Repository navigation
Expand file tree
/
Copy pathpyproject.toml
More file actions
425 lines (405 loc) · 17 KB
/
Copy pathpyproject.toml
File metadata and controls
425 lines (405 loc) · 17 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
272
273
274
275
276
277
278
279
280
281
282
283
284
285
286
287
288
289
290
291
292
293
294
295
296
297
298
299
300
301
302
303
304
305
306
307
308
309
310
311
312
313
314
315
316
317
318
319
320
321
322
323
324
325
326
327
328
329
330
331
332
333
334
335
336
337
338
339
340
341
342
343
344
345
346
347
348
349
350
351
352
353
354
355
356
357
358
359
360
361
362
363
364
365
366
367
368
369
370
371
372
373
374
375
376
377
378
379
380
381
382
383
384
385
386
387
388
389
390
391
392
393
394
395
396
397
398
399
400
401
402
403
404
405
406
407
408
409
410
411
412
413
414
415
416
417
418
419
420
421
422
423
424
425
[project]
name = "cognee"
version = "1.6.2"
description = "Cognee - is a library for enriching LLM context with a semantic layer for better understanding and reasoning."
authors = [
{ name = "Vasilije Markovic" },
{ name = "Boris Arzentar" },
]
requires-python = ">=3.10,<3.15"
readme = "README.md"
license = "Apache-2.0"
classifiers = [
"Development Status :: 4 - Beta",
"Intended Audience :: Developers",
"License :: OSI Approved :: Apache Software License",
"Topic :: Software Development :: Libraries",
"Operating System :: MacOS :: MacOS X",
"Operating System :: POSIX :: Linux",
"Operating System :: Microsoft :: Windows",
]
dependencies = [
"openai>=1.80.1",
"python-dotenv>=1.0.1,<2.0.0",
"pydantic>=2.10.5",
# GHSA-4xgf-cpjx-pc3j: 2.12.0–2.14.1 vulnerable, fixed in 2.14.2. Exclude the
# vulnerable range rather than capping, so the patched 2.14.2+ is adopted once
# it clears the `exclude-newer` window (it was <2 days old at time of writing).
# >=2.7.0: NoDecode (cognee/modules/improve/config.py) first shipped there.
"pydantic-settings>=2.7.0,!=2.12.*,!=2.13.*,!=2.14.0,!=2.14.1,<3",
"typing_extensions>=4.12.2,<5.0.0",
"numpy>=1.26.4, <=4.0.0",
"sqlalchemy>=2.0.39,<3.0.0",
"aiosqlite>=0.20.0,<1.0.0",
"filelock>=3.12.0,<4.0.0", # cross-process migration lock for SQLite (Linux/macOS/Windows)
