Skip to content
CAI
Software that uses CAICheck a score

fallow-rs/fallow

52.2

Weak · 14 September 2026

629.3k

lines of production code

Rust

primary language

1

measurement over time

CAI band scale
CAI lens gauges

What this system is

Fallow is a static analysis and code health platform for TypeScript and JavaScript projects that detects dead code, duplication, security vulnerabilities, and architectural violations. It provides a comprehensive CLI, an LSP for real-time editor diagnostics, and a programmatic API for integrating analysis into CI/CD pipelines and agent workflows. The system supports complex monorepo structures, integrates with major frameworks, and offers features like auto-fixing, runtime coverage correlation, and interactive visualization.

Features

Add Deno workspace support and structured diagnostics

The workspace discovery logic now parses Deno \deno.json\ and \deno.jsonc\ files to identify workspace members and import maps, allowing Deno monorepos to be analyzed without npm bridge manifests. To improve visibility into discovery issues, the system now emits structured diagnostics for malformed manifests, unreachable glob matches, missing tsconfig references, and undeclared workspaces, with aggregated stderr warnings for large monorepos to prevent output flooding.

crates/config/src/workspace · high confidence

Add Fallow security audit gate for Claude Code PreToolUse hooks

This change introduces a new setup-hook configuration that integrates the Fallow security audit tool into the Claude Code workflow. A new \fallow-gate.sh\ script is added to intercept git commit and push commands, verifying that the installed Fallow binary meets a minimum version floor (default 2.85.0) to ensure compatibility with the \--gate-marker\ flag. The script attempts to locate the Fallow binary via PATH, \node\_modules/.bin\, Yarn, or npx, runs an audit, and blocks the commit if the audit verdict is 'fail'. The \settings.json\ file registers this script as a command hook for the \PreToolUse\ event, ensuring security checks run before tool usage.

_crates/cli/src/setup\hooks · high confidence

Add fuzzing corpus and targets for custom parsers

Added fuzzing infrastructure for custom parsers, including Rust fuzz targets for Astro, CSS, MDX, scripts, and Single File Components (SFCs) that exercise the core extraction and parsing logic, along with initial corpus files covering various syntax patterns for these formats.

fuzz · high confidence

Added demo project with sample components and utilities

A new demo project has been added to the assets folder, providing a reference implementation for users. This includes a configuration file (.fallowrc.json) enabling warnings for unused dev dependencies, along with a set of TypeScript source files demonstrating various patterns: React components (Button, Modal, Test), utility functions for formatting dates/currency/percentages and validating emails/phones, service modules for authentication and user retrieval, and type definitions for API responses and legacy configurations.

assets/demo-project · high confidence

Automated VSIX packaging and type-aware sidecar distribution

The VS Code extension now includes a new build pipeline in \editors/vscode/scripts\ that generates platform-specific VSIX packages bundling the type-aware analysis sidecar. This pipeline automatically packages the correct TypeScript backend binaries for each OS and architecture (darwin-arm64, darwin-x64, linux-arm64, linux-x64, win32-arm64, win32-x64) alongside a universal variant, verifies the integrity and executability of the bundled files, and produces a signed inventory manifest with SHA-256 checksums for all artifacts.

editors/vscode/scripts · high confidence

CLI now embeds Fallow agent skill files for offline onboarding

The CLI build process now embeds the Fallow agent skill (including SKILL.md, agent configurations, and reference documentation) directly into the binary. This allows the \fallow agent install\ command to materialize a version-matched copy of the skill even when the project lacks \node\_modules/fallow\, enabling one-pass harness onboarding without external dependencies. A symlink for \schema.json\ is also added to point to the root schema.

crates/cli · high confidence

Enforce forbidden boundary calls between code zones

The analyzer now detects and reports violations when code in a defined zone calls functions or methods that are explicitly forbidden for that zone. This feature allows you to configure specific zones (e.g., 'domain', 'ui') and define rules that prohibit certain callee patterns (e.g., \console.\*\, \child\_process.exec\) within those zones. The system matches calls against these patterns by checking both the written path and the import-resolved canonical path, ensuring that restrictions apply regardless of how the function is imported. If a zone is defined but no files are classified into it, a warning is issued to prevent silent rule failures.

_crates/core/src/analyze/boundary\calls · high confidence

Engine-owned baseline, cache inspection, and churn analysis modules

The engine now owns the baseline data structure used to compare analysis results against previous runs, including support for new finding types such as unused enum/class/store members, policy violations, and Next.js route collisions. A new cache-status module provides read-only inspection of the persisted extraction and graph caches for the \fallow doctor\ command, correctly handling version mismatches and foreign blobs without triggering false drift reports. Git churn analysis is now handled by the engine with a reproducible run-scoped clock (derived from HEAD's committer timestamp or an environment override) to ensure consistent recency-weighted scores across runs, alongside helpers for changed-file detection and CODEOWNERS-based ownership grouping.

crates/engine/src · high confidence

Framework-agnostic template complexity scoring for Astro, Vue, Svelte, and Angular

The \crates/extract/src/template\_complexity\ module now provides a unified, framework-agnostic engine for scoring the complexity of frontend template markup. This engine analyzes JavaScript expressions within template bindings (such as \v-if\, \@if\, \{\#if}\, and attribute bindings) to calculate cyclomatic and cognitive complexity metrics, ensuring consistent scoring across Angular, Vue, Svelte, and Astro. The implementation includes specific scanners for each framework—handling Astro's inline JS expressions, Vue's directive-based control flow, Svelte's logic blocks and snippets, and Angular's template syntax—while masking non-template code like \\<script\>\ and \\<style\>\ blocks to prevent double-counting. This change introduces synthetic \\<template\>\ complexity units that allow users to identify and address high-complexity logic embedded directly within their component views.

_crates/extract/src/template\complexity · high confidence

GitLab CI now posts typed MR comments and inline review discussions

The CI pipeline now uses dedicated Bash scripts to post structured Merge Request comments and inline review discussions to GitLab. These scripts handle authentication via GITLAB\_TOKEN, fetch correct diff references for accurate inline positioning, and render analysis results using the 'fallow' CLI with support for scoping reports to changed files. The implementation includes robust error handling, retry logic for API rate limits, and sidecar marker files to propagate job status (such as skip reasons or deduplication failures) to downstream CI stages.

ci/scripts · high confidence

Initial release of the Fallow VS Code extension

This change introduces the Fallow VS Code extension, providing real-time code intelligence for TypeScript and JavaScript directly in the editor. Users gain access to LSP-powered diagnostics for unused code, duplication, circular dependencies, and complexity, alongside tree views for browsing findings and a status bar for issue counts. The extension supports interactive features such as quick-fix code actions, code lenses for reference counts, and client-side diagnostic muting to reduce noise. It also includes specialized views for project health, security candidates, and runtime coverage, along with commands for auditing changed files and managing licenses. The extension bundles its own LSP client and automatically manages the download of the Fallow CLI binaries.

editors/vscode · high confidence

Introduce @fallow-cli/fallow-node programmatic API

Ship a new Node.js package that exposes fallow's analysis capabilities (dead code, circular dependencies, duplication, similar code, complexity, health, etc.) via a JavaScript API. The package includes native bindings, a loader that resolves companion binaries for type-aware and similar-code analysis, and a build script that generates protocol constants from JSON manifests.

crates/napi · high confidence

Introduce Fallow Review (Electron) desktop app for guided code review

Adds the Fallow Review Electron application, a native desktop interface for reviewing code changes (particularly agent-authored ones) using Fallow's deterministic engine. The app provides a guided walkthrough of review focus areas and file diffs, allows users to screenshot and annotate the running application, and features an in-page picker to select UI components and view their grounded facts. It routes all selections and annotations back to the coding agent via a local feed, supporting configurable agent backends (Claude Code, Codex, OpenCode) and a localhost bridge for inspector interactions.

apps/review-electron · high confidence

Introduce Fallow Viz interactive codebase map and analysis lenses

Adds the visual assets for the new Fallow Viz feature, including a dark-first CSS theme with semantic color tokens and a JavaScript engine that renders an interactive codebase map. The map visualizes files as tiles sized by disk usage, with color coding for unused code, duplication, architecture violations, health risks, and security candidates. It also supports analysis lenses with explicit availability states, allowing users to filter and view specific aspects of the codebase analysis.

crates/cli/viz-assets · high confidence

Introduce Fallow Zed extension for TypeScript and JavaScript diagnostics

Users can now install the Fallow extension in Zed to receive diagnostics for unused code, dependency issues, and duplication in TypeScript and JavaScript projects. The extension acts as a thin wrapper that launches the existing fallow-lsp binary, supporting automatic binary resolution from local workspaces, PATH, or managed downloads with Ed25519 signature verification. It exposes configuration options for enabling specific diagnostic categories, muting specific issue types, and enabling inline complexity code lenses, providing editor-level feedback that complements the CLI's full health and security reports.

editors/zed · high confidence

Introduce Node.js bindings for programmatic analysis API

This change adds a new NAPI-based interface (\crates/napi/src/lib.rs\) that exposes the underlying analysis engine to Node.js applications. It defines structured options for various analysis modes—including dead code, duplication, similar code, feature flags, and complexity—allowing users to configure parameters such as root paths, thread counts, caching, and specific detection flags (e.g., unused exports, circular dependencies, Svelte/Vue-specific checks) directly from JavaScript/TypeScript code.

