Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
361 changes: 360 additions & 1 deletion DOCS.md

Large diffs are not rendered by default.

9 changes: 6 additions & 3 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -159,7 +159,7 @@ written to disk, and never phones home. `vg serve config` lists every knob and
- **search_symbols** — find a symbol by name or literal string.
- **query_graph** — find code by meaning: symptoms, relationships, what-breaks-if.
- **get_node** — inspect one symbol: signature, callers, callees, area.
- **find_path** — shortest connection between two symbols.
- **find_path** — shortest connection between two symbols, with each hop's edge kind; `calls_only` follows calls and gives each call-site line.
- **impact_of** — blast radius of a change: dependents, files, covering tests, risk.
- **tests_for** — which tests cover a symbol.
- **get_graph_summary** — code map overview: counts, languages, top areas and hubs.
Expand All @@ -176,10 +176,11 @@ written to disk, and never phones home. `vg serve config` lists every knob and
- **library_docs** — version-correct usage docs for a library, sliced to a token budget.
- **compress_content** / **retrieve_original** / **compression_stats** (with `--compress`) — shrink a tool output before it enters the context, expand a marker back to the original or just the slice you need, and report what compression saved.
- **memory_search** / **memory_save** (with `--memory`) — project-scoped memory shared across your AI agents.
- **review_doc** (with `--review`) — write the review document for a change: open it, patch a block by id, check every pin, read the history, restore a version, and read and answer the comments people left on the pushed document in Vibgrate Cloud. Saved under `.vibgrate/review-docs/`, never in the repository.

The last two groups are listed only when you ask for them. Every advertised
The last three groups are listed only when you ask for them. Every advertised
tool schema is re-sent on every agent step, so a capability nobody enabled is a
standing cost; both groups stay callable either way.
standing cost.

Prefer the hosted server over your team's scan data? **[Vibgrate Cloud MCP](https://vibgrate.com/mcp)** connects your assistant to Vibgrate Cloud (OAuth 2.1, 51 tools).

Expand Down Expand Up @@ -768,6 +769,8 @@ All HCS computation runs in an optional, separately-licensed engine module that
| `vg scan --vulns` | Also detect known vulnerabilities (OSV; offline via `--package-manifest`) |
| `vg update` | Check for and install updates |
| `vg why <package>` | Who introduced a dependency, its version history, and any open vulnerabilities |
| `vg why <file:line>` | The commit that last changed a line, and the VG Code session that wrote it (opt in with `vg review trailer on`) |
| `vg review trailer push` | Share the VG Code sessions behind your commits with Vibgrate Cloud, so `vg why <file:line> --cloud` works for teammates |

### Workspace auth & cloud upload

Expand Down
2 changes: 1 addition & 1 deletion action.yml
Original file line number Diff line number Diff line change
Expand Up @@ -46,7 +46,7 @@ inputs:
image-tag:
description: 'Scanner image tag to run (defaults to a pinned, tested release).'
required: false
default: '2026.930.1' # vibgrate:cli-version — stamped by scripts/stamp-release-pins.mjs
default: '2026.1003.1' # vibgrate:cli-version — stamped by scripts/stamp-release-pins.mjs
verify:
description: 'Verify the image cosign signature + provenance before running (requires cosign on the runner).'
required: false
Expand Down
4 changes: 2 additions & 2 deletions charts/vibgrate/Chart.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -6,8 +6,8 @@ type: application
# independently of the CLI. appVersion pins the tested scanner image tag and is
# stamped to the released @vibgrate/cli calendar version by
# scripts/stamp-release-pins.mjs (via the marker on the appVersion line below).
version: 0.1.3
appVersion: "2026.930.1" # vibgrate:cli-version — stamped by scripts/stamp-release-pins.mjs
version: 0.1.2
appVersion: "2026.1003.1" # vibgrate:cli-version — stamped by scripts/stamp-release-pins.mjs
home: https://vibgrate.com
icon: https://vibgrate.com/web-app-manifest-512x512.png
sources:
Expand Down
2 changes: 1 addition & 1 deletion package.json
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
{
"name": "@vibgrate/cli",
"version": "2026.930.1",
"version": "2026.1003.1",
"description": "vg — local codebase intelligence CLI + MCP server for AI coding agents: deterministic code graph, drift reporting, and version-correct library docs (Apache-2.0)",
"//mcpName": "Official MCP registry ownership proof: the registry fetches the published npm package and requires this field to match the com.vibgrate/ai-context server entry (see docs/marketing/mcp-registry/README.md). Must ship in the published @vibgrate/cli package.json.",
"mcpName": "com.vibgrate/ai-context",
Expand Down
4 changes: 2 additions & 2 deletions packaging/homebrew-tap/Formula/vg.rb
Original file line number Diff line number Diff line change
Expand Up @@ -3,8 +3,8 @@
class Vg < Formula
desc "Deterministic, no-API-key code graph for AI assistants (vg)"
homepage "https://vibgrate.com"
url "https://registry.npmjs.org/@vibgrate/cli/-/cli-2026.930.1.tgz"
sha256 "b33508a85a7c9dcb06151b64c90363c15eeb03a74f7d3bd30a41e6a38af05c11"
url "https://registry.npmjs.org/@vibgrate/cli/-/cli-2026.914.1.tgz"
sha256 "21c164080d1ba33dc53d604a8754ffa0079daa9c8b771a9053c224a2c43877bf"
license "Apache-2.0"
depends_on "node"

Expand Down
2 changes: 1 addition & 1 deletion packaging/scoop-bucket/vg.json
Original file line number Diff line number Diff line change
@@ -1,5 +1,5 @@
{
"version": "2026.930.1",
"version": "2026.914.1",
"description": "Deterministic, no-API-key code graph for AI assistants (vg)",
"homepage": "https://vibgrate.com",
"license": "Apache-2.0",
Expand Down
53 changes: 53 additions & 0 deletions releases/v2026.1003.1.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,53 @@
# Vibgrate CLI 2026.1003.1

_Released 2026-10-03_

This release of Vibgrate CLI introduces several new features and improvements focused on enhancing the review process and collaboration among team members. Key updates include improved visibility of code sessions, enhanced document generation capabilities, and better handling of review comments.

## What changed

### New

- Teammates can now see which VG Code session wrote a line, even when it ran on another machine.
- `vg review trailer push` uploads sessions named by `Vibgrate-Session` trailers on unpushed commits.
- `vg why <file:line> --cloud` retrieves session information from Vibgrate Cloud.
- `vg serve --review` allows agents to write review documents with new operations.
- `vg review doc --comments` lists comments on the pushed review document.
- `vg review doc` now shows the data a change reads and writes based on the repository's data model.
- `vg review doc --also ../client` allows changes across repositories to be included in one review document.
- `vg review doc --push` uploads the review document to Vibgrate Cloud for GitHub App integration.
- `vg review doc --session <id>` generates a review document for a specific VG Code chat.
- `vg show <name> --diagram` provides a visual explanation of code with pinned diagrams.

### Fixed

- `vg init` now correctly suggests `vg scan` and `vg baseline` as next commands.
- `vg review` no longer lists renamed files multiple times.

## Benchmarks

Two-arm benchmark of this release against 2026.930.1, interleaved on one runner against the pinned corpus (236 metrics compared).

| Metric | Previous | This release |
| --- | --- | --- |
| Languages with extraction | 19 count | 19 count |
| Definitions extracted (corpus total) | 26227 count | 26227 count |
| Call edges extracted (corpus total) | 18264 count | 18264 count |
| Locate accuracy (top-1) | 0.94 ratio | 0.94 ratio |
| Dependency detection (authored manifest truth) | 0.96 ratio | 0.96 ratio |
| CLI startup (--version, median) | 622 ms | 624.50 ms |

2 regression(s) — published, not omitted:
- Tasks passed on both arms: 36 → 34 (-5.6%)
- Comparable-task rate (both arms passed / total): 0.95 → 0.89 (-5.6%)

