fallow
Codebase intelligence for TypeScript and JavaScript. Finds unused code, duplication, circular dependencies, complexity hotspots, and architecture drift. Optional runtime intelligence layer (Fallow Runtime) adds production execution evidence. Rust-native,
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| semgrep | semgrep:env-spread | AI (semgrep): env-spread is in test harness setting NODE_PATH for spawned launcher; no exfil destination. | ai | |
| semgrep | semgrep:dynamic-require | AI (semgrep): Fires in test files using a constant path variable; stable false positive for this package. | ai | |
| provenance | missing-githead | AI (provenance): SLSA provenance attestation present; missing gitHead is a minor metadata gap, not a security signal. | ai | |
| source-diff | source-size-tripled | AI (source-diff): Size increase is a new .d.ts type declaration file (80KB), not executable payload. | ai | |
| install-scripts | install-script:postinstall | AI (install-scripts): Standard prebuilt-binary selection for Rust-native CLI; platform packages are scoped under @fallow-cli/* as optional deps. | ai |
Versions (showing 100 of 163)
| Version | Deps | Published |
|---|---|---|
| 3.9.1 | 1 / 1 | |
| 3.8.1 | 1 / 1 | |
| 3.8.0 | 1 / 1 | |
| 3.7.1 | 1 / 1 | |
| 3.7.0 | 1 / 1 | |
| 3.6.0 | 1 / 1 | |
| 3.5.1 | 1 / 1 | |
| 3.5.0 | 1 / 1 | |
| 3.4.2 | 1 / 1 | |
| 3.3.0 | 1 / 1 | |
| 3.2.0 | 1 / 1 | |
| 3.1.0 | 1 / 1 | |
| 3.0.0 | 1 / 1 | |
| 2.104.0 | 1 / 1 | |
| 2.103.0 | 1 / 1 | |
| 2.102.0 | 1 / 1 | |
| 2.101.0 | 1 / 1 | |
| 2.100.0 | 1 / 1 | |
| 2.99.0 | 1 / 1 | |
| 2.98.0 | 1 / 1 | |
| 2.97.0 | 1 / 1 | |
| 2.96.0 | 1 / 1 | |
| 2.95.0 | 1 / 1 | |
| 2.94.0 | 1 / 1 | |
| 2.93.0 | 1 / 1 | |
| 2.92.1 | 1 / 1 | |
| 2.91.0 | 1 / 1 | |
| 2.90.0 | 1 / 1 | |
| 2.89.0 | 1 / 1 | |
| 2.88.3 | 1 / 1 | |
| 2.88.2 | 1 / 1 | |
| 2.88.1 | 1 / 1 | |
| 2.88.0 | 1 / 1 | |
| 2.87.0 | 1 / 1 | |
| 2.86.0 | 1 / 1 | |
| 2.85.0 | 1 / 1 | |
| 2.84.0 | 1 / 1 | |
| 2.83.0 | 1 / 1 | |
| 2.82.0 | 1 / 1 | |
| 2.80.0 | 1 / 1 | |
| 2.79.0 | 1 / 1 | |
| 2.78.1 | 1 / 1 | |
| 2.73.0 | 1 / 1 | |
| 2.71.1 | 1 / 1 | |
| 2.70.0 | 1 / 1 | |
| 2.69.0 | 1 / 1 | |
| 2.68.0 | 1 / 1 | |
| 2.67.0 | 1 / 1 | |
| 2.66.2 | 1 / 1 | |
| 2.66.1 | 1 / 1 | |
| 2.64.0 | 1 / 1 | |
| 2.63.0 | 1 / 1 | |
| 2.62.0 | 1 / 1 | |
| 2.61.0 | 1 / 1 | |
| 2.60.0 | 1 / 1 | |
| 2.59.0 | 1 / 1 | |
| 2.58.0 | 1 / 1 | |
| 2.57.0 | 1 / 1 | |
| 2.56.0 | 1 / 1 | |
| 2.55.0 | 1 / 1 | |
| 2.54.3 | 1 / 1 | |
| 2.54.2 | 1 / 1 | |
| 2.54.1 | 1 / 1 | |
| 2.54.0 | 1 / 1 | |
| 2.53.0 | 1 / 1 | |
| 2.52.1 | 1 / 1 | |
| 2.52.0 | 1 / 1 | |
| 2.51.0 | 1 / 1 | |
| 2.50.0 | 1 / 1 | |
| 2.49.0 | 1 / 1 | |
| 2.48.5 | 1 / 1 | |
| 2.48.4 | 1 / 1 | |
| 2.48.1 | 1 / 1 | |
| 2.48.0 | 1 / 1 | |
| 2.47.0 | 1 / 0 | |
| 2.46.0 | 1 / 0 | |
| 2.45.1 | 1 / 0 | |
| 2.44.2 | 1 / 0 | |
| 2.44.1 | 1 / 0 | |
| 2.44.0 | 1 / 0 | |
| 2.43.0 | 1 / 0 | |
| 2.41.0 | 1 / 0 | |
| 2.40.3 | 1 / 0 | |
| 2.40.2 | 1 / 0 | |
| 2.40.1 | 1 / 0 | |
| 2.40.0 | 1 / 0 | |
| 2.38.0 | 1 / 0 | |
| 2.37.0 | 1 / 0 | |
| 2.36.0 | 1 / 0 | |
| 2.35.0 | 1 / 0 | |
| 2.33.0 | 1 / 0 | |
| 2.32.0 | 1 / 0 | |
| 2.30.0 | 1 / 0 | |
| 2.29.1 | 1 / 0 | |
| 2.29.0 | 1 / 0 | |
| 2.28.2 | 1 / 0 | |
| 2.28.1 | 1 / 0 | |
| 2.28.0 | 1 / 0 | |
| 2.27.5 | 1 / 0 | |
| 2.27.3 | 1 / 0 |
v3.9.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.8.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.8.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.7.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.7.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.6.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.5.1
2 findingsSpreading entire process.env into an object — may capture all secrets 47 | const result = spawnSync(process.execPath, [path.join(BIN_DIR, launcher), ...args], { 48 | encoding: "utf8", > 49 | env: { 50 | ...process.env, 51 | NODE_PATH: path.join(work, "node_modules"),
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.5.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.4.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.3.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.2.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.1.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.0.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.104.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.103.0
3 findingsDynamic require() with a variable — could load arbitrary modules 40 | 41 | test("isVersionQuery recognizes --version, -V, and -v as the first argument", () => { > 42 | const { isVersionQuery } = require(RUN_BINARY); 43 | assert.equal(isVersionQuery(["node", "fallow", "--version"]), true); 44 | assert.equal(isVersionQuery(["node", "fallow", "-V"]), true);
Dynamic require() with a variable — could load arbitrary modules 58 | 59 | test("describeVerified annotates the resolved version's signing status", () => { > 60 | const { describeVerified } = require(RUN_BINARY); 61 | const ok = { ok: true, sentinelPath: "/c/s" }; 62 | // Signed-era version: appended as `signed`.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.102.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.