"packaging>=24.0", # requirement parsing for the GLiNER runtime install
# gliner2 needs transformers<5, and transformers 4.x needs these two ranges. Pinned
# in core (the lockfile already resolves inside them) so the GLiNER runtime installed
# at first use never has to change a package the running process has imported.
"huggingface-hub>=0.34,<1",
"tokenizers>=0.22,<=0.23.0",
"tiktoken>=0.8.0,<1.0.0",
# <1.97.0: 1.97.0 fails to build litellm.types.utils.Message on Python 3.10 (unresolved
# forward ref) and 1.98.0+ import typing.NotRequired (3.11+). See BerriAI/litellm#38202.
"litellm>=1.83.7,<1.97.0",
"instructor>=1.9.1,<1.15.3",
"filetype>=1.2.0,<2.0.0",
"aiohttp>=3.13.5,<4.0.0",
"aiofiles>=23.2.1",
# AES-256-GCM encryption for stored OAuth integration credentials
# (cognee/modules/integrations/crypto.py) — unconditionally imported via
# client.py's Slack router registration, so this is a core dependency,
# not an integration-specific extra.
# <51 (not <50): downstream consumers pin cryptography>=50.0.0 for
# PYSEC-2026-3552/3553/3554; our usage (Fernet, AESGCM) is stable across 50.x.
"cryptography>=43.0.0,<51",
"rdflib>=7.1.4,<7.2.0",
"pypdf>=6.6.2,<7.0.0",
"jinja2>=3.1.3,<4",
"lancedb>=0.24.3,<1.0.0", # 0.24.2 bundles lance 0.32.0 whose list-column decoder panics on tables with deletion vectors
"nbformat>=5.7.0,<6.0.0",
"alembic>=1.13.3,<2",
"limits>=4.4.1,<6",
"fastapi>=0.116.2,<1.0.0",
"starlette>=0.48",
"python-multipart>=0.0.22,<1.0.0",
"fastapi-users[sqlalchemy]>=15.0.2",
# Local CPU embeddings (onnxruntime, ~65 MB): the embedder cognee runs on when no
# LLM key and no EMBEDDING_* settings are configured, so a bare install can ingest.
"fastembed<=0.8.0",
# onnxruntime 1.23.2 only ships wheels through cp313; cp314 wheels start
# at onnxruntime 1.24.1. Split by python_version so existing 3.10–3.13
# users keep the pinned version and 3.14 picks up the first cp314-capable
# release.
"onnxruntime<=1.23.2 ; python_version < '3.14'",
"onnxruntime>=1.24.1 ; python_version >= '3.14'",
"structlog>=25.2.0,<26",
"pympler>=1.1,<2.0.0",
"pylance>=0.22.0,<=0.36.0",
# ladybug 0.18.x+ publishes only macosx_15_0 wheels (its sdist needs C++20
# std::atomic_ref, which Apple Clang's libc++ on macOS <= 14 lacks), so
# macOS 13/14 (Darwin 22/23) get 0.17.x — the last line with macosx_13_0
# wheels; storage code 41, which ladybug_migrate upgrades forward when the
# machine later moves to a newer line. Those platforms therefore stay
# exposed to the storage-corruption defects fixed in 0.18.2 and 0.19.1
# (COG-6185).
# Pinned at 0.19.0, not 0.19.1: extension.ladybugdb.com publishes no
# v0.19.1 JSON extension (404 on every platform), and 0.19.1 segfaults
# cognee's DB worker mid-write in CI. 0.19.0 carries the same storage
# fix and its extension build exists.
# Each pinned version's on-disk storage code must also exist in
# cognee_db_workers.ladybug_migrate.ladybug_version_mapping (0.19.0 -> 43),
# so bumping this pin is a two-file change.
# 0.19.x Windows wheels no longer vendor the OpenSSL DLLs their extension
# imports; cognee_db_workers._windows_openssl supplies them. Drop that shim
# once a pinned release vendors OpenSSL again.
"ladybug>=0.17.0,<0.18 ; sys_platform == 'darwin' and ('Darwin Kernel Version 22.' in platform_version or 'Darwin Kernel Version 23.' in platform_version)",
"ladybug==0.19.0 ; sys_platform != 'darwin' or ('Darwin Kernel Version 22.' not in platform_version and 'Darwin Kernel Version 23.' not in platform_version)",
"python-magic-bin<0.5 ; platform_system == 'Windows'", # Only needed for Windows
"networkx>=3.4.2,<4",
"uvicorn>=0.34.0,<1.0.0",
"gunicorn>=20.1.0,<24",
"websockets>=15.0.1,<16.0.0",
"tenacity>=9.0.0",
"fakeredis[lua]>=2.32.0",
"diskcache>=5.6.3",
"aiolimiter>=1.2.1",
"urllib3>=2.6.0",
"cbor2>=5.8.0",
"langdetect>=1.0.9",
"datamodel-code-generator>=0.54.0",
# Enola powers the built-in deterministic code-graph route. Keep this pinned:
# its snapshot contract and known answers are validated by test_code_graph_e2e.py.
"enola-cli==0.4.26",
# dlt powers database, CSV and Google Drive/Gmail ingestion.
"dlt[sqlalchemy]>=1.9.0,<2",
# dlt's filesystem read_csv reader requires pandas but does not declare it
"pandas>=2.2.2,<3.0.0",
]
[project.optional-dependencies]
api=[]
