[Feature Request - Codemaps] Deduplicate Structural Graph Edges and Augment with Metadata (Call Sites)
@satvikkk ci sta già lavorando.
Dal 16/2/2026.
Valutazione
Questa issue non è ancora stata valutata.
Descrizione
In the codemaps GraphService unconditionally adds an edge each time a parser detects a relationship (e.g., calls, imports). If a function calls the fs module 10 times, the parser emits 10 identical structural edges into the JSON payload. While this captures raw control flow, it significantly inflates the token size of the graph output for LLM agents and creates redundant noise during traversal.
Problem Statement: When an MCP agent queries the AST graph to understand the architecture or look for security boundaries, the identical duplicate edges are inefficient:
- Token Bloat: Sending 50 identical
A -> Bedges wastes LLM context window limits. - Analysis Complexity: Graph algorithms run slower and need manual filtering if traversing a multigraph.
**Proposed Solution:**The backend GraphService should natively de-duplicate edges between the same conceptual source and target nodes, but preserve the frequency and location metadata. Instead of an array of redundant edges, the graph JSON for an edge would look like this:
{ "source": "src/index.ts:scan_dir",
"target": "module:fs",
"type": "calls",
"weight": 3,
"locations": [
{"line": 28, "snippet": "await fs.readdir"},
{"line": 34, "snippet": "await fs.stat"},
{"line": 45, "snippet": "await fs.realpath"}
]
}
**Why this matters for Agents:**By collapsing edges but enriching them with target telemetry (like code snippets and varying lines), the structural architecture answers "Who interacts with whom?" exactly once. If a security agent spots a dangerous data cross (e.g. untrusted input -> exec), it can immediately inspect the locations array attached to that single edge to launch a direct pinpoint audit without re-parsing the entire codebase.
Implementation Details:- Update add_edge() in GraphService to check if a {source, target} pair already exists.- If it does, push the new line references into the locations array and bump the weight.
Note: This is dependent on the CodeMaps tool.
- Lingua principale
- TypeScript
- Stelle
- 794
- Fork
- 58
- Metriche di merge delle PR
- Nessuna PR unita negli ultimi 30g
Preparare l'ambiente
- Nessun Dockerfile né file Docker Compose
- Nessun modello di pull request
- Leggi la guida per i contributori
Come iniziare
- Leggi tutta la issue e poi la guida ai contributi del progetto.
- Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
- Fai un fork del repository e lavora su un branch.
- Apri una pull request che faccia riferimento al numero della issue.
Altre issue di gemini-cli-extensions/security
-
HelpAperta
Difficoltà 1/5 Meno di un'ora Idoneità per principianti 10/100
-
Difficoltà 3/5 1-2 giorni Idoneità per principianti 45/100
gemini-cli-extensions/security#133 · 3 commenti ·
-
Difficoltà 4/5 3-5 giorni Idoneità per principianti 35/100
-
Difficoltà 5/5 Più di una settimana Idoneità per principianti 20/100
-
Difficoltà 5/5 Più di una settimana Idoneità per principianti 20/100
gemini-cli-extensions/security#102 · 5 commenti ·
Tutte le issue di gemini-cli-extensions/security
Issue simili
-
bug via-triage
Difficoltà 2/5 1-3 ore Idoneità per principianti 78/100
pingdotgg/t3code#14452 · 1 commento ·
I maintainer di solito rispondono entro 1 giorno
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 75/100
solana-foundation/program-examples#747 · 1 commento ·
I maintainer di solito rispondono entro 9 giorni
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 65/100
remotion-dev/remotion#11847 ·
I maintainer di solito rispondono entro 1 giorno
-
bug
Difficoltà 2/5 1-3 ore Idoneità per principianti 78/100
openwatersio/slackwater#355 ·
I maintainer di solito rispondono entro 1 giorno
-
bug
Difficoltà 2/5 1-3 ore Idoneità per principianti 74/100
melgarafael/DeskcommCRM#1998 · 3 commenti ·
I maintainer di solito rispondono entro 1 giorno