Releases: Viraj465/CodeTrace-ai
Release list
Codetrace AI v1.0.3
CodeTrace AI v1.0.3 — The Governance Release
v1.0.3 changes how CodeTrace answers. Every structural claim now carries a live file:line citation and an evidence grade. When the evidence isn't there, the agent says so instead of guessing.
This release also:
- connects to any OpenAI- or Anthropic-compatible endpoint
- makes Ollama hardware-aware
- closes a path-containment gap
- fixes several bugs that silently degraded results
pip install -U codetrace-aiRequires Python 3.10–3.12.
⚠️ Upgrade notes (read first)
- Re-register MCP in each project. Previous versions registered the MCP server against the indexed project instead of the installed package, so your IDE integration may be broken. Run
codetrace register-mcpin each project. Registration now writes project-local.mcp.json,.cursor/mcp.jsonand.vscode/mcp.json. These files contain absolute paths for your machine, so you'll probably want them in.gitignore. - Rebuild your index. Re-indexing a file used to drop inbound call edges from other files, so graphs updated incrementally on ≤1.0.2 can understate blast radius. Delta sync alone won't repair this, because unchanged files are skipped. Run a full rebuild: delete
.codetrace/graph_metadata.dband.codetrace/sync_metadata.db, then runcodetrace index .. - Gemini now always runs at temperature 1.0.
- Ollama now uses the native Ollama API and sizes
num_ctxautomatically. If you tuned context manually before, pin it again withcodetrace set-ctx <tokens>, or use0for auto.
✨ Highlights
🏛️ Governed Pipeline Protocol
Every structural claim is graded:
CONFIRMED: established by a tool call in this sessionINFERRED: reasoned from confirmed evidence, and labelled as suchUNRESOLVED: not enough evidence
Claims need a file:line citation from live tool output. Memory from compressed history or prior sessions counts as context, not evidence. When something is missing, the agent names what's missing and what re-indexing would fix it.
Investigation follows the narrowest path the question needs:
search_codebase → get_symbol_relations → read_file → analyze_impact → report
🔌 Any LLM endpoint via custom
Point CodeTrace at any OpenAI- or Anthropic-compatible API: DeepSeek, vLLM, LM Studio, Together, Fireworks, or a corporate gateway. You provide the API style, base URL and model name. API keys are optional for local endpoints. Model lists are fetched automatically when the endpoint exposes them.
🖥️ Hardware-aware Ollama
- Detects GPU memory on NVIDIA and Apple Silicon and picks a safe context window.
- Lowers the window after the current turn if the model spills to CPU.
- On a hard out-of-memory error, stops and asks before retrying smaller.
Tune it with:
codetrace set-ctx 16384 # pin a window
codetrace set-ctx --backoff 0.75 # keep 75% on each auto-lower🧩 MCP from the CLI
codetrace mcp [PATH]starts the stdio MCP server directly.codetrace register-mcp [PATH]re-registers it for Claude Code, Cursor and VS Code. Existing entries are preserved, and non-JSON config files are left untouched and reported.
Also new
codetrace set-default-ctxandcodetrace set-model-limitsfor cloud models LiteLLM doesn't recognise.codetrace index <GitHub/GitLab URL>keeps the clone under~/.codetrace/repos/, so re-indexing is incremental and you cancodetrace chatagainst it.- Output Normalizer: headings, bullet styles, code-fence tags and spacing render the same regardless of provider.
🔒 Security
- Path containment fix.
read_fileandwrite_filepreviously used a prefix check, so a sibling directory such asproject-secretpassed as insideproject. Checks now usePath.is_relative_to, and out-of-project writes are refused before the approval prompt appears. Upgrading is recommended. - Config hardening.
~/.codetrace/config.json, which holds your API key, is now written atomically with owner-only permissions.
🐛 Fixes
git_diffalways returned an empty diff, because the revision was passed after--and git treatedHEADas a filename.- Re-indexing a file dropped inbound call edges. Also, calls no longer resolve across unrelated languages.
NameError: loggercrashed every Ollama session at startup.- MCP auto-registration now registers the current interpreter and installed package.
- Gemini 400 errors caused by
stream_options. - Blank
Architect Error:messages: timeouts and empty exceptions now show a readable cause. - The API-key leak detector no longer flags commit SHAs and long identifiers.
⚙️ Improvements
- Thread-safe Tree-sitter parsing.
- Chunked ChromaDB upserts and SQLite-safe chunked deletes.
- Batched FlashRank re-ranking, which ends out-of-memory crashes on CPU-only machines.
- Built-in ignore list (
node_modules, virtualenvs, IDE folders) and correct handling of nested.gitignorefiles. - Case-insensitive path handling on Windows.
🧪 Tests
First automated test suite, running in CI. It covers indexing regressions, the MCP server, the output normalizer, safety and config, and the token manager.
Full changelog: v1.0.2...v1.0.3
PyPI: https://pypi.org/project/codetrace-ai/1.0.3/