scraping = [
"tavily-python>=0.7.12",
"beautifulsoup4>=4.13.1",
"playwright>=1.9.0",
"lxml>=4.9.3,<5 ; python_version < '3.13'",
"lxml>=5,<6 ; python_version >= '3.13' and python_version < '3.14'",
# cp314 wheels start at lxml 6.0.1; without this 3.14 falls back to a
# source build that requires libxml2/libxslt headers (CI doesn't have them).
"lxml>=6.0.1,<7 ; python_version >= '3.14'",
"protego>=0.1",
"APScheduler>=3.10.0,<=3.11.0"
]
# fastembed is a core dependency. The empty extra keeps `cognee[fastembed]` installable.
fastembed = []
neo4j = ["neo4j>=5.28.0,<6"]
neptune = ["langchain_aws>=0.2.22"]
postgres = [
"psycopg2>=2.9.10,<3",
"pgvector>=0.3.5,<0.4",
"asyncpg>=0.30.0,<1.0.0",
]
postgres-binary = [
"psycopg2-binary>=2.9.10,<3.0.0",
"pgvector>=0.3.5,<0.4",
"asyncpg>=0.30.0,<1.0.0",
]
turso = ["libsql-experimental>=0.0.55,<0.1"]
notebook = ["notebook>=7.1.0,<8"]
langchain = [
"langsmith>=0.2.3,<1.0.0",
"langchain_text_splitters>=0.3.2,<1.0.0",
"langchain-core>=1.2.5"
]
llama-index = ["llama-index-core>=0.14.20,<0.15"]
huggingface = ["transformers>=4.46.3,<6"]
ollama = ["transformers>=4.46.3,<6"]
mistral = ["mistral-common>=1.5.2,<2", "mistralai>=1.9.10,<2"]
anthropic = ["anthropic>=0.27"]
azure = ["azure-identity>=1.15.0,<2"]
deepeval = ["deepeval>=3.0.1,<4"]
posthog = ["posthog>=3.5.0,<4"]
groq = ["groq>=0.8.0,<1.0.0"]
llama-cpp = ["llama-cpp-python[server]>=0.3.0,<1.0.0"]
docs = [
"lxml>=4.9.3,<5 ; python_version < '3.13'",
"lxml>=5,<6 ; python_version >= '3.13' and python_version < '3.14'",
# cp314 wheels start at lxml 6.0.1.
"lxml>=6.0.1,<7 ; python_version >= '3.14'",
"unstructured[csv, doc, docx, epub, md, odt, org, ppt, pptx, rst, rtf, tsv, xlsx, pdf]>=0.18.1,<19",
"nltk>=3.9.3,<4", # TODO: Remove when unstructured is above v0.21.0 as it won't use nltk anymore
]
# enola-cli is a core dependency. The empty extra keeps `cognee[codegraph]` installable.
codegraph = []
evals = [
"plotly>=6.0.0,<7",
"gdown>=5.2.0,<6",
"pandas>=2.2.2,<3.0.0",
"matplotlib>=3.8.3,<4",
"scikit-learn>=1.6.1,<2",
"locust>=2.0.0,<3",
]
# Note: New s3fs and boto3 versions don't work well together
# Always use compatible fixed versions of these two dependencies
aws = ["s3fs[boto3]==2025.3.2"]
# dlt is a core dependency. The empty extra keeps `cognee[dlt]` installable.
dlt = []
gmail = [
"google-api-python-client>=2.100.0,<3",
"google-auth>=2.23.0,<3",
"google-auth-oauthlib>=1.1.0,<2",
]
google-drive = [
"google-api-python-client>=2.100.0,<3",
"google-auth>=2.23.0,<3",
"google-auth-oauthlib>=1.1.0,<2",
]
baml = ["baml-py (==0.206.0)"]
dev = [
"pytest>=7.4.0,<8",
"pytest-cov>=6.1.1,<7.0.0",
"pytest-asyncio>=0.21.1,<0.22",
"pytest-timeout>=2.3.1,<3",
"pytest-split>=0.11.0,<0.12",
# examples/advanced_guides/temporal_awareness_example and its unit tests
"dateparser>=1.2,<2",
"coverage>=7.3.2,<8",
"pre-commit>=4.0.1,<5",
"notebook>=7.1.0,<8",
"deptry>=0.20.0,<0.21",
"ruff>=0.9.2,<=0.16.6",
"tweepy>=4.14.0,<5.0.0",
"gitpython>=3.1.43,<4",
"mkdocs-material>=9.5.42,<10",
"mkdocs-minify-plugin>=0.8.0,<0.9",
"mkdocstrings[python]>=0.26.2,<0.27",
"ty>=0.0.31,<0.1.0",
]
debug = ["debugpy>=1.8.9,<2.0.0"]
redis = ["redis>=5.0.3,<6.0.0"]
tracing = [
"opentelemetry-api>=1.20.0,<2",
"opentelemetry-sdk>=1.20.0,<2",
"opentelemetry-exporter-otlp-proto-grpc>=1.20.0,<2",
"opentelemetry-exporter-otlp-proto-http>=1.20.0,<2",
]