crates/napi/src · high confidence

Introduce V8 coverage parsing and UTF-16 offset mapping

Added a new \v8-coverage\ crate that parses V8 \ScriptCoverage\ JSON dumps (emitted by Node, c8, or the Inspector protocol) and converts V8's UTF-16 code-unit source offsets into Istanbul-compatible 1-indexed line and 0-indexed column positions. This provides the foundational data structures (\V8CoverageDump\, \ScriptCoverage\, \LineOffsetTable\) required for the runtime-coverage pipeline, ensuring accurate line/column mapping for sources containing non-ASCII characters.

crates/v8-coverage · high confidence

Introduce \`fallow coverage\` subcommands for runtime coverage analysis and cloud uploads

The CLI now includes a new \fallow coverage\ command group with five subcommands: \setup\ for resumable first-run configuration, \analyze\ for processing local runtime coverage artifacts or fetching data from the Fallow Cloud, \upload-inventory\ for pushing static function inventories, \upload-source-maps\ for uploading build source maps, and \upload-static-findings\ for pushing static dead-code verdicts. This enables users to integrate runtime coverage data with static analysis for a comprehensive view of code health, with explicit support for cloud-based analysis and CI integration.

crates/cli/src/coverage · high confidence

Introduce \`fallow license\` CLI subcommand for license management

The CLI now includes a dedicated \fallow license\ command with subcommands to activate, check status, refresh, and deactivate licenses. Activation supports installing a JWT directly, reading from a file or stdin, or obtaining a 30-day trial via email. The status command displays tier, seats, features, and remaining days. Refresh fetches a new JWT from the API, supporting a fallback to a full-access API key if the current license is missing or stale. All network-bound flows verify the JWT offline using an embedded Ed25519 public key. Output is available in human-readable or JSON formats, with sensitive data like JWTs and API keys redacted in logs.

crates/cli/src/license · high confidence

Introduce comprehensive auto-fix capabilities for dead-code findings

The \fallow fix\ command now automatically applies safe, atomic edits to source files and configuration to remove unused code. This update adds dedicated fixers for unused dependencies (removing entries from \package.json\), unused catalog entries (cleaning \pnpm-workspace.yaml\), unused exports (removing or pruning \export\ statements), unused enum members (folding entire enum declarations when all members are unused), and unused class members. It also introduces a config fixer that automatically adds \ignoreExports\ rules to \.fallowrc.json\ to suppress duplicate export warnings. All fixes are applied with strict safety checks, preserving file encodings (UTF-8 BOM, CRLF/LF), handling dry-run previews, and withholding mutations when analysis confidence is low or the code is referenced off-graph.

crates/cli/src/fix · high confidence

Introduce data-driven security candidate detection with stable finding identities

The security analysis capability now uses a data-driven catalogue (security\_matchers.toml) to detect syntactic security-sink candidates for issues like dangerous HTML (CWE-79), OS command injection (CWE-78), and code injection (CWE-94/95). This catalogue supports framework-specific gating via dependency enablers and precise argument-shape filtering to reduce false positives. To ensure consistent reporting across JSON and SARIF outputs, stable rule and per-finding correlation IDs are now generated deterministically from the rule, file path, and line number. Additionally, security rules are automatically promoted from 'off' to 'warn' by default, and severity is derived based on runtime hotness, boundary crossings, and source reachability.

crates/security · high confidence

Introduce declarative rule-pack policy engine

The analysis engine now supports configurable rule packs that allow teams to define custom policies for banned calls, imports, exports, and catalogue-derived effects. These rules can be scoped to specific file paths, exclude patterns, and boundary zones, with configurable severity levels and suppression support. The system evaluates these rules against the module graph to report policy violations, enabling enforcement of architectural constraints and coding standards beyond the default linter rules.

crates/core/src/analyze/policy · high confidence

Introduce granular CLI check filtering and rule application

The CLI check command now supports a comprehensive set of \--\<rule-name\>\ flags (e.g., \--unused-exports\, \--private-type-leaks\, \--circular-deps\) that allow users to selectively enable or disable specific issue types during analysis. This change introduces a new \IssueFilters\ struct and a dedicated \filtering\ module that handles both these explicit CLI filters and diff-based scoping (retaining only findings on changed lines). Additionally, the \rules\ module now enforces severity-based filtering, ensuring that findings are suppressed according to the \ResolvedConfig\ rules, including per-file overrides for dead-code and framework-specific issues.

crates/cli/src/check · high confidence

Introduce graph crate for module dependency analysis and project state management

The new \crates/graph\ crate provides the core infrastructure for codebase intelligence by constructing module dependency graphs, resolving import specifiers, and tracking export usage. It introduces \ProjectState\ to manage centralized project state, including a file registry with stable, path-based \FileId\ assignment for deterministic lookups and workspace-aware queries. The implementation uses \FxHashMap\ for performance and includes comprehensive tests to verify file ID stability and workspace resolution logic.

crates/graph/src · high confidence

Introduce local similar-code intelligence with offline embedding

The API now includes a local similar-code discovery feature that runs entirely offline. This change adds a new \similar\_code\ module that orchestrates a trusted local companion binary (sidecar) to generate source embeddings. It handles provider discovery, validates model integrity via SHA-256, manages a persistent bounded cache for vectors, and enforces strict timeouts and input/output size limits during inference.

_crates/api/src/similar\code · high confidence

Introduce local similar-code intelligence with offline model support

The \tools/similar-code-sidecar\ now provides local code intelligence by downloading and running the Jina AI \jina-embeddings-v2-base-code\ model directly on the user's machine. This change adds a \setup\ command to install the pinned Apache-2.0 model into a local cache directory (verified via SHA-256) and a \serve\ command that processes code embeddings via stdin/stdout without sending source code to external servers. The sidecar enforces strict resource limits (e.g., max functions, total bytes, timeout) and reports readiness status, enabling offline, privacy-preserving similar-code analysis.

tools/similar-code-sidecar · high confidence

Introduce optional local similar-code analysis with signed native sidecar

The npm package now includes an optional \fallow-similar-code\ sidecar that enables local, offline duplicate-code detection. Users run \fallow similar-code setup --local\ to download pinned Apache-2.0 model artifacts into the user cache. The sidecar binaries are distributed as platform-specific packages (e.g., \@fallow-cli/fallow-similar-code-darwin-arm64\) and are launched via a launcher that verifies each binary's detached Ed25519 signature and SHA-256 digest before execution, failing closed on any mismatch. The main \fallow\ package ships launcher shims for \fallow-lsp\ and \fallow-mcp\ that delegate to the single multicall binary, and the distribution includes platform READMEs, a \.fallowrc.json\ entry configuration, and \.npmrc\ settings to enforce minimum release ages.

npm · high confidence

Introduce runtime coverage analysis with signed sidecar verification

The \fallow health\ command now integrates runtime coverage analysis, powered by a dedicated sidecar binary. This new capability includes Ed25519 signature verification for the sidecar binary to ensure integrity, automatic license validation for the feature, and the ingestion of V8 and Istanbul coverage data to identify production coverage gaps. The implementation adds a new \coverage\ module within the health subsystem to handle the complex logic of mapping runtime execution data back to source code, including source map resolution and function identity matching.

crates/cli/src/health · high confidence

Introduce stable type-aware semantic analysis client

The API now includes a new type-aware client module that implements a batched semantic protocol for analyzing dead code, symbol usage, and type coupling. This change adds the client-side logic to construct bounded semantic queries (for symbol use, trace, impact, API surface, and type coupling) and reconcile the responses against local analysis results. Users benefit from more robust, identity-aware semantic analysis that degrades gracefully on identity mismatches rather than failing, supports bounded generic scans, and correctly normalizes Windows paths for consistent cross-platform behavior.

_crates/api/src/type\aware/client · high confidence

Introduce standalone MCP server crate with stdio entry point and static reference resources

The \crates/mcp\ crate now provides the standalone \fallow-mcp\ binary and the \fallow mcp-server\ subcommand, wiring the MCP tool router over stdin/stdout via a dedicated multi-threaded Tokio runtime. The server honors \--version\ flags before starting the stdio handshake and exposes static, read-only reference resources (tool manifest, issue-type registry, explain index, task matrix, and JSON schemas) via the \fallow://\ URI scheme, alongside long-form per-tool guides for \check\_health\ and \get\_cloud\_runtime\_context\.

crates/mcp/src · high confidence

Introduce trigger-tree telemetry for documentation discoverability

Added a new \.trigger-tree\ integration to measure which maintainer documentation Codex and Claude Code discover. The setup pins trigger-tree v1.23.2, configures prompt logging to hash-only mode via \config.sh\, and establishes a static discoverability gate (\gate.json\) that enforces a score of 100 on Git-visible documentation structure in CI.

.trigger-tree · high confidence

Introduce type-aware TypeScript analysis sidecar

The \tools/type-aware-sidecar\ package is now available, providing a standalone Node.js service for type-aware semantic analysis. It includes a CLI for running analysis queries and a session mode for streaming requests, communicating via a defined wire protocol (version 7) with a TypeScript-Go backend (version 7.0.2). The sidecar implements core graph algorithms for cycle detection, semantic identity resolution, and project state management, while also handling platform-specific requirements like Windows child process policies and preflight checks to ensure the correct TypeScript version is resolved.

