Every network call that Fallow makes.
The Fallow Cloud package, @fallow-cli/beacon, counts how often production calls each function. It sends those counts with the function names, file paths and line numbers they belong to. It never sends arguments, return values, request data or user data.
This page is for the security review that comes before the beacon runs in production. It lists every call that the beacon and the free scan make, when each call happens and the exact fields it sends.
The free scan runs on your own machines. Fallow Cloud receives data only when you add the beacon to a service or run an upload command. The analysis sidecar opens no network connection, and local runtime analysis works offline. Check source maps before you upload them, because a source map can hold your original source code.
Each call starts from something you configure or run.
The beacon and the coverage commands send to the endpoint you set. The license commands go to api.fallow.cloud.
@fallow-cli/beacon, HTTP modePOST
{endpoint}/v1/ingest- When
- The beacon flushes a batch of coverage from a Node, Bun, Deno, serverless or browser runtime that you configured.
- What it sends
- The fields in the tables below, with your API key in the Authorization header.
@fallow-cli/beacon, file modeNo network call
- When
- You configure
transport: "fs"andwriteToDir. - What it sends
- Nothing to Fallow. The beacon writes the coverage JSON into the directory you chose.
fallow-cov, analysis sidecarNo network call
- When
- Local runtime coverage analysis starts it.
- What it sends
- Nothing. It reads a JSON request on stdin and writes the analysis as JSON on stdout.
fallow licensePOST
api.fallow.cloud/v1/auth/license/*- When
- You run
fallow license activate,activate --trialorrefresh. - What it sends
- License data: for example your email address, a device code, the current license token or an API key.
fallow coverage upload-inventoryPOST
{endpoint}/v1/coverage/:repo/inventory- When
- You or your CI run the command after a deploy.
- What it sends
- The commit SHA and the static function list: file paths, function names, positions, a hash of each function's source text and its complexity scores. When git history is available, it adds per-file churn: commit counts, lines added and deleted, the number of authors and the time of the last commit. With
--with-callers, it adds the files that import each function.
fallow coverage upload-source-mapsPOST
{endpoint}/v1/coverage/:repo/source-maps- When
- You or your CI run the command after a build.
- What it sends
- The source map files of the build. A source map can hold your original source code in its
sourcesContentfield.
fallow coverage upload-static-findingsPOST
{endpoint}/v1/coverage/:repo/static-findings- When
- You or your CI run the command.
- What it sends
- The commit SHA and the unused exports and dead files that Fallow found, each with its file path, export name and line number.
fallow, cloud runtime modeGET
{endpoint}/v1/coverage/:repo/runtime-context- When
- You turn on cloud mode for runtime analysis with a flag or an environment variable.
- What it sends
- The repository name and the filters, in the URL. No source code and no syntax tree.
The beacon sends these fields and no others.
The list follows the type definitions of @fallow-cli/beacon. Each request to /v1/ingest has the fields in the first table.
| Field | What it holds |
|---|---|
Authorization | The header with your API key, as a Bearer token. |
v | The payload schema version. |
batch | The list of coverage payloads. |
clientReports | Counts of payloads the beacon dropped, and why. Present only after a drop. |
| Field | What it holds |
|---|---|
payloadId | A random id, so the server can drop duplicates. |
projectId | The project id you configured. |
environment | The environment name you configured, for example production. |
runtimeSurface | Optional. The name you gave this runtime, for example web or worker. |
commitSha | The commit SHA of the deployed build. |
timestamp | The time of the snapshot. |
coverageSource | The collector that made the payload: v8 or istanbul. |
coverageOrigin | Optional. The origin you set: production, test, ci, build_time or unknown. |
functions | One entry per function, with the fields in the next table. |
| Field | What it holds |
|---|---|
filePath | The path of the file that holds the function. |
functionName | The name of the function. |
lineNumber | The line where the function starts. |
columnNumber | Optional. The column where the function starts. |
endLine | Optional. The line where the function ends. |
endColumn | Optional. The column where the function ends. |
stableId | Optional. A short hash that identifies the function. |
hitCount | The number of calls in the snapshot. |
trackingState | called, never_called or untracked. |
| Field | What it holds |
|---|---|
reason | Why the beacon dropped payloads, for example queue_overflow or network_error. |
droppedCount | The number of payloads it dropped. |
timestamp | The time of the drop. |
What the beacon never sends.
- Function bodies, string literals or other file contents.
- HTTP request or response bodies, headers, URLs, function arguments or return values.
- Environment variables, secrets, credentials, heap contents or stack traces.
- Pings on startup, install counts or diagnostic callbacks.
- Traffic to a language model provider.
What you control.
- Runtime collection is opt-in. You configure the API key and the endpoint.
- The
beforeSendhook can change or drop a payload before it leaves the process, anddenyPathsleaves out files that match a pattern. - Local runtime analysis reads files from disk and never contacts Fallow Cloud.
- The sidecar checks the license offline, with an Ed25519 public key compiled into it.
- Cloud mode needs an explicit flag or environment variable.
FALLOW_API_KEYalone does not turn it on.
The free scan and its GitHub Action make four calls of their own.
These calls come from fallow and its GitHub Action, not from Fallow Cloud. Telemetry is off until someone turns it on, and the model download starts only after you confirm it. The telemetry page in the docs lists what one event holds.
fallow, update checkGET
api.fallow.cloud/v1/cli/latest-version- When
- At most once in 24 hours, on an interactive terminal run. It never runs in CI, with
--quietor with machine output such as JSON.FALLOW_UPDATE_CHECK=offorDO_NOT_TRACKturns it off. - What it sends
- A request for the latest version number, with no data about your code.
fallow, product telemetryPOST
api.fallow.cloud/v1/telemetry/events- When
- Only after a person turns it on with
fallow telemetry enable. It is off by default. - What it sends
- Anonymous workflow events.
FALLOW_TELEMETRY=inspectprints the exact payload of a run without sending it.
fallow similar-code setup, model downloadGET
huggingface.co/jinaai/jina-embeddings-v2-base-code- When
- You run it and confirm the download.
- What it sends
- A request for the model file. No data about your code.
fallow GitHub Action, branded commentsPOST
api.fallow.cloud/v1/ci/github-token- When
- A workflow run that grants
id-token: write, before the Action posts a pull-request comment.branded-token: falseturns it off. - What it sends
- The short-lived GitHub Actions OIDC token of the run. It names the repository, the workflow and the commit. Fallow returns a GitHub App token for that repository only.
Legal terms and a security contact.
Fallow Cloud is hosted in the EU: the API and database run in Amsterdam, and stored files and database backups stay in the EU. The subprocessor list names each vendor and where it processes data. Hosted data is kept to run the service and to show your team its analysis.