
Research
/Security News
TensorLake npm SDK Compromised in ChainDrop Shai-Hulud Credential-Stealing Attack
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.
@codragraph/graphstore
Advanced tools
Dolt-like content-addressed versioning for the CodraGraph knowledge graph — snapshots, branches, diffs, three-way merge.
Dolt-like content-addressed versioning for the CodraGraph knowledge graph.
Your codebase has git history. Your agent's understanding of it should too.
This package adds a versioning layer underneath the existing LadybugDB-backed query path. Each codragraph analyze produces an immutable, content-addressed snapshot of the knowledge graph, including FeatureCluster nodes and their feature membership/dependency edges. Branches, merges, and structured diffs operate on those snapshots; querying a historical snapshot materializes it back into an ephemeral LadybugDB so the existing Cypher/MCP surface keeps working unchanged.
Developer preview. Capabilities:
src/
├── types.ts Branded ObjectId, Snapshot, Commit, Branch, GraphDiff
├── cas/
│ ├── interface.ts ContentAddressedStore { put, get, has, list }
│ └── fs-cas.ts Filesystem CAS — .codragraph/graphstore/objects/<aa>/<rest>
├── snapshot/
│ ├── row-source.ts RowSource / RowSink — abstract over LadybugDB
│ ├── serializer.ts Walk RowSource → emit Snapshot
│ └── materializer.ts Read Snapshot → write rows into RowSink
├── history/
│ ├── commit.ts createCommit, readCommit
│ ├── branch.ts createBranch, listBranches, getHead, setHead, HEAD
│ └── log.ts walkCommits backward
├── diff/
│ ├── structural.ts Diff between two Snapshot ids
│ └── semantic.ts Higher-level diff with change classification
└── merge/
└── three-way.ts LCA-based three-way merge with conflict detection
Most users get graphstore through @codragraph/cli; install this package
directly only when you want to embed content-addressed graph versioning in
your own tool.
import { FsCAS } from "@codragraph/graphstore/cas";
import { serializeSnapshot, materializeSnapshot } from "@codragraph/graphstore/snapshot";
import { createCommit, getHead, setHead } from "@codragraph/graphstore/history";
import { diffSnapshots } from "@codragraph/graphstore/diff";
const cas = new FsCAS({ root: ".codragraph/graphstore" });
// Take a snapshot
const snapshot = await serializeSnapshot({ source: cgdbRowSource, cas });
const commit = await createCommit({
cas,
snapshot: snapshot.id,
parents: [],
author: { name: "anit", email: "anit@example.com" },
message: "initial index",
});
await setHead({ root: ".codragraph/graphstore", branch: "main", commit: commit.id });
// Diff two snapshots
const diff = await diffSnapshots({ cas, from: snapA.id, to: snapB.id });
Apache-2.0. You can use, modify, redistribute, bundle, and host this package commercially, subject to the Apache-2.0 notice and attribution requirements.
FAQs
Dolt-like content-addressed versioning for the CodraGraph knowledge graph — snapshots, branches, diffs, three-way merge.
We found that @codragraph/graphstore demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Research
/Security News
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.

Research
/Security News
Socket found 16 malicious Firefox extensions designed to steal crypto wallet recovery phrases and private keys using cloned Rabby and OKX interfaces.

Product
Socket now scans VS Code extensions, giving teams early detection of risky behaviors, hidden capabilities, and supply chain threats in developer tools.