_crates/api/src/type\aware/transport, tools/type-aware-sidecar · high confidence

Introduces a new Styling Health score and grade axis

The engine now calculates a dedicated Styling Health score (0–100, letter grade) based on structural CSS analytics, operating as a second axis orthogonal to the existing JS/TS code health. This score evaluates five penalty categories—duplication, dead surface, broken references, token erosion, and structural issues—using a v3 rubric that down-weights exact CSS duplication in favor of detecting value drift and inconsistency. The grade includes a confidence flag that marks the result as low-confidence when the analyzed CSS surface is too sparse (fewer than 50 authored declarations) or predominantly atomic CSS-in-JS, ensuring that thin projects are not penalized unfairly.

_crates/engine/src/health/styling\score · high confidence

Introduces robust subprocess lifecycle management with process-tree cleanup and busy-executable retries

The \crates/process\ library now provides a unified system for managing child processes, ensuring they are properly cleaned up via OS-level process trees (Unix process groups and Windows Job Objects) rather than relying on fragile PID tracking alone. It includes a process-wide registry that tracks live children and a \drain\_and\_kill\ function for bounded, signal-safe shutdown cleanup. Additionally, spawn operations now automatically retry with exponential backoff when encountering transient \ExecutableFileBusy\ errors, preventing failures during rapid package manager or build-tool activity.

crates/process · high confidence

LSP server overhaul with type-aware analysis, React intelligence, and scoped diagnostics

The LSP server in \crates/lsp/src\ has been rebuilt to support type-aware TypeScript analysis, React component intelligence (render-site counts, prop/hook usage), and scoped diagnostics via a \changedSince\ filter. Users now see inline complexity lenses, security candidate hovers, and duplication findings directly in their editor, with diagnostics filtered by git scope and muted categories. The server also handles document staleness to prevent stale diagnostic publishing and supports multi-root workspaces with optimized hashing.

crates/lsp/src · high confidence

New CI summary templates for audit, check, combined, and health reports

The CI pipeline now uses new \jq\ scripts in \ci/jq/\ to generate structured Markdown summaries for GitHub Actions and GitLab CI. \summary-audit.jq\ renders a comprehensive audit report covering dead code, complexity, duplication, and styling, including new categories like boundary violations, policy violations, and Next.js-specific issues (route collisions, misplaced directives). \summary-check.jq\ provides a detailed breakdown of code issues (unused exports, dependencies, catalog entries, etc.) with collapsible sections. \summary-combined.jq\ merges check, duplication, and health data into a single view, adding health score trends and runtime coverage findings. \summary-health.jq\ focuses on code complexity and runtime coverage, displaying hot paths and coverage verdicts. These templates standardize the presentation of analysis results across CI platforms.

ci/jq · high confidence

New CLI binaries for schema emission and test-sidecar stubbing

Two new binaries have been added to the CLI crate: \schema\_emit\ and \stub\_sidecar\. The \schema\_emit\ binary (gated by the \schema-emit\ feature) regenerates the \docs/output-schema.json\ file by deriving definitions from the Rust source of truth, merging them with the committed schema, and printing the resulting JSON Schema to stdout, ensuring the published schema stays in sync with the code. The \stub\_sidecar\ binary is a test-only tool (gated by \test-sidecar-key\) that simulates the closed-source \fallow-cov\ sidecar; it reads requests from stdin and emits responses based on the \FALLOW\_STUB\_MODE\ environment variable, allowing the runtime coverage test harness to exercise the full spawn and marshalling pipeline without depending on the proprietary sidecar.

crates/cli/src/bin · high confidence

New CLI migration tool for Knip, JSCPD, and Stylelint configurations

The CLI now includes a migration command that automatically converts existing configuration files from Knip, JSCPD, and Stylelint into the native Fallow format. The tool maps source-specific settings—such as Knip's \rules\ and \ignore\ patterns, JSCPD's duplication thresholds, and Stylelint's selector complexity rules—to their Fallow equivalents, while explicitly warning about unmappable options like JSCPD's reporter configuration or Stylelint's syntax formatting rules. Users can generate the resulting configuration in JSONC, TOML, or JSON formats, with the output automatically mirroring the source file's extension and including helpful comments and documentation links for any dropped or transformed settings.

crates/cli/src/migrate · high confidence

New LSP code actions for unused exports, catalog cleanup, and security candidate suppression

The LSP now provides quick-fix code actions directly in the editor. For unused exports and types, it offers an action to remove the \export\ keyword, with strict re-validation to ensure the edit is safe. For package management, it adds actions to remove unused pnpm catalog entries and empty catalog groups. Additionally, it introduces additive 'suppress' actions for security findings, allowing users to dismiss specific \TaintedSink\ candidates on a single line or all candidates of a kind in a file by inserting \// fallow-ignore-\*\ comments.

_crates/lsp/src/code\actions · high confidence

New TypeScript analysis options and issue types exposed via NAPI bindings

The NAPI bindings now expose a comprehensive set of TypeScript analysis options and result structures, enabling programmatic control over type-aware analysis, duplication detection, and dead code identification. Users can configure type-awareness via \TypeAwareOptions\ (including \require\ modes) and access detailed findings for dead code issues such as \privateTypeLeaks\, \unusedDependencies\, and \devDependenciesInProduction\. Additionally, new interfaces for \SimilarCodeOptions\ and \FeatureFlagsReport\ allow for cosine-similarity based code duplication detection and feature flag analysis directly through the Node.js API.

crates/napi/types · high confidence

New architecture boundary and code-quality detectors

The analysis engine now includes several new detectors to enforce architecture and code quality. It can detect imports that cross defined architecture boundary zones without permission (boundary violations) and identify reachable files that are not assigned to any zone (coverage violations). For React and Preact projects, it flags groups of three or more components with identical prop shapes across multiple files, suggesting a missing shared abstraction. In Next.js applications, it detects dynamic-segment name conflicts in the App Router that cause runtime errors, flags 'use client' files that incorrectly export server-only or route-config names, and identifies unused server actions (use-server exports referenced nowhere). Additionally, it now collects and correlates feature flags with dead code findings to highlight unused guarded code.

crates/core/src/analyze · high confidence

New benchmark suite for performance and accuracy validation

The benchmarks directory now includes a comprehensive suite of scripts and fixtures to validate the tool's performance and accuracy. This includes \bench-ci.sh\ for running real-world projects in CI, and Node.js scripts (\bench.mjs\, \bench-circular.mjs\, \bench-dupes.mjs\) that compare the tool against industry standards like Knip, madge, and jscpd. The suite also provides generators for synthetic circular dependency and duplicate code fixtures, along with a script to download real-world project fixtures (e.g., Vue, Svelte, Next.js) for testing.

benchmarks · high confidence

New built-in plugins for AdonisJS, Angular, Astro, Ava, Babel, Biome, Browser Extensions, Bun, c8, Capacitor, Changesets, commit-and-tag-version, Commitizen, Commitlint, and config parsing infrastructure

The plugin system in \crates/core/src/plugins\ has been expanded with a large set of new built-in framework and tooling plugins. These include dedicated plugins for AdonisJS (v5/v6/v7), Angular (including ng-packagr library entry points), Astro, Ava, Babel (with short-name resolution for presets/plugins), Biome, Browser Extensions (parsing WebExtension/Chrome manifest.json), Bun (including \bunfig.toml\ preload and test root configuration), c8, Capacitor, Changesets, commit-and-tag-version (crediting custom updater modules and bump targets), Commitizen, and Commitlint. Additionally, a comprehensive AST-based config parser (\config\_parser.rs\) and a data-driven config-value dependency crediting system (\config\_value\_credits.rs\) have been added to support these plugins and other framework integrations by extracting imports, config values, and runtime-referenced dependencies from JS/TS configuration files.

crates/core/src/plugins · high confidence

New combined mode output formats and impact tracking

The CLI now supports \--format github-annotations\ and \--format github-summary\ for CI reporting, and \--format json\ output is compacted by default. A new \--churn-file\ option allows providing import churn data for health analysis, and positional PATH arguments are now supported to scope file commands. Additionally, the combined run now records whole-project impact metrics (dead code, complexity, duplication) and cache state telemetry when running without scope narrowing or production overrides.

crates/cli/src/combined · high confidence

New configuration options for architecture boundaries, code duplication, and feature flags

The config crate now supports new sections for defining architecture boundaries (including presets like Layered, Hexagonal, and Bulletproof React), configuring code duplication detection (with options for minOccurrences and ignoreImports), and detecting feature flags via custom SDK patterns. It also introduces validation for user-supplied glob patterns to prevent path traversal and absolute path errors, and adds a finding-ignore matcher to hide specific findings without removing files from the graph.

crates/config/src/config · high confidence

New declarative external plugin system and rule-pack support

The config crate now supports a new external plugin system and declarative rule packs. You can define framework-specific static analysis rules in standalone JSON or JSONC files (rule packs) to ban specific calls, imports, or effects. Additionally, you can register external plugins via TOML, JSON, or JSONC manifests to auto-detect frameworks, define entry points, and configure auto-imports (e.g., for Nuxt components). The crate also introduces a new \config\_writer\ module to safely edit \.fallowrc\ files in place (e.g., for \fallow fix\ actions) and a \fixability\ module to determine if config edits can be applied without fragmenting monorepos.

crates/config/src · high confidence

New extract crate modules for asset normalization, complexity, CSS analytics, and feature flags

