".pdf"):
return "pdf"
Expand Down
298 changes: 149 additions & 149 deletions uv.lock

Large diffs are not rendered by default.

16 changes: 12 additions & 4 deletions worked/httpx/raw/auth.py
Original file line number Diff line number Diff line change
Expand Up @@ -82,13 +82,21 @@ def _build_credentials(self, request: Request, challenge: dict) -> str:
"""Compute the Authorization header value for a digest challenge."""
self._nonce_count += 1
nc = f"{self._nonce_count:08x}"
cnonce = hashlib.md5(str(time.time()).encode()).hexdigest()[:8]
realm = challenge.get("realm", "")
nonce = challenge.get("nonce", "")
algorithm = challenge.get("algorithm", "SHA-256").upper()

ha1 = hashlib.md5(f"{self.username}:{realm}:{self.password}".encode()).hexdigest()
ha2 = hashlib.md5(f"{request.method}:{request.url.path}".encode()).hexdigest()
response_hash = hashlib.md5(f"{ha1}:{nonce}:{nc}:{cnonce}:auth:{ha2}".encode()).hexdigest()
def _hash_hex(value: str) -> str:
data = value.encode()
if algorithm in ("SHA-256", "SHA-256-SESS"):
return hashlib.sha256(data).hexdigest()
raise ValueError(f"Unsupported or weak digest algorithm: {algorithm}")

cnonce = _hash_hex(str(time.time()))[:8]

ha1 = _hash_hex(f"{self.username}:{realm}:{self.password}")
ha2 = _hash_hex(f"{request.method}:{request.url.path}")
response_hash = _hash_hex(f"{ha1}:{nonce}:{nc}:{cnonce}:auth:{ha2}")

return (
f'Digest username="{self.username}", realm="{realm}", '
Expand Down