Repository navigation
v3.0.0: new brand, styling audit, rule packs, and architecture guard
Fallow 3.0
Your code-health gate now reviews your styles. Same PR, same JSON, no new tool.
Fallow 3.0 is a major release for one reason: fallow audit, the gate that already reviews your TypeScript and JavaScript, now reviews your CSS and CSS-in-JS in the same PR, in the same JSON stream, with no separate tool and no extra config. That is the change that crossed the version to 3.0.
Alongside it: policy-as-code with rule packs, a pre-edit architecture guard, better PR and MR reporting, and a new brand mark.
No breaking changes. CLI flags, configuration, and JSON output contracts are all unchanged. The major bump marks the platform milestone (styling in audit), not a breaking API change. GitHub Action users on @v2 should move to @v3 to keep receiving releases.
npm install -g fallow@3.0.0
# or
npx fallow@3.0.0Styling analysis, now inside fallow audit
Run fallow audit on your next PR and styling feedback lands next to your JS and TS findings, in the same JSON. No new command, no new config, no second tool. Findings are verdict-neutral by default: they report, they do not fail the gate. What you get:
- Design-system drift and near-duplicate theme tokens
- Duplicate CSS blocks and selector-complexity hotspots
- Dead styling surface and broken references
- Raw one-off values that bypass your tokens
The deep pass scans the project-wide styling surface, then narrows cross-file results back to the anchors the PR touched. A two-file change gets styling feedback scoped to those two files, not a repo-wide dump.
Two new findings, css-token-drift and raw-style-value, flag introduced raw values on design-system axes: colors, font sizes, line heights, radii, and shadows. They are low-confidence and verify-first, so they stay off the gate until you opt in:
Dialing it back:
--no-css(oraudit.css: false) disables styling analysis entirely.--no-css-deep(oraudit.cssDeep: false) keeps the local styling checks and skips only the project-wide reachability pass.
Styling actions are report-only (auto_fixable: false). Agents surface the finding and let you verify and edit by hand, rather than rewriting your styles for you.
Custom rules: policy as code
Encode your architecture in declarative rule packs, enforce them in the same gate, and let agents check the rules before writing a line.
- Authoring.
fallow rule-pack init | list | test | schemascaffolds, inspects, and validates policy packs.initdrops in a starter or architecture-oriented pack and can wire it straight into your config.listshows loaded packs with their sources, severities, matchers, and messages (human or JSON).testandschemavalidate a pack before you ship it. - V2 matchers. Scope rules to boundary
zones, ban direct exports withbanned-export, and use a trailing/*banned-import specifier for subpath-only deep-import bans. Everything reports under one stablepolicy-violationfamily, so existing suppressions and CI keep working untouched. - A guard that runs before the edit.
fallow guard <files>tells you which rules govern a file before a line is written: its boundary zone, allowed import zones, forbidden call patterns, rule-pack rules, effective severities, and suppression tokens. It works on files that do not exist yet, and it is exposed as the read-only MCPguardtool, so an agent can ask "what rules apply here?" and stay inside the lines from the first draft.
Improved PR and MR reporting
The bundled GitHub Actions and GitLab CI integrations now render sticky summary comments from typed Rust output: a gate table, an attention banner, top fixes, and sidecar artifacts for the full drilldown. Clean runs no longer spawn a fresh comment, and an existing Fallow comment is updated in place so stale warnings disappear. GitHub Actions posts a native Fallow Check Run when checks: write is available. Inline review comments and MR discussions skip empty envelopes, so a dead-code-only job no longer leaves "0 inline findings" noise.
New FALLOW_PR_COMMENT_LAYOUT (default | compact | gate-only | details) controls the sticky summary layout.
Other changes
- Callback arguments get real names. A function passed as a call or
newargument is no longer surfaced as anonymous. It takes the callee's name (arr.map(cb), route handlers,.references(() => ...)), matching the runtime instrumenter so static inventory and runtime coverage agree on the same name. - New f-wing brand mark, across the icon, the light and dark wordmark lockups, the VS Code sidebar icon, and the docs.
- Engine and registry architecture split completed (internal). Command, API, MCP, and editor flows now route through typed engine and API boundaries, and combined and audit runs reuse retained project artifacts instead of repeating discovery, parse, and graph work. The security catalogue moved into a dedicated
fallow-securitycrate. CLI wire contracts, config, and output formats are unchanged.
Thanks
Thanks @revazi for adding repo-scoped agent skills (#1727).
Full Changelog: v2.104.0...v3.0.0