The \crates/extract/src\ area introduces several new modules that expand the tool's extraction and analysis capabilities. \asset\_url.rs\ adds a \normalize\_asset\_url\ helper to correctly treat bare filenames as relative paths, preventing them from being misclassified as npm packages. \complexity.rs\ implements a new AST visitor to compute per-function cyclomatic and cognitive complexity, including React-specific metrics like hook density and JSX depth. \css.rs\ and \css\_metrics.rs\ provide a hybrid parser for CSS/SCSS files, extracting class names, imports, and structural analytics like specificity and design token usage. \flags.rs\ adds detection for feature flags across various SDKs (LaunchDarkly, Statsig, etc.) and environment variables. Additionally, \astro.rs\ and \glimmer.rs\ add support for extracting logic from Astro frontmatter and Glimmer templates, while \css\_classes.rs\ enables static class token scanning for typo detection.

crates/extract/src · high confidence

New incremental parse cache with bitcode serialization and size caps

The extraction crate now uses a new on-disk cache to store parsed module information, allowing unchanged files to skip AST parsing on subsequent runs. The cache serializes data using the bitcode library and uses xxh3 content hashing to detect changes. It includes write-time size enforcement with LRU eviction to keep the cache file under a configurable cap, and config-aware invalidation to ensure stale data is not reused when extraction settings change.

crates/extract/src/cache · high confidence

New interactive codebase map visualization

The visualization frontend now includes a new interactive codebase map. This feature introduces a graph-based view of the project, featuring zoomable and pannable navigation, file clustering by directory or import community, and an 'ego' view that highlights a selected file's direct dependencies. The UI includes a toolbar with analysis lenses, a search function, and theme toggling, while the build process now uses Rolldown to bundle the visualization assets.

viz-frontend · high confidence

New local similar-code and type-aware analysis sidecars

This release introduces two new analysis sidecars in the tools directory. The similar-code sidecar (tools/similar-code-sidecar) provides a local, privacy-preserving code similarity engine using the jina-embeddings-v2-base-code model via a Rust Candle backend, with strict artifact verification and no network access during analysis. The type-aware sidecar (tools/type-aware-sidecar) offers TypeScript semantic analysis using a pinned TypeScript 7.0.2 backend, supporting symbol-use, symbol-trace, api-surface, symbol-impact, and type-coupling queries. It includes Windows-specific child process handling and explicitly identifies Svelte virtual-module export gaps as unavailable rather than claiming complete evidence.

tools · high confidence

New programmatic API for analysis context, audit, and output assembly

The \crates/api/src\ module has been significantly expanded with new files that establish the programmatic analysis context resolution, audit result classification, and output serialization contracts. \analysis\_context.rs\ introduces \ProgrammaticAnalysisContext\ to centralize validation, root/config/diff resolution, and thread-pool management for API runs. \audit\_keys.rs\ and \audit\_output.rs\ define the \DeadCodeAuditLedger\ for comparing findings against base snapshots and provide typed JSON/SARIF/CodeClimate assembly inputs for audit results. \combined\_output.rs\ and \compact\_output.rs\ implement the serialization logic for combined JSON reports and compact text lines, while \coverage.rs\ standardizes the precedence for Istanbul coverage inputs. \dead\_code\_codeclimate.rs\ and \dead\_code\_sarif.rs\ handle the construction of issues for these specific formats, and \decision\_surface.rs\ exposes the structural decision extraction logic for review briefs.

crates/api/src · high confidence

New programmatic analysis runtime for API consumers

The \crates/api/src/runtime\ module now provides a dedicated programmatic entry point for running analyses (dead code, duplication, health, feature flags, audit, decision surface, and similar code) directly from the API layer, bypassing the CLI. This runtime introduces cooperative cancellation support, allowing long-running analyses to be stopped mid-flight via a cancellation token, and implements typed programmatic output structures for all analysis sections. It also handles configuration loading, production mode resolution, and workspace scoping for programmatic callers.

crates/api/src/runtime · high confidence

New report output formats: shields.io SVG badges, GitHub annotations/summaries, and CodeClimate

The CLI now supports several new report formats. You can generate shields.io-compatible SVG badges for your project health using \--format badge\. For CI integration, \--format github-annotations\ emits GitHub Actions workflow commands, while \--format github-summary\ produces a markdown job summary. Additionally, \--format codeclimate\ outputs issues in the CodeClimate JSON format, compatible with GitLab Code Quality reports.

crates/cli/src/report · high confidence

New rule-pack templates and agent onboarding scaffolding

The CLI now ships with five new rule-pack templates (ai-safe-repo, clean-architecture, next-app-router, side-effect-free-domain, starter) to help teams enforce architectural and security policies out of the box. Additionally, the \fallow agent\ command now includes a new onboarding flow that scaffolds \AGENTS.md\ and \CLAUDE.md\ files and registers the \fallow-mcp\ server with supported coding agents (Claude, Codex, Cursor), including a PreToolUse gate script to ensure agents run analysis before editing.

crates/cli/src · high confidence

New scripts for CI validation, benchmarking, and code quality enforcement

The scripts directory now includes a suite of new tooling to enforce quality and reliability standards. A new allocation regression checker (alloc-check.sh) compares Rust benchmark results against a baseline to detect memory usage increases. An assertion script (assert-local-resolution.mjs) prevents Node module resolution from escaping the repository checkout, ensuring deterministic builds in nested worktrees. Documentation integrity is improved with scripts that validate agent doc anchors, check audit schema synchronization between Rust sources and Markdown, and verify CI summary row parity between GitHub and GitLab. Additionally, a comment quality checker (check-comment-quality.mjs) scans source code for low-value 'narrator' comments, and a benchmark harness validator (check-benchmark-harness.py) ensures CI benchmark configurations remain consistent with Cargo declarations.

scripts · high confidence

New structured output contracts for audit briefs, decision surfaces, and review workflows

The \crates/output\ crate now includes a comprehensive set of new modules defining the JSON schemas and data structures for the audit and review subsystems. This introduces the \ReviewBrief\ envelope (schema v10) for triage and impact closure facts, the \DecisionSurface\ envelope (schema v1) for ranking structural decisions by consequence, and the \WalkthroughGuide\ for agent-driven review directions. It also adds specific output contracts for branching conservation analysis (\audit\_branching\), weighted focus maps with runtime-backed skip labels (\audit\_focus\), SARIF assembly for duplication and health reports (\analysis\_sarif\), and styling audit context rendering (\audit\_render\). These changes formalize the wire format for reviewer routing, blast-radius reporting, and decision-surface actions, replacing ad-hoc structures with versioned, schema-validated envelopes.

crates/output · high confidence

New tokenizer for duplication detection with CSS canonicalization and SFC support

The duplication detector now uses a new tokenization layer in \crates/engine/src/duplication\_detector/tokenize\ that supports Single File Components (Vue, Svelte, Astro, MDX) by extracting and tokenizing their script, template, and style regions separately. It introduces CSS value canonicalization in the style path—collapsing zero units (e.g., \0px\ to \0\) and expanding hex colors (e.g., \\#fff\ to \\#ffffff\)—so near-miss CSS clones are detected without affecting JS/markup tokenization. The tokenizer also supports type stripping for cross-language clone detection between \.ts\ and \.js\ files, and can skip import/re-export declarations to reduce noise. Comprehensive tests cover basic tokenization, CSS canonicalization, edge cases, ES modules, expressions, import skipping, JSX, operators, and type stripping.

_crates/engine/src/duplication\detector/tokenize · high confidence

New visitor module for AST-based module extraction

The \crates/extract/src/visitor\ directory has been introduced to handle the AST-based extraction of module information. This new module includes helpers for Angular component metadata, React/JSX structural extraction, and a comprehensive visitor implementation that tracks exports, imports, class members, and framework-specific patterns like DI and security sinks. It also includes extensive unit tests to validate the extraction logic.

crates/extract/src/visitor · high confidence

Opt-in hardcoded secret detection and security finding ranking

The security analysis now includes an opt-in detector for hardcoded secrets, identifying static string literals that match provider token shapes or exhibit high entropy corroborated by secret-shaped identifiers. Additionally, security findings are now ranked by runtime reachability, source-backed evidence, and dead-code context to help prioritize the most impactful candidates for verification.

crates/core/src/analyze/security · high confidence

Stable type-aware TypeScript analysis integration

The API now includes a stable, shared client for optional TypeScript semantic analysis, enabling more accurate dead-code detection and symbol impact tracing by leveraging a companion process. This change introduces a new \type\_aware\ module that manages the lifecycle of the semantic sidecar, handles protocol communication, and refines programmatic analysis results to ensure consistency with TypeScript types. Users benefit from improved precision in identifying unused code and understanding symbol dependencies when the feature is enabled.

