Graphify Release Notes (v8): Critical Fixes, Security Updates, and Platform Support (0.9.15–0.9.20)
Graphify v8 versions 0.9.15 through 0.9.20 introduce strict PreToolUse hooks for AI safety, atomic JSON writes for crash resilience, semantic-cache anchoring fixes, and Amp platform support, while hardening security with query-log opt-in and Windows path handling.
The Graphify release notes for the v8 branch detail rapid iteration on the knowledge-graph engine maintained at Graphify-Labs/graphify. Spanning from July 13 to July 18, 2026, these six patch releases focus on AI assistant integration safety, deterministic graph extraction via tree-sitter ASTs, and cross-platform stability. All changes are documented in the repository’s [CHANGELOG.md](https://github.com/Graphify-Labs/graphify/blob/v8/CHANGELOG.md).
Version 0.9.20 (2026-07-18): Critical Hook and Cache Fixes
PreToolUse Hook Integration with Grep Tool
The PreToolUse hook now nudges on the Grep tool in addition to Bash [#1986]. This ensures Claude Code’s search guard works correctly with the newer Grep tool implementation, preventing unauthorized raw reads during AI-assisted coding sessions.
Windows Path Handling
Forward-slashes are now forced in the resolved Graphify binary path, fixing Git Bash escaping issues on Windows [#1987]. This resolves command-not-found errors when running graphify from Windows terminals.
Semantic Cache Anchoring
Cache entries now key on the scan root and write into the proper output directory [#1990–#1991]. This fixes a bug where semantic-cache writes would anchor incorrectly, causing cache misses or writes to wrong directories.
Alias-Based Re-Export Fixes
Alias-based re-exports no longer emit dangling absolute-path symbol targets [#1983]. This prevents broken graph edges when modules use re-export aliases.
Version 0.9.19 (2026-07-18): Strict Hook and Guard Improvements
Strict PreToolUse Hook Mode
A strict PreToolUse hook blocks the first raw read of a session instead of merely nudging [#1840]. Enable this via the --strict flag during install or toggle at runtime:
graphify install --project --strict
export GRAPHIFY_HOOK_STRICT=1 # enable blocking
export GRAPHIFY_HOOK_STRICT=0 # disable (soft nudge)
Hook Guard Context Awareness
The hook guard now respects out-of-tree files and stale graphs, softening to a nudge when appropriate [#1840]. This reduces false positives when working with files outside the current scan root.
Cross-Extension Self-Cycle Prevention
Fixed cross-extension re-export self-cycles that could cause infinite loops during graph construction [#1814].
Enhanced File-Hash Memoization
File-hash memoization now includes path salt [#1989], preventing collisions when identical file contents exist at different paths.
Improved Ignore Patterns
The --no-gitignore flag now respects .graphifyignore [#1971], and glob matching semantics were improved to use * per-segment [#1975].
Version 0.9.18 (2026-07-17): Extraction Robustness
Partial Extraction Protection
Partial extraction no longer overwrites a larger graph unless explicitly requested [#1951]. Users must now pass --allow-partial to force a partial update, preventing accidental data loss during interrupted scans.
Atomic JSON Writes
All JSON artifacts now use atomic writes [#1952], eliminating truncated files on crashes. The engine writes to a temporary file before moving it to graphify-out/graph.json.
Partial LLM Chunk Marking
Partial LLM chunks are now marked "partial" [#1950] to avoid caching incomplete results during interrupted semantic extraction.
Semantic Cache Validation
Added validation for the semantic cache [#1953]; malformed chunks are skipped rather than causing fatal errors.
Unverified Node Flagging
Unverified code-typed nodes are now flagged [#1949], improving confidence scoring in the knowledge graph.
Watch Mode Deduplication
Watch/update operations no longer duplicate semantic documents [#1954], reducing graph bloat during iterative development.
Version 0.9.17 (2026-07-16): Platform and Language Support
Amp Platform Support
Added Amp platform support with skill and install wiring [#948], expanding Graphify’s compatibility to Amp-based AI assistants.
Manifest.json Handling
Fixed a bug where --code-only caused a full scan instead of respecting the manifest [#1925].
Hyperedge Stamping
Hyperedges are now recorded in the manifest [#1920] to avoid redundant re-extraction during incremental updates.