# Slim docling profile: converts office/HTML/email/markdown/LaTeX documents
# without torch or the ML layout models (~280MB installed vs multiple GB).
# PDF/image conversion through docling needs the ML pipeline: install the
# `docling-full` extra for that (cognee's default PDF path uses pypdf either way).
docling = [
"docling-slim[convert-core,format-pdf,format-office,format-html,format-email,format-markdown,format-latex]>=2.115,<3",
]
docling-full = ["docling>=2.115,<3", "transformers>=4.55"]
# GLiNER demo: LLM-free graph extraction and summaries (cognee/tasks/graph/gliner_demo).
# Recommended for GLiNER users (torch from PyPI: the CUDA build on Linux). Without it, the
# first GLiNER cognify installs this same list itself (gliner_demo/install.py reads it from
# cognee's metadata), taking torch from the PyTorch CPU index. torch is listed explicitly
# for that (gliner2[local] requires the same range). protobuf + sentencepiece are needed
# by the DeBERTa tokenizer fallback.
gliner = ["gliner2[local]>=2.0.0,<3", "torch>=2.1,<3", "protobuf>=5.29.6", "sentencepiece>=0.2.0"]
rapidocr = ["rapidocr-onnxruntime>=1.3.0,<2"]
[project.urls]
Homepage = "https://www.cognee.ai"
Repository = "https://github.com/topoteretes/cognee"
[project.scripts]
cognee-cli = "cognee.cli._cognee:main"
[build-system]
# Pinned: the build backend decides the wheel's Metadata-Version, and the PyPI
# publish action validates it with a pinned twine — an unpinned hatchling let
# the emitted metadata drift to 2.5 and broke the release publish gate. Bump
# this together with the gh-action-pypi-publish pin in the release workflows.
requires = ["hatchling==1.32.0"]
build-backend = "hatchling.build"
[tool.hatch.build]
# The bundled Ladybug JSON extension binaries are gitignored (built or
# fetched at release time — see cognee_db_workers/ladybug_extensions/README.md).
# Include them in both the sdist and wheel because `uv build` builds the wheel
# from the sdist.
artifacts = ["cognee_db_workers/ladybug_extensions/**/*.lbug_extension"]
exclude = [
"/bin",
"/dist",
"/.data",
"/.github",
"/deployment",
"/cognee-mcp",
"/cognee-frontend",
"/examples",
"/helm",
"/licenses",
"/logs",
"/notebooks",
"/profiling",
"/tests",
"/tools",
]
[tool.hatch.build.targets.wheel]
packages = ["cognee", "cognee_db_workers", "kuzu"]
[tool.uv]
# Note: exclude newer packages that are less than 2 days old
exclude-newer = "2 days"
# Enola releases are deliberately pinned and validated against the code-graph
# known answers. Allow a newly pinned release to resolve during that 2-day window.
exclude-newer-package = { enola-cli = "0 days" }
constraint-dependencies = [
"protobuf>=5.29.6, !=6.30.*, !=6.31.*, !=6.32.*, !=6.33.1, !=6.33.2, !=6.33.3, !=6.33.4", # protobuf 6.33.5 and higher versions + version 5.29.6