_crates/api/src/type\aware · high confidence

Structured audit cache keys and cache-rejection diagnostics

The \crates/types\ crate now exposes typed models for the audit base-snapshot cache key (\AuditCacheKeyPayload\ and \AuditCacheKeyBuilder\) and a detailed \CacheRejection\ enum that explains why a persisted cache was not reused. For users, this means the tool can now distinguish between a first run, a legitimate content drift, and actionable issues like config drift, format version mismatches, or oversized blobs, providing clearer diagnostics and more reliable cache behavior during audits.

crates/types · high confidence

VS Code extension overhaul with LSP client, tree views, and status bar

The VS Code extension has been rebuilt to provide a richer, more robust analysis experience. It now features a dedicated LSP client for real-time diagnostics, a sidebar tree view for browsing findings, and a status bar for quick access to audit verdicts and health metrics. The extension includes a new baseline command to set analysis scope, improved binary resolution logic to handle local and managed installations, and a single-flight analysis mechanism to prevent race conditions. Users will see enhanced feedback through inline complexity decorations, progressive disclosure of health details, and clearer error handling with automatic backoff on repeated failures.

editors/vscode/src · high confidence

Architecture

Human report rendering is modularized into dedicated submodules

The human-readable report output logic has been reorganized from a monolithic structure into distinct, focused submodules (check, cross\_ref, dupes, health, health\_hotspots, health\_runtime, health\_targets, perf, traces, and walkthrough). This change improves code maintainability and readability by separating the rendering concerns for different analysis categories—such as dead code, duplication, health metrics, and performance timings—into their own files, while preserving the existing user-facing output format and behavior.

crates/cli/src/report/human · high confidence

Refactored import resolution into a modular, session-based architecture

The import resolution engine in \crates/graph/src/resolve\ has been restructured into distinct submodules (\static\_imports\, \dynamic\_imports\, \require\_imports\, \re\_exports\, \fallbacks\, etc.) to improve maintainability and testability. This change introduces a \ResolverSession\ struct that caches expensive setup state (such as workspace canonicalization and resolver construction), allowing callers to reuse this state across multiple resolution runs for better performance. The refactoring also adds specific fallback strategies for SCSS partials, CSS extensions, and path aliases, while ensuring that dynamic imports and CommonJS \require\ calls are resolved uniformly into the graph's internal representation.

crates/graph/src/resolve · high confidence

Behavioural changes

Align configuration format with oxlint conventions

The project configuration format has been updated to match oxlint conventions, requiring users to migrate their existing configuration files to the new structure.

(repo-wide) · high confidence

CI reports now scope findings to changed lines via diff filtering

The CLI now supports filtering analysis results to only those findings that overlap with the current code diff, reducing noise in CI comments. Users can provide the diff via the \--diff-file\ flag, \--diff-stdin\ for piped input, or the \FALLOW\_DIFF\_FILE\ environment variable. The system respects the \FALLOW\_DIFF\_FILTER\ environment variable to control filtering granularity (e.g., \added\, \diff\_context\, \file\, or \nofilter\). Additionally, the \FALLOW\_SUMMARY\_SCOPE\ variable allows limiting the PR comment summary to the diff scope. This change ensures that CI reviews and PR comments primarily highlight issues relevant to the current changeset.

crates/cli/src/report/ci · high confidence

CI summaries now use modular jq scripts for annotations, filtering, and reporting

The GitHub Action and GitLab CI summary generation has been refactored from monolithic scripts into a set of modular jq files (annotations-check, annotations-dupes, annotations-health, filter-changed, summary-audit, summary-check). This change introduces precise, file-scoped filtering for PR comments when the 'changed-since' mode is active, ensuring annotations only appear for modified files while preserving project-wide dependency findings in the total count. It also standardizes the output format for annotations and audit summaries, adding support for new finding types such as boundary violations, policy violations, Next.js directive issues, and pnpm catalog errors, while improving clarity with caveats for findings based on incomplete file reads.

action/jq · high confidence

CSS health analytics split into specialized submodules

The CSS analytics engine in the health module has been reorganized into dedicated submodules (classes, cva, markup\_scan, near\_duplicates, preprocessor, theme\_tokens, and token\_consumers) to improve maintainability. This refactoring introduces specific new analysis capabilities: detection of likely CSS class typos in markup via one-edit distance suggestions, identification of duplicate variant blocks and token drift in Class Variance Authority (CVA) usage, and improved handling of preprocessor virtual stylesheets. It also enhances theme token analysis by detecting unused Tailwind v4 @theme tokens and near-duplicate styling values (colors, lengths, shadows) across the project, while adding logic to abstain from analysis in preprocessor-dominant projects to reduce false positives.

_crates/engine/src/health/css\analytics · high confidence

CSS-in-JS styling analytics now support object notation and design tokens

The styling-health analytics pipeline now covers CSS-in-JS libraries that use object-literal styles (StyleX, Panda, vanilla-extract, and emotion) in addition to the previously supported tagged-template forms. Object-style styles are serialized into virtual stylesheets and split into three categories—structural, structural-partial, and atomic—so the engine can correctly apply duplicate-detection and structural-grade policies depending on whether the library produces flat atomic CSS. The pipeline also extracts design-token definitions and cross-module consumer usage for StyleX, vanilla-extract, and Panda, enabling token blast-radius analysis. These changes are health-time-only and do not affect the extraction cache.

_crates/extract/src/css\_in\js · high confidence

Core engine refactoring and new analysis capabilities

The core analysis engine has been significantly restructured: the monolithic analyze.rs, discover.rs, graph.rs, and resolve.rs modules have been removed and replaced with a new plugin-based architecture and extracted crates (fallow-extract, fallow-graph). This change introduces a new error handling system (FallowError) with actionable help text and error codes, a new suppression context that tracks used vs. stale suppressions, and new capabilities for detecting external style package usage and managing git environment variables to prevent hook-related failures. Additionally, a new progress spinner UI has been added for the analysis pipeline, and package asset patterns for scaffolding templates are now automatically derived from package.json files.

crates/core/src · high confidence

Duplication detector now uses persistent token caching and near-miss detection

The duplication analysis engine in \crates/engine/src/duplication\_detector\ has been restructured to include a persistent token cache that validates file identity via content hashing (falling back to metadata when unavailable) to prevent stale reports after timestamp-altering operations like \git checkout\. Additionally, a new near-miss detection module using MinHash and shingle filtering has been added to identify functionally similar but not identical code, while the core detection logic now groups clones into families with automated refactoring suggestions (extract function or module) and generates stable, collision-resistant fingerprints for traceability.

_crates/engine/src/duplication\detector · high confidence

Enforce local pre-commit and pre-push quality checks

The repository now installs local Git hooks that automatically run Rust formatting (cargo fmt), linting (clippy), and typo checks before every commit, and additional checks before every push. The pre-commit hook also scans for hidden Unicode characters and validates commit messages using commitlint (skipping locally if node\_modules is missing, as CI enforces this). The pre-push hook unsets GIT\_DIR and GIT\_WORK\_TREE to prevent environment leakage into spawned processes, then runs fmt and clippy again to ensure code quality before pushing. These changes shift more validation to the local developer environment while keeping heavier checks like Miri and full test suites in CI to respect budget constraints.

.githooks · high confidence

Graceful shutdown and orphan process reaping on Ctrl+C

The CLI now installs signal handlers for SIGINT/SIGTERM (Unix) and console control events (Windows) to prevent orphaned subprocesses when the user interrupts the command. By default, the handler kills all registered child processes, drains them within a bounded time budget, and exits with a standard signal-based exit code (130 for interrupt, 143 for terminate). For the \fallow watch\ command, the CLI enters a cooperative shutdown mode where the handler only signals shutdown, allowing the watch loop to exit cleanly with code 0 while still ensuring in-flight git subprocesses are reaped.

crates/cli/src/signal · high confidence

Graph crate refactored into focused submodules with new analysis capabilities

The graph crate has been restructured from a single large module into focused submodules (ambiguity, build, cycles, effective\_exports, etc.) to improve maintainability and reduce complexity. This refactoring introduces new analysis capabilities including star-export collision detection (ambiguity.rs), circular dependency enumeration via Tarjan's algorithm (cycles.rs), effective export binding resolution with namespace awareness (effective\_exports.rs), and impact-closure computation for change-impact analysis (impact\_closure.rs). The module now provides fan-in/fan-out metrics for blast-radius estimation (fan\_io.rs) and tracks re-export routes for accurate symbol provenance (effective\_re\_exports.rs). These changes enable more precise dead-code detection, better coordination-gap reporting for cross-module changes, and improved handling of complex re-export patterns including star exports and namespace aliases.

crates/graph/src/graph · high confidence

Health engine refactored into modular pipeline with identity-preserving baselines and coverage intelligence

The health analysis engine has been restructured into a modular pipeline (actions, analysis\_data, assembly, baseline\_io, branching, churn\_file, component\_rollup, core\_pipeline, coverage\_gaps, coverage\_intelligence) to improve maintainability and introduce new capabilities. Users now benefit from identity-preserving baseline modes that track file moves and warn on partial staleness, ensuring baselines remain robust across refactors. The engine also introduces Coverage Intelligence, which provides actionable findings for risky changes, deletions, and review needs by combining runtime coverage, test coverage, and complexity metrics. Additionally, Angular component complexity rollups now correctly aggregate template and class function complexity, and coverage gap reporting has been refined to exclude stylesheets and respect file-level suppressions.

crates/engine/src/health · high confidence

Improved dependency usage detection in CI pipelines and CLI flag arguments

The script analysis engine now scans CI configuration files (\.gitlab-ci.yml\ and \.github/workflows/\*.yml\) to identify npm packages and entry-point files used in pipeline commands, preventing false "unused dependency" reports for tools invoked only in CI. Additionally, a new CLI flag-credit system recognizes packages loaded via specific flag values (e.g., \eslint --format gha\ loading \eslint-formatter-gha\), ensuring dependencies used exclusively through such conventions are correctly credited.

crates/core/src/scripts · high confidence

Improved re-export chain resolution and cycle detection

The graph module now features a dedicated re-export propagation system that accurately resolves star and named re-export chains, ensuring references are correctly credited to their original source modules even through complex barrel files. This update introduces explicit detection and reporting of re-export cycles (including self-loops) as user-visible findings, and hardens the resolution logic to prevent silent truncation of re-export chains. Additionally, the system now correctly handles type-only re-exports and ambient module exports, improving the accuracy of unused export detection and reference tracking.