PHP Namespace-Aware Re-Exports
Improved handling of PHP namespace-aware re-exports [#1923], ensuring accurate symbol resolution in PHP codebases.
Language-Specific Fixes
Recognizes .cjs files as code [#1912] and improves diagnostics for ignored files [#1922].
Version 0.9.16 (2026-07-14): Stability and Compatibility
Extraction Reconciliation
Semantic extraction now reconciles dispatched versus returned files [#1890], ensuring the graph accurately reflects the actual scanned codebase.
Absolute Path Leakage Fix
Fixed absolute scan-path leakage by enforcing project-root anchoring [#1789]. This prevents exposure of full filesystem paths in the generated graph.
TypeScript Extension Handling
Upper-case TypeScript extensions (.TS, .TSX) are now parsed correctly [#1881].
Kotlin Built-in Types
Kotlin built-in types no longer create spurious references edges [#1876], cleaning up the graph structure for Kotlin projects.
Persistent Exclude Patterns
--exclude patterns now persist across rebuilds in .graphify_build.json [#1886], maintaining consistent filtering without re-specifying flags.
Version 0.9.15 (2026-07-13): Security and UX
Privacy-First Query Logging
Query-log is now opt-in and disabled by default [#1797], respecting user privacy. Enable it explicitly if you need to audit queries.
Markdown Node Deduplication
Duplicate markdown nodes are now merged [#1799], reducing graph size when documentation files contain repeated content.
Improved Pruning
Enhanced pruning of excluded files [#1795] ensures that files matching exclude patterns are completely removed from the graph rather than left as orphaned nodes.
Practical Usage Examples
Leverage the latest features with these common commands:
# Install the CLI (recommended)
uv tool install graphifyy
# Register the skill with your AI assistant (default soft-nudge)
graphify install
# Enable strict hook mode (blocks first raw read)
graphify install --project --strict
# Build a graph for the current directory (uses atomic writes)
graphify .
# Incrementally update only changed files (honors .graphifyignore)
graphify . --update
# Force a full re-extract after large refactors
graphify . --force
# Run a semantic-aware query
graphify query "what connects auth to the database?"
# Find the shortest path between two symbols
graphify path "FastAPI" "ModelField"
# Explain a node with its edges and confidence tags
graphify explain "APIRouter"
# Export to GraphML for visualization in Gephi or Yed
graphify export graphml
Tip: To avoid polluting your IDE’s prompt cache, add generated files to
.claudeignoreor equivalent assistant ignore files.
Summary
- Graphify v8 releases 0.9.15–0.9.20 harden AI integration safety through strict PreToolUse hooks and deterministic graph extraction.
- Atomic writes and partial extraction guards prevent data corruption during crashes or interrupted scans.
- Privacy controls make query logging opt-in, while Windows path handling improves cross-platform reliability.
- Semantic cache anchoring and file-hash memoization significantly improve performance and accuracy.
- The [
CHANGELOG.md](https://github.com/Graphify-Labs/graphify/blob/v8/CHANGELOG.md) file in the repository contains the complete historical record.
Frequently Asked Questions
How do I enable strict hook mode in Graphify?
Set the GRAPHIFY_HOOK_STRICT environment variable to 1 or install with --strict. This configures the PreToolUse hook to block the first raw read of a session rather than just nudging, preventing AI assistants from accessing files outside the graph without explicit permission.
What is the --allow-partial flag in Graphify 0.9.18?
The --allow-partial flag explicitly permits partial extraction to overwrite existing graph data [#1951]. Without this flag, Graphify protects against partial overwrites that could result from interrupted scans, ensuring you cannot accidentally replace a complete graph with an incomplete one.
How does Graphify handle query logging for privacy?
As of version 0.9.15, query logging is opt-in and disabled by default [#1797]. This privacy-first approach ensures that your graph queries are not written to disk unless you explicitly enable logging, preventing sensitive codebase information from persisting in log files.
Where can I find the complete Graphify changelog?
The complete chronological list of all fixes, features, and breaking changes is maintained in the [CHANGELOG.md](https://github.com/Graphify-Labs/graphify/blob/v8/CHANGELOG.md) file at the root of the Graphify-Labs/graphify repository. This file contains detailed issue references and release dates for all versions prior to 0.9.15.
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →