Code-Graph-RAG

The ultimate RAG for your monorepo. Query, understand, and edit multi-language codebases with the power of AI and knowledge graphs

Memory & Knowledge Python Listed MIT

Is Code-Graph-RAG safe? Promising trust profile, but some evidence still deserves review.

OSSF Scorecard 8.7 / 10
Provenance None
Signed commits 65%
Last push today
Compare Code-Graph-RAG

How does it stack up against its Memory & Knowledge neighbours?

Pick any agent to compare →
Suggest a correction

In detail: Code-Graph-RAG scores 71.4/100 (Grade B), ranked #304 of 1325 tracked open-source AI agent projects, on evidence coverage C (2 of 5 independent signal types). The public evidence: no package-provenance attestation found; OSSF Scorecard rates its supply-chain practices 8.7/10; 65% of recent commits are signed; last pushed 2026-09-26. Every point is earned from checkable signals — never paid placement. How scoring works →

How Code-Graph-RAG compares in Memory & Knowledge

  1. #19 RAGFlow 72.0 +0.6
  2. #20 Tidb 71.5 +0.1
  3. #21 Code-Graph-RAG 71.4 this agent
  4. #22 txtai 70.9 −0.5
  5. #23 Vellum Assistant 69.6 −1.8

Bars show each HVTrust score; the tick marks Code-Graph-RAG’s 71.4.

Where the 71.4 comes from

HVTrust dimensions vs the Memory & Knowledge average

71.4 / 100 · 100.0% confidence

Code-Graph-RAG Memory & Knowledge average (44 agents)

Safety / Integrity50% OSSF Scorecard · 30% provenance · 20% signed commits
14.1 / 25
2.2 above avg 11.9
Identity / Provenance60% listing status · 40% build provenance
10.8 / 18
1.8 below avg 12.6
Transparency50% declared license · 50% OSSF Scorecard
15.9 / 17
2.9 above avg 13.0
Maintenance60% last-push freshness · 40% commit activity
20.0 / 20
2.9 above avg 17.1
AdoptionLog-scaled stars · package downloads
8.9 / 20
4.7 below avg 13.6

Quick Trust Read

What Would Improve It
Publish package provenance or release attestations for stronger supply-chain evidence.
Recent Changes
2026-09-26
Rank Moved
Rank rose 36 spots (#340 → #304)
2026-09-23
Provider Added
Runtime surface grew — new detected provider dependency: Qdrant
2026-09-23
Mcp Status Changed
Detected MCP server support changed: none → implemented
Maintainer Checklist
Publish provenance Add package provenance or release attestations so users can verify where shipped artifacts came from.
85.5
Activity sub-score · out of 100
#21

How to read this: HVTrust (0–100) weighs supply-chain signals (provenance, OSSF Scorecard, signed commits, open license) alongside real-world adoption. Grade B reflects the trust score band: A ≥ 80, B ≥ 65, C ≥ 50, D < 50. Evidence coverage C is separate — it grades how many independent signal types back the score (2 of 5), so a high score on thin evidence stays visible. Full methodology →

Signals refreshed 2026-09-26 06:32 UTC · Repo last pushed today

Rank Trend

2026-08-11 2026-09-26

Activity & Reach

Stars
5.2k
Forks
685
Last Push
2026-09-26
today
Commits (4 wk)
2016
Downloads (7d)
—
HN mentions (30d)
—
Open Issues
89
Rank Change
▲36
was #340

Analysis

Activity Inputs

85.5 / 100
StarsRepository reach
22.3 / 30
FreshnessLast push recency
25.0 / 25
ActivityRecent commits
25 / 25
CommunityFork signal
13.2 / 20

Supply Chain Trust

Package Provenance
None
No package attestations found
OSSF Scorecard
8.7 / 10
OpenSSF Scorecard · scanned Sep 20, 2026
Signed Commits
65%
of last 100 commits verified
Binary-Artifacts 10
Branch-Protection 4
CI-Tests 10
CII-Best-Practices 5
Code-Review 0
Contributors 10
Dangerous-Workflow 10
Dependency-Update-Tool 10
Fuzzing 10
License 10
Maintained 10
Packaging 10
Pinned-Dependencies 9
SAST 10
Security-Policy 10
Signed-Releases 10
Token-Permissions 10
Vulnerabilities 10

Common questions about Code-Graph-RAG

Code-Graph-RAG has a mixed signal profile. Some trust indicators are present, others are missing. Whether it is safe for your use case depends on which gaps matter to you — review the breakdown below before adopting in production.
Does Code-Graph-RAG publish package provenance?
No published build provenance is currently detected for Code-Graph-RAG. This is common for open-source projects but means consumers cannot independently verify that the package on the registry matches the GitHub source.
Does Code-Graph-RAG have an OpenSSF Scorecard?
Code-Graph-RAG has an OpenSSF Scorecard score of 8.7/10. The Scorecard checks for branch protection, signed releases, dependency updates, fuzzing, code review, and other supply-chain hygiene items. See the full check breakdown on this page.
Is Code-Graph-RAG actively maintained?
Actively maintained. The repository was pushed to within the last 1 day(s).
What license does Code-Graph-RAG use?
Code-Graph-RAG ships under MIT. A declared, OSI-approved license is one of the transparency signals HVTrust scores.
Are Code-Graph-RAG's commits signed?
65% of the last 100 commits to Code-Graph-RAG are verified-signed (GPG, SSH, S/MIME, or GitHub's signing flow). Signed commits help confirm that code was authored by who the commit claims.

Not a safety endorsement. HVTracker describes what public signals show, not whether a project is safe for your use case. Run your own security review before adopting in production.

AI agent surface

MCP, providers, tool surface
Scored in HVTrust

These runtime-trust fields — detected from public repo docs and manifests — contribute a bounded adjustment to this project's HVTrust score alongside supply-chain evidence. The exact values each field can add or subtract are documented in the methodology → Compare this surface across every listed agent in the capability matrix →

MCP Server Support
high confidence
Implemented
Code-Graph-RAG appears to expose MCP server capabilities.
Detailed evidence is not shown in the public view.
External Service Dependencies
high confidence
1 detected
Public provider/service dependencies detected.
Credential signal: No explicit API-key/config marker detected.
Tool / Plugin Surface
high confidence
1 tags
Broad capability areas detected.
  • database
Detailed evidence is not shown in the public view.
Package Provenance Drift
N/A
No package source configured
Detailed evidence is not shown in the public view.
  • MCP signal live
  • External deps live
  • Tool / plugin surface live
  • Package provenance drift live
How this surface has changed

Detected changes to Code-Graph-RAG's runtime surface and supply-chain posture, from daily public-signal snapshots. A change here means our detectors see something different — a genuinely changed capability, or better evidence of an existing one.

2026-09-23
Provider Added
Runtime surface grew — new detected provider dependency: Qdrant
2026-09-23
Mcp Status Changed
Detected MCP server support changed: none → implemented
2026-09-03
Tool Surface Changed
Detected tool/plugin surface changed: declared → none

Maintain Code-Graph-RAG?

For maintainers

HVTrust scores Code-Graph-RAG from public signals only — we never contact maintainers first. If a signal is wrong, stale, or missing (provenance you publish, a Scorecard you run, signed releases), tell us and we'll review it. Corrections are public and tracked on GitHub.

Reputation Timeline

Signal history
Rank 16Listed 2Surface 1Delisted 1HVTrust 1Grade 1MCP 1Surface 1
2026-09-26
Rank Moved
Rank rose 36 spots (#340 → #304)
2026-09-23
Provider Added
Runtime surface grew — new detected provider dependency: Qdrant
2026-09-23
Mcp Status Changed
Detected MCP server support changed: none → implemented
2026-09-23
Grade Changed
Trust grade C → B
2026-09-23
Rank Moved
Rank dropped 68 spots (#264 → #332)
2026-09-23
HVTrust Changed
HVTrust up 11.6pts (58.0 → 69.6)
2026-09-22
Newly Listed
First tracked at rank #264
2026-09-21
Removed From Active Tracking
Removed from active tracking
2026-09-20
Rank Moved
Rank rose 18 spots (#333 → #315)
2026-09-16
Rank Moved
Rank rose 21 spots (#357 → #336)
2026-09-11
Rank Moved
Rank dropped 10 spots (#331 → #341)
2026-09-07
Rank Moved
Rank dropped 16 spots (#307 → #323)
2026-09-06
Rank Moved
Rank dropped 10 spots (#297 → #307)
2026-09-05
Rank Moved
Rank dropped 45 spots (#252 → #297)
2026-09-04
Rank Moved
Rank dropped 10 spots (#242 → #252)
2026-09-03
Tool Surface Changed
Detected tool/plugin surface changed: declared → none
2026-09-03
Rank Moved
Rank dropped 17 spots (#225 → #242)
2026-08-31
Rank Moved
Rank dropped 22 spots (#196 → #218)
2026-08-26
Rank Moved
Rank dropped 15 spots (#168 → #183)
2026-08-24
Rank Moved
Rank dropped 13 spots (#156 → #169)
2026-08-22
Rank Moved
Rank rose 10 spots (#171 → #161)
2026-08-19
Rank Moved
Rank dropped 10 spots (#156 → #166)
2026-08-12
Rank Moved
Rank rose 12 spots (#164 → #152)
2026-08-10
Newly Listed
First tracked at rank #166

Embed Badge Badge guide for maintainers →

For maintainers
HVTrust 71.4 Grade B
Markdown:
[![HVTrust](https://hvtracker.net/badge/code-graph-rag.svg)](https://hvtracker.net/agents/code-graph-rag)
HTML:
<a href="https://hvtracker.net/agents/code-graph-rag"><img src="https://hvtracker.net/badge/code-graph-rag.svg" alt="HVTrust"></a>

Other agents in Memory & Knowledge

Data sources
GitHub REST API (repo, commits, stars, forks, license) · OpenSSF Scorecard CLI
Each agent's signals refresh once daily across 6 staggered batches. Methodology v4.3 · Raw JSON