_crates/graph/src/graph/re\exports · high confidence

Introduce offline Ed25519 license verification with clock-skew tolerance

The \crates/license\ crate now provides offline JWT verification for the Fallow CLI, enforcing Ed25519 signature validation and rejecting tokens with an \iat\ claim exceeding a 24-hour clock-skew tolerance (configurable via \FALLOW\_LICENSE\_SKEW\_TOLERANCE\_SECONDS\). License material is loaded from environment variables or the user's home directory, and the system exposes a grace period with watermarking for expired licenses before enforcing a hard fail.

crates/license · high confidence

MCP tools now use typed API paths with CLI fallback

The MCP server tools in \crates/mcp/src/tools\ have been refactored to execute analysis commands through a typed programmatic API when parameters map cleanly, falling back to CLI argument construction only for unsupported surfaces like baselines, regressions, or type-aware analysis. This change introduces a new \api\_runtime\ module that handles blocking execution, timeouts, and structured error reporting, while tools like \analyze\, \audit\, and \check\_changed\ now support direct API calls without spawning a subprocess for standard operations, improving performance and reliability for agent-driven workflows.

crates/mcp/src/tools · high confidence

Modularized LSP diagnostics by issue type

The LSP diagnostics module has been refactored to organize diagnostic generation into distinct files by category (quality, structural, unused, and security). This change introduces a centralized \build\_diagnostics\ function that aggregates results from these modules, enabling clearer separation of concerns for duplicate exports, code duplication, circular dependencies, re-export cycles, boundary/policy violations, Next.js structural issues, unused code, and security candidates.

crates/lsp/src/diagnostics · high confidence

New file, import, and lifecycle analysis predicates

The analysis engine now includes a dedicated \predicates\ module that centralizes detection logic for file types (such as React JSX, TypeScript declarations, HTML, test/spec files, and tooling configuration files), import characteristics (including Node.js/Bun/Deno builtins, virtual modules, path aliases, and implicit dependencies), and framework-specific lifecycle methods (Angular and React). This refactoring consolidates previously scattered checks into reusable functions, ensuring that configuration files are excluded from unused-file reports, virtual modules are not flagged as unresolved imports, and framework-invoked lifecycle methods are correctly identified as used.

crates/core/src/analyze/predicates · high confidence

New framework-specific template scanners for Angular, Glimmer, Vue, and Svelte

The \crates/extract/src/sfc\_template\ module now includes dedicated scanners for Angular, Glimmer, Vue, and Svelte templates. The Angular scanner (\angular.rs\) extracts member references from external HTML files and inline templates, supporting Angular 17+ control flow (\@if\, \@for\, \@defer\) and strict-mode Glimmer/Ember components (\glimmer.rs\) via a custom tokenizer. Vue (\vue.rs\) and Svelte (\svelte.rs\) scanners are refactored to handle Single-File Component (SFC) structures, including typed iteration variables for \v-for\ and \{\#each}\ blocks, and Svelte 5 runes extraction. These changes improve the accuracy of unused member detection by correctly crediting class members and imports referenced in framework-specific template syntax.

_crates/extract/src/sfc\template · high confidence

New suffix array-based duplication detection engine

The duplication detection engine has been replaced with a new implementation that uses a suffix array and Longest Common Prefix (LCP) array to identify code clones in linear time, avoiding the previous quadratic pairwise comparisons. This new engine introduces a multi-step pipeline: token ranking, concatenation with sentinels, suffix array construction (SA-IS), LCP scanning, clone group extraction, and result filtering. It supports a rolling detection mode for incremental analysis, handles boundary tokens (e.g., in component files), and includes detailed statistics reporting. The change also adds comprehensive tests for the new detection logic, including boundary handling and empty input cases.

_crates/engine/src/duplication\detector/detect · high confidence

Plugin registry refactored into modular components with expanded built-in plugin support

The plugin registry has been restructured into focused submodules (builtin.rs, helpers.rs, mod.rs, tests.rs) to improve maintainability and performance. This change introduces a comprehensive catalog of built-in plugins for frameworks (Next.js, Nuxt, Remix, Astro, Angular, SvelteKit, etc.), build tools (Vite, Webpack, Rollup, Turborepo), testing frameworks (Vitest, Jest, Playwright, Cypress), and quality tools (ESLint, Biome, Prettier, Tailwind). The refactoring includes performance optimizations such as lazy caching of config matchers and optimized file discovery patterns, while adding extensive test coverage for plugin detection logic including edge cases like production filtering and scoped package matching.

crates/core/src/plugins/registry · high confidence

Pre-bash guard hook prevents unsafe agent commands

A new Python hook at \.claude/hooks/pre-bash-guard.py\ intercepts Bash tool invocations to enforce safer agent behavior. It blocks the use of globally installed \fallow\ binaries, requiring the local \cargo run\ or target binary instead, and prevents unbounded \cargo --workspace\ output from flooding context by enforcing redirection or paging. Additionally, it stops commits that stage VS Code extension runtime files without the corresponding built dist bundle, guiding users to run the necessary build and lint steps first.

.claude/hooks · high confidence

Refactored GitHub Action into modular, verifiable shell scripts

The GitHub Action's internal logic has been extracted from a monolithic structure into a set of dedicated, executable scripts (analyze, annotate, broker-token, check-code-scanning, comment, install, review, summary, and verify-installed). This change introduces explicit binary verification using Ed25519 signatures and SHA-256 digests to ensure the integrity of the installed Fallow CLI. It also adds a branded token broker to allow PR comments and reviews to be authored by the Fallow app rather than the generic GitHub Actions bot, and improves robustness by disabling inherited \errexit\ flags and handling SARIF uploads for public repositories without requiring GitHub Advanced Security.

action/scripts · high confidence

Refactored source discovery into modular entry-point and infrastructure parsers

The source discovery logic in \crates/core/src/discover\ has been restructured into distinct modules (\entry\_points\, \infrastructure\, \parse\_scripts\, \walk\) to improve maintainability and performance. This change introduces dedicated parsing for infrastructure configuration files (Dockerfile, Procfile, fly.toml) to detect external process entry points, and refines \package.json\ script parsing to accurately identify script file references across various runners (node, tsx, bun, etc.). The file walking logic now includes stricter size-based filtering to skip large minified assets and prevents out-of-memory issues by bounding the scan of skipped hidden directories, while also consolidating entry-point deduplication and warning logic.

crates/core/src/discover · high confidence

Regression detection now supports configurable tolerance and schema versioning

The CLI's regression check now allows users to define a tolerance threshold (either absolute count or percentage) for allowed issue increases, preventing CI failures for minor regressions. The baseline format has been updated to schema version 2, which includes a compatibility identity to ensure counts are compared against the correct analysis mode, and adds forward-compatible fields for new issue types like unused store members and boundary violations.

crates/cli/src/regression · high confidence

Unified 'fallow' binary supports CLI, LSP, and MCP modes

The packaged \fallow\ binary now acts as a single entry point that routes to the CLI, LSP server, or MCP server depending on the subcommand. Invocations without a server subcommand (e.g., \fallow --version\, \fallow dead-code\) are delegated verbatim to the existing CLI, ensuring byte-for-byte parity with the standalone CLI binary. Explicit \lsp-server\ and \mcp-server\ subcommands route to their respective bundled server implementations, enabling the same binary to serve as the CLI, the language server, and the MCP server for the VS Code extension and npm packages.

crates/cli/src/coverage/snapshots, crates/multicall · high confidence

VS Code extension regenerates TypeScript contracts from updated schema and engine types

The VS Code extension's generated TypeScript contracts have been regenerated to align with the latest engine and schema changes. The \issue-types.ts\ file now includes a comprehensive set of issue type defaults and aliases, reflecting new detection capabilities such as unused component props/emits/inputs/outputs, Svelte events, Next.js route collisions, and dependency override issues. The \lsp-initialization-options.d.ts\ file introduces new LSP configuration options for duplication modes, health checks, and type-aware analysis. The \output-contract.d.ts\ file has been significantly expanded to include new JSON output envelope types for features like impact analysis, security survivors/blind spots, review walkthroughs, and type-aware status, ensuring the extension's type definitions match the current CLI output schema.

editors/vscode/src/generated · high confidence

Fixes

Fix catalog suppression parsing to preserve quoted content

The unused catalog analysis now correctly handles suppression comments in \pnpm-workspace.yaml\ files that contain quoted strings. Previously, the marker-instrumentation approach used to detect \fallow-ignore\ comments could be confused by multiline quoted scalars or escaped marker text, potentially leading to incorrect suppression behavior. This fix ensures that quoted content within the YAML is preserved during the parsing and scanning process, allowing suppression directives to be applied accurately without false positives or negatives.