"pyasn1>=0.6.2",
"wheel>=0.46.2",
"nltk>=3.9.3",
# spacy 3.8.14 dropped cp314 wheels (3.8.10-3.8.13 had them); pin so the
# Python 3.14 release path keeps a wheel available. Pulled transitively
# via unstructured.
"spacy<3.8.14 ; python_version >= '3.14'",
# scipy cp314 wheels start at 1.16.1; 1.16+ also dropped cp310, so the
# resolver collapses <3.11 and >=3.14 onto the latest cp310-compatible
# version (1.15.3) by default — which has no cp314 wheel. Force 3.14 to
# use 1.16.1+ so the wheel-only release sync succeeds. Pulled
# transitively via pandas / scikit-learn / fastembed.
"scipy>=1.16.1 ; python_version >= '3.14'",
]
[tool.pytest.ini_options]
# `pytest` with no path collects only the library test tree; cognee-mcp has its
# own pyproject and suite. See cognee/tests/README.md for layout and credentials.
testpaths = ["cognee/tests"]
markers = [
"deployment: smoke tests against a deployed cognee instance (cognee/tests/deployment/)",
]
[tool.ruff]
line-length = 100
exclude = [
"migrations/", # Ignore migrations directory
"notebooks/", # Ignore notebook files
"build/", # Ignore build directory
"cognee/pipelines.py",
"cognee/modules/users/models/Group.py",
"cognee/modules/users/models/ACL.py",
"cognee/modules/pipelines/models/Task.py",
"cognee/modules/data/models/Dataset.py",
"cognee/modules/notebooks/tutorials/" # Ignore tutorial Python files
]
[tool.ruff.lint]
# E402 is not in ruff 0.16's default set, but the pre-commit hook (ruff 0.15) has
# enforced it all along; select it so CI and the hook agree and the `# noqa: E402`
# comments that satisfy the hook are not reported as stale.
extend-select = ["E402"]
ignore = [
"F401",
# N999: module names like LanceDBAdapter.py and DTO.py are public import paths.
"N999",
# RUF012: `metadata: dict = {...}` on DataPoint subclasses is a pydantic field
# default, which ruff cannot recognise because the pydantic base is indirect.
"RUF012",
# TRY004: raise TypeError from an isinstance check. Of the 59 sites, 28 are
# pydantic validators (only ValueError becomes a ValidationError there) and
# most of the rest validate the shape of decoded data, which callers and
# tests catch as ValueError. The rule's advice conflicts with both.
"TRY004",
# ASYNC230/220/221/251: blocking file, subprocess and sleep calls inside async
# functions. The document loaders and the local storage layer do their file IO
# synchronously by design today, and the parser holding the handle is the real
# blocking work, so the fix is moving each loader's parse off the event loop
# (SDK-600), not wrapping open() calls. Re-enable when that lands.
"ASYNC230",
"ASYNC220",
"ASYNC221",
"ASYNC251",
]
[tool.ruff.lint.flake8-bugbear]
# FastAPI dependency-injection defaults are evaluated per request, not at import.
extend-immutable-calls = [
"fastapi.Depends",
"fastapi.Query",
"fastapi.Form",
"fastapi.File",
"fastapi.Path",
"fastapi.Body",
"fastapi.Header",
"fastapi.Cookie",
"fastapi.Security",
]
[tool.ruff.lint.per-file-ignores]
# Package init order is load-bearing (side-effect registration, circular-import
# avoidance); sorting these breaks `import cognee`.
"__init__.py" = ["I001"]
# Logging handlers and filters must never log or raise from inside emit()/filter():
# doing so re-enters the logging machinery. They swallow broadly and report via
# Handler.handleError, the same shape the stdlib handlers use.
"cognee/shared/logging_utils.py" = ["BLE001", "S110"]
# Route signatures declare query defaults as literals (`datasets: ... = []`); they
# are API defaults FastAPI hands to the handler, never mutated, and a None default
# would change the OpenAPI schema. Applies to every API version.
"cognee/api/*/*/routers/*.py" = ["B006"]
# Generated by BAML (see the header of each file): regenerate instead of editing.
"cognee/infrastructure/llm/structured_output_framework/baml/baml_client/*.py" = ["B006"]
[tool.ty.src]
# TODO: Gradually add more directories to include until we have type hints for all modules
include = [
"cognee/exceptions",
"cognee/infrastructure/context",
"cognee/infrastructure/data",
"cognee/infrastructure/engine",
"cognee/infrastructure/entities",
"cognee/infrastructure/files",
"cognee/infrastructure/llm",
"cognee/infrastructure/loaders",
"cognee/infrastructure/locks",
"cognee/infrastructure/session",
"cognee/infrastructure/utils",
"cognee/memory",
"cognee/migration",
"cognee/pipelines",
"cognee/shared"
]
# Exclude generated files
exclude = ["cognee/infrastructure/llm/structured_output_framework/baml/baml_client/"]
[dependency-groups]
dev = [
"httpx>=0.28.1",
"pytest>=7.4.4",
"pytest-asyncio>=0.21.2",
"pytest-timeout>=2.3.1",
"pytest-split>=0.11.0,<0.12",
"ruff>=0.13.1",
"dateparser>=1.2,<2",
]