Full report and methodology: https://vibgrate.com/cli/benchmarks

## Install or update

```sh
npm install -g @vibgrate/cli
vg
```

Full changelog: https://vibgrate.com/changelog/cli/2026.1003.1
33 changes: 26 additions & 7 deletions src/commands/path.ts
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
import { Command } from 'commander';
import { resolveOne } from '../engine/lookup.js';
import { pathDisconnect, shortestPath } from '../engine/paths.js';
import { callPath, describeHops, pathDisconnect, shortestPath } from '../engine/paths.js';
import { recordCliCall, CLI_TOOL_ALIASES } from '../engine/savings.js';
import { applyGlobalOptions, readGlobal } from '../cli-options.js';
import { requireGraph, rootOf } from './util.js';
Expand All @@ -14,12 +14,13 @@ import { c, info, json } from '../util/output.js';
export function registerPath(program: Command): void {
const cmd = program
.command('path')
.description('how A connects to B (shortest path)')
.description('how A connects to B (shortest path; --calls follows call edges only)')
.argument('<a>', 'source node')
.argument('<b>', 'target node')
.option('--pick-a <n>', 'pick the nth candidate for A when ambiguous')
.option('--pick-b <n>', 'pick the nth candidate for B when ambiguous')
.action(function (this: Command, a: string, b: string, opts: { pickA?: string; pickB?: string }) {
.option('--calls', 'follow call edges only, and show the call-site line of each hop')
.action(function (this: Command, a: string, b: string, opts: { pickA?: string; pickB?: string; calls?: boolean }) {
const global = readGlobal(this);
const { graph } = requireGraph(global);

Expand All @@ -28,7 +29,7 @@ export function registerPath(program: Command): void {
const rb = resolveOne(graph, b, opts.pickB ? Number(opts.pickB) : undefined);
if (!rb.node) throw ambiguityError(`"${b}" ${rb.candidates.length ? 'is ambiguous' : 'not found'}`, rb.candidates, '--pick-b');

const result = shortestPath(graph, ra.node.id, rb.node.id);
const result = opts.calls ? callPath(graph, ra.node.id, rb.node.id) : shortestPath(graph, ra.node.id, rb.node.id);
// Record the call for the command-vs-MCP split when an AI identified itself
// (before the not-found throw, so a no-path attempt is counted as a miss).
if (global.client) {
Expand Down Expand Up @@ -62,14 +63,32 @@ export function registerPath(program: Command): void {

const byId = new Map(graph.nodes.map((n) => [n.id, n] as const));
const names = result.ids.map((id) => byId.get(id)?.qualifiedName ?? id);
const steps = describeHops(graph, result.ids, result.direction);

if (global.json) {
json({ from: ra.node.qualifiedName, to: rb.node.qualifiedName, hops: names.length - 1, direction: result.direction, path: names });
json({
from: ra.node.qualifiedName,
to: rb.node.qualifiedName,
hops: names.length - 1,
direction: result.direction,
path: names,
steps,
...(opts.calls ? { callsOnly: true } : {}),
});
return;
}

info(`${c.cyan('vg path')} · ${names.length - 1} hop(s)${result.direction === 'reverse' ? c.dim(' (reverse)') : ''}`);
info(' ' + names.map((n) => c.bold(n)).join(c.dim(' → ')));
info(`${c.cyan('vg path')} · ${names.length - 1} hop(s)${opts.calls ? c.dim(' · calls only') : ''}${result.direction === 'reverse' ? c.dim(' (reverse)') : ''}`);
if (!opts.calls) {
info(' ' + names.map((n) => c.bold(n)).join(c.dim(' → ')));
return;
}
info(` ${c.bold(names[0])}`);
for (const s of steps) {
const where = s.line ? ` ${s.file ?? ''}:${s.line}` : '';
const how = [s.awaited ? 'awaited' : null, s.resolution].filter(Boolean).join(', ');
info(` ${c.dim('→')} ${c.bold(s.to)}${c.dim(` ${s.kind}${where} · ${how}`)}`);
}
});
applyGlobalOptions(cmd);
}
Expand Down
Loading
Loading