_crates/core/src/analyze/unused\catalog · high confidence

Graph cache schema version bumped to 44

The persisted graph cache schema version has been incremented to 44 to reflect significant changes in how import and export references are resolved and credited. This update ensures that cached graphs are rebuilt rather than reused, preventing stale 'unused export' reports caused by previous logic gaps. Key changes include: correctly crediting default exports regardless of how they are spelled on import or export sides; handling MDX prose lines that resemble statements without dropping file imports; treating whole namespace imports as 'mark-all' uses instead of narrowing to specific members; resolving \import X = require\ as CommonJS namespace edges; and properly handling \export type \*\ within ambient module declarations. These adjustments ensure that the persisted graph accurately reflects current resolution semantics for TypeScript, JSX, MDX, and CommonJS patterns.

crates/graph/src/cache · high confidence

Improved unused-class-member detection for complex access patterns

The unused-class-member analysis in \crates/core/src/analyze/members\ has been refactored into specialized submodules to resolve several false positives where class members were incorrectly reported as unused. The new \factory\ module credits accesses made through static-factory call bindings, free-function factory returns, and object-literal factory returns. The \fluent\_chain\ module now recognizes member accesses within fluent builder chains (both standard and constructor-rooted). The \heritage\ module adds support for Angular external-template member accesses and resolves interface-typed property dispatch through implementers. The \instance\ module fixes inheritance tracking by correctly propagating instance-binding fields from base classes to subclasses. Additionally, the \playwright\ module resolves indexed-access fixture types (e.g., \Factory\["getter"\]\) to their underlying class exports, and the \typed\_property\ module credits accesses reached through typed property hops across module boundaries.

crates/core/src/analyze/members · high confidence

The vendored CI script templates in the CLI now use symlinks to point to the shared CI scripts in the workspace root. This ensures that updates to the central CI scripts (such as comment.sh, gitlab\_common.sh, and review.sh) are immediately reflected in the CLI templates without requiring separate bundling or duplication.

crates/cli/templates/ci/scripts · high confidence

Test coverage

Add allocation and large-scale analysis benchmarks; Add component-level benchmark shards for cache, config, engine, graph, output, and programmatic commands; Add coverage producer conformance test corpus; Add sample-app fixture lockfile for review-electron tests; Added API contract and schema conformance tests; Added Deno workspace fixture for testing; Added Docusaurus fixture tests for advanced, classic, and theme-only conventions; Added E2E test fixtures for Playwright webServer command parsing; Added Ember Classic fixture tests for strict-mode Glimmer support; Added Playwright E2E test fixture for pnpm exec web server; Added Playwright fixture tests for branch aliasing scenarios; Added Playwright fixture tests for mergeTests helper edge cases; Added Playwright test fixture for indexed-access getter types; Added Playwright test fixtures for local setup validation; Added React component health test fixtures; Added Svelte project fixture for testing template and import analysis; Added TypeScript compile-time tests for similar-code API types; Added Vue inject fixture tests for unprovided keys and collision scenarios; Added Vue project fixture for testing SFC template usage; Added benchmarks for duplication detection and similar code analysis; Added comprehensive integration test suite for core analysis capabilities; Added comprehensive test coverage for the MCP server; Added comprehensive test coverage for the VS Code extension's analysis and diagnostic logic; Added comprehensive unit tests for the extract crate's file-type parsers; Added conformance test fixtures for static analysis edge cases; Added conformance test suite comparing fallow vs knip; Added cross-platform path handling tests; Added duplication accuracy benchmark harness and baseline; Added ecosystem regression tests for real-world JS/TS projects; Added end-to-end integration test for dynamic import .then() patterns; Added integration and stress tests for churn cache and duplicate detection; Added integration test fixture for optional dependencies; Added integration test fixture for the bulletproof boundary preset; Added integration test fixture for workspace app entry point; Added integration test for package.json \#subpath imports; Added integration test harness for VS Code extension; Added integration tests for MCP server capabilities and configuration; Added integration tests for the VS Code extension; Added real-process integration tests for the VS Code extension; Added regression test for feature-flag inline suppression; Added security taint analysis test fixtures; Added semantic clone conformance test corpus; Added test coverage for JavaScript/TypeScript extraction logic; Added test coverage for Vue v-for loop variable class member accesses; Added test coverage for per-class \this\ binding scoping; Added test coverage for vi.mock with no \_\mocks\\_ sibling; Added test fixture for Angular Material SCSS entrypoint resolution; Added test fixture for Angular inherited members and DI-injected references; Added test fixture for Angular inject(InjectionToken) template members; Added test fixture for Angular unprovided InjectionToken detection; Added test fixture for Angular unused component inputs and outputs; Added test fixture for Astro script import extraction; Added test fixture for Bulletproof boundary rules with auto-discovery and strict mode scenarios; Added test fixture for Bun builtin modules; Added test fixture for Bun package.json catalogs; Added test fixture for CLI binary name resolution; Added test fixture for CSS @apply extraction; Added test fixture for CSS package subpath imports; Added test fixture for CSS-in-JS styling with styled-components and Emotion; Added test fixture for Danger plugin activation without dependencies; Added test fixture for ESLint meta-preset plugin resolution; Added test fixture for Express security framework entry-point analysis; Added test fixture for Glimmer TypeScript path aliases; Added test fixture for HTML entry point parsing; Added test fixture for HTML workspace root-relative paths; Added test fixture for Hono-style HTML tagged template literal asset tracking; Added test fixture for Ionic lifecycle hook detection; Added test fixture for Jest mock reachability; Added test fixture for Lit and Web Components detection; Added test fixture for NestJS lifecycle method detection; Added test fixture for Nuxt auto-imported components; Added test fixture for OpenCode plugin configuration; Added test fixture for Oxlint JS plugin compatibility; Added test fixture for Pinia store member access via typed parameters; Added test fixture for Playwright getter-chain unused-member detection; Added test fixture for Prettier package.json string configs; Added test fixture for React Native Storybook support; Added test fixture for SvelteKit remote function analysis; Added test fixture for Tailwind v4 @plugin directive; Added test fixture for TanStack Router virtual route configurations; Added test fixture for URL directory resolution edge cases; Added test fixture for Varlock plugin integration; Added test fixture for Vercel TypeScript configuration usage; Added test fixture for Vite React Babel plugin configuration; Added test fixture for Vite Rollup path-helper inputs; Added test fixture for Vite SCSS additionalData configuration; Added test fixture for Vite array-based alias configuration; Added test fixture for Vite config default export handling; Added test fixture for Vue namespace re-exports; Added test fixture for auto-discover feature boundaries; Added test fixture for barrel default re-export behavior; Added test fixture for barrel export analysis; Added test fixture for broken tsconfig extends chain; Added test fixture for broken tsconfig path aliases; Added test fixture for bun.lockb override resolution diagnostic; Added test fixture for cross-file exported class instances; Added test fixture for cross-package enum and class member exports; Added test fixture for cross-package namespace aliasing via star barrels; Added test fixture for custom ESLint config in hidden directory; Added test fixture for custom route file ignore prefix; Added test fixture for default ignore patterns; Added test fixture for dev-dependency-in-production rule; Added test fixture for electron-vite rollup input parsing; Added test fixture for factory member return-type annotation handling; Added test fixture for iconify credit attribution; Added test fixture for instanceof-narrowed method calls; Added test fixture for issue \#1441 inferred return member crediting; Added test fixture for local namespace export behavior; Added test fixture for local unexported options class handling; Added test fixture for merged namespace star re-export; Added test fixture for mixed path-alias exports; Added test fixture for multi-hop namespace aliasing; Added test fixture for namespace barrel duplicate exports; Added test fixture for namespace re-export member access; Added test fixture for namespace-imported unrendered components; Added test fixture for namespace-object alias credit propagation; Added test fixture for native web components detection; Added test fixture for nested .env.schema discovery; Added test fixture for nested barrel export propagation; Added test fixture for ng-packagr entry point parsing; Added test fixture for orphan MDX file detection; Added test fixture for pnpm bare binary handling; Added test fixture for quoted argument regression; Added test fixture for same-name schema value dependencies; Added test fixture for security dead-code cross-link analysis; Added test fixture for static factory method member crediting; Added test fixture for symbol-level call chain analysis; Added test fixture for tRPC declarative validation security checks; Added test fixture for tracking class member usage through object containers; Added test fixture for type-level enum usage; Added test fixture for typed prop destructuring in Svelte components; Added test fixture for typed-instance monorepo path-alias scenario; Added test fixture for underscore-prefixed prop ignoring; Added test fixture for unreachable mixed exports; Added test fixture for unused re-export detection; Added test fixture for useMemo-bound class instance member crediting; Added test fixture for validating stale suppression detection; Added test fixture for webpack entry pattern handling; Added test fixture for webpack resolve.alias and entry context parsing; Added test fixture for wildcard tsconfig path aliases and Node builtins; Added test fixture to cover coverage gaps; Added test fixtures for Angular @if aliasing; Added test fixtures for Astro and Lit framework health parity; Added test fixtures for Astro/MDX member expressions and MDX prose environment mentions; Added test fixtures for BoundaryZone subtree-relative patterns; Added test fixtures for CLI integration tests; Added test fixtures for CSS fuzzy clone detection; Added test fixtures for Firebase Messaging service worker scenarios; Added test fixtures for GraphQL document imports; Added test fixtures for JSDoc import() types and JSX asset references; Added test fixtures for JSX namespace member access; Added test fixtures for Jest and Vitest manual mock semantics; Added test fixtures for Kibana plugin manifest entry resolution; Added test fixtures for LLM prompt-injection sinks; Added test fixtures for LSP integration testing; Added test fixtures for Lexical custom node lifecycle analysis; Added test fixtures for MDX import handling; Added test fixtures for Next.js 'use client' export validation; Added test fixtures for Next.js App Router route collision detection; Added test fixtures for Next.js route tree collision scenarios; Added test fixtures for Next.js, Nuxt, SvelteKit, Vite, and Vue aliasing and component conventions; Added test fixtures for NoSQL injection, SSTI, XXE, and Zip-slip detections; Added test fixtures for Obsidian plugin support; Added test fixtures for OpenNext Cloudflare configuration scenarios; Added test fixtures for Pinia store member detection; Added test fixtures for Pinia store member detection; Added test fixtures for Playwright wrapper member validation; Added test fixtures for React Compiler configuration; Added test fixtures for React Router route configuration modes; Added test fixtures for React component intelligence and multi-component hook analysis; Added test fixtures for SCSS partial resolution and class inheritance; Added test fixtures for SQL injection detection scenarios; Added test fixtures for Storybook and Vitest entry export detection; Added test fixtures for Svelte snippet handling; Added test fixtures for SvelteKit workspace backend and frontend routes; Added test fixtures for TAP and TSD test runners; Added test fixtures for TypeScript export and type-scoping scenarios; Added test fixtures for Vite plugin usage detection; Added test fixtures for Vitest doMock reachability and manual mocks; Added test fixtures for Vue and Nuxt edge cases; Added test fixtures for Vue, Angular, and Astro iteration binding analysis; Added test fixtures for aliased Sass partial resolution; Added test fixtures for ambient module star re-exports; Added test fixtures for ambient type-star exports; Added test fixtures for analysis consistency gaps; Added test fixtures for architecture boundary violation detection; Added test fixtures for barrel re-export and inheritance scenarios; Added test fixtures for browser extension and web app manifests; Added test fixtures for class member usage analysis; Added test fixtures for client-server leak detection; Added test fixtures for code duplication detection; Added test fixtures for command injection and unsafe deserialization security rules; Added test fixtures for complex re-export scenarios; Added test fixtures for conditional and runtime dynamic imports; Added test fixtures for constructor-receiver and fluent-chain member usage; Added test fixtures for cross-workspace export map resolution; Added test fixtures for dangerous HTML sink detection; Added test fixtures for decorator inheritance, mixed usage, and namespaced decorators; Added test fixtures for default export handling with star re-exports; Added test fixtures for default specifier and CSS module handling; Added test fixtures for detecting disabled TLS validation; Added test fixtures for duplicate exports and type-only cycles; Added test fixtures for dynamic import and context resolution patterns; Added test fixtures for dynamic import literal analysis; Added test fixtures for dynamic import resolution; Added test fixtures for dynamic regex construction detection; Added test fixtures for empty flag outputs; Added test fixtures for external plugin framework support; Added test fixtures for external style package dependencies; Added test fixtures for factory member usage and Pinia store access; Added test fixtures for fluent builder chains and generic-constrained instance bindings; Added test fixtures for framework-aware security sink detection; Added test fixtures for hexagonal architecture boundary presets; Added test fixtures for ignoreExportsUsedInFile configuration; Added test fixtures for import analysis scenarios; Added test fixtures for import-equals edge cases; Added test fixtures for interface and type-alias property hops; Added test fixtures for interface property dispatch; Added test fixtures for issue \#195 scenarios; Added test fixtures for misplaced 'use client' directives; Added test fixtures for mocked module reachability scenarios; Added test fixtures for module analysis scenarios; Added test fixtures for multi-hop taint analysis boundaries; Added test fixtures for object-literal factory returns; Added test fixtures for oxlint JS plugin configuration parsing; Added test fixtures for package import resolution; Added test fixtures for pkg-utils build-config plugin; Added test fixtures for pnpm package source resolution; Added test fixtures for private field dependency injection; Added test fixtures for private-type-leak detection across multiple frameworks; Added test fixtures for re-export cycles; Added test fixtures for root-relative HTML resolution; Added test fixtures for root-relative static asset resolution; Added test fixtures for route loader data analysis; Added test fixtures for rule-pack validation; Added test fixtures for secret and PII logging detection; Added test fixtures for secret-to-network exfiltration detection; Added test fixtures for security catalogue sink batch 2; Added test fixtures for security framework entry-point sources; Added test fixtures for security literal sinks (issue 901); Added test fixtures for shallow nested package script discovery; Added test fixtures for source-backed ReDoS regex sinks; Added test fixtures for star-export ambiguity scenarios; Added test fixtures for super method call extraction; Added test fixtures for suppression inventory command; Added test fixtures for template-based XSS sinks; Added test fixtures for test-only and production dependencies; Added test fixtures for the reactCompilerPreset configuration; Added test fixtures for tsconfig project references; Added test fixtures for tsdown mts and cts config recognition; Added test fixtures for type-aware analysis; Added test fixtures for type-only import boundary rules; Added test fixtures for under-tested scenarios; Added test fixtures for unknown issue-kind suppression handling; Added test fixtures for unlisted dependencies and workspace shared package; Added test fixtures for unprovided Vue inject and Svelte getContext scenarios; Added test fixtures for unreachable code analysis; Added test fixtures for unused Svelte component props; Added test fixtures for unused Vue component props analysis; Added test fixtures for unused code and JSDoc public tag detection; Added test fixtures for unused server actions and misplaced directives; Added test fixtures for virtual and workspace mock resolution; Added test fixtures for whole-object namespace imports; Added test fixtures for workspace dist path aliasing; Added test fixtures for workspace internal dependencies; Added test fixtures for workspace packages without exports; Added test for rspress @theme virtual module resolution; Added test for skipping irrelevant package scans; Added test harness for CLI integration and coverage validation; Added test suite for GitLab CI installation and bash helpers; Added tests for GitHub Action install verification and issue-kind drift guards; Added tests for Playwright factory wrapping fixture constants; Added tests for Playwright fixture helper function; Added tests for nested Playwright fixtures with named aliases; Added unit tests for unused dependency analysis rules; Added utility helper modules to the test fixture workspace; Expanded CLI integration and snapshot test coverage; Expanded Next.js fixture coverage for framework conventions; Expanded SvelteKit fixture with route groups and parameterized routes; Expanded snapshot test coverage for CLI output formats; Integration test coverage for core analysis capabilities.

Dependencies

MCP server migrated to rmcp 2.x

The MCP server implementation in \crates/mcp/src/server\ has been updated to use the rmcp 2.x library. This migration changes the underlying server handler and tool routing infrastructure, which may affect how the server initializes and exposes its tools to clients.

crates/mcp/src/server · high confidence

Housekeeping

Added terminal demo screencast asset

A new terminal recording file (demo.cast) has been added to the assets/screenshots directory, capturing a demonstration of the tool's output including unused files, exports, dependencies, and circular dependency detection within a demo project.

assets/screenshots · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Baseline

  • First survey — no prior run to compare against. CAI 52.

Lenses

  • Code Health 72
  • Architecture 93
  • Maturity 67
  • Readiness 62
  • Security 54
  • Domain Modelling 100
  • Accessibility 40

Changes since last survey

  • 300 commits — 193 feature/other, 107 fixes

By area

  • (root) — 57 commits
  • crates/cli — 47 commits
  • (repo) — 27 commits
  • .github/workflows — 19 commits
  • tests/fixtures — 16 commits
  • apps/review-electron — 15 commits
  • editors/vscode — 13 commits
  • crates/core — 12 commits
  • crates/napi — 12 commits
  • crates/engine — 8 commits
  • crates/mcp — 8 commits
  • crates/extract — 6 commits
  • .agents/skills — 4 commits
  • benchmarks/package-lock.json — 4 commits
  • crates/api — 4 commits
  • docs/development — 4 commits
  • npm/fallow — 4 commits
  • scripts/workflow-policy.test.mjs — 4 commits
  • viz-frontend/package-lock.json — 4 commits
  • .github/scripts — 3 commits

Notable commits

  • fix: Merge pull request #2434 from fallow-rs/fix/similar-code-review-findings
  • fix: chore: start contract drift fix
  • fix: chore: start similar-code review fixes
  • fix: fix(audit): honor health.coverage and health.coverageRoot from config
  • fix: fix(audit): keep concurrent base worktree paths distinct and reclaim abandoned caches (#2500)
  • fix: fix(audit): scope base snapshot to sparse cone and analysis subdir
  • fix: fix(audit): score the base attribution pass with the supplied Istanbul coverage
  • fix: fix(brand): inset the mark inside the icon badge
  • fix: fix(brand): regenerate the icon PNGs from the inset badge
  • fix: fix(brand): round the icon badge to the logo.svg radius
  • fix: fix(brief): stop a hoist to module scope reading as an in-place split (#2539)
  • fix: fix(check): fail strict runs on findings the override path let through (#2447)
  • fix: fix(ci): allow cold-cache check completion
  • fix: fix(ci): complete provider lifecycle reconciliation
  • fix: fix(ci): initialize Windows pnpm cache store
  • fix: fix(ci): name the coverage root only when the coverage file failed to join (#2463)
  • fix: fix(ci): reconcile inline review lifecycles
  • fix: fix(ci): show clone evidence in inline reviews
  • fix: fix(cli): bound the coordination-gap lines on the human review brief (#2565)
  • fix: fix(cli): complete the knip and jscpd migration tables (#2523)
  • …and 280 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

fallow-rs/fallow was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 14 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 8622017e6effcad51ddff304032914e08366de27 — the exact code this score is about.
  • Scored under rubric-2026.09.11 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-af56a6303ce2.