About Arbor
What else does this change reach?
A diff shows the lines that changed. Arbor shows what those lines reach before you edit or merge: who calls them, what they call, and which entry points lead to them, each with a file and line you can check.
At a glance
- What it is
- An engine that maps the calls in your code and answers who calls what
- License
- Open source, MIT, written in Rust
- Where it runs
- On your machine, from the
arborCLI or your assistant over MCP - First release
- 0.1.0, January 5, 2026
- Latest release
- v3.0.3, September 29, 2026
- Arbor Cloud
- Open since October 7, 2026: pull request analysis on GitHub, with a free trial. Plans
Why Arbor exists
A pull request shows a diff. It doesn’t show who calls the functions in it, which HTTP handlers or jobs lead to them, or which tests exercise them. Finding that by hand means searching for names and opening file after file. Arbor builds the map once and answers from it, in your terminal and in your coding assistant.
arbor diff --base main reports a branch the way its pull request shows it. Each modified symbol gets its own blast radius, new symbols are listed separately, and tests that call the change are listed as worth running.
$ arbor diff --base main
Change Impact Preview
Compared: changes since this branch left main (merge base d4be9b0)
Changed files:
• src/parser.py (modified)
Symbols: 1 modified · 0 new
Impact of the modified symbols (new code has no existing callers):
• 1 direct callers
• 1 indirect callers
• 1 API entrypoints affected
• 2 files likely require updates
• 4 impacted nodes totalThe engine runs on your machine
The engine is open-source Rust under the MIT license. It parses code with Tree-sitter, builds a call and dependency graph with petgraph, and saves it in .arbor/ inside your project. Dedicated parsers cover Rust, TypeScript and JavaScript, Python, Go, Java, C and C++, C#, and Dart. Kotlin, Swift, Ruby, PHP, and Shell use a line-based fallback that records declarations but not the calls inside them.
In the terminal, ask arbor callers, arbor path, arbor refactor, or arbor diff. In your assistant, arbor bridge serves the same graph as an MCP server with 16 tools. Indexing, queries, the bridge, and receipts make no network requests: no telemetry, no update check, no model calls. The first public release, 0.1.0 on January 5, 2026, already included the MCP bridge.
Receipts for coding-agent turns
When a coding agent finishes a turn, the question is what it changed, including anything you didn’t ask for. Receipts, new in v3.0.3, answer it. arbor hook claude wires them into Claude Code: one hook snapshots your working tree when you send a request, and another writes a receipt when Claude stops.
The receipt lists the files and functions that changed, flags the files it judges outside your request, names the pages, API routes, and areas the change can reach, and suggests up to four things to test. arbor receipt undo <id> --unasked puts back only the flagged files. Receipts are computed locally from git and the graph, with no model call.
Arbor receipt · "make tokenize skip blank lines"
Changed 2 files · 4 functions
⚠ Not in your request (1):
src/auth.py · Sign in · verify_session, sign_in
Undo it: `arbor receipt undo 20260929T235026-959cc81d --unasked`
Could affect: Sign in · 1 other function uses this code
Test before you ship:
1. Sign out, then sign back in
Saved as 20260929T235026-959cc81d · `arbor receipt show`Show the evidence, and the gaps
Every symbol Arbor reports comes with its file and line, and call edges carry the call site where the parser recorded one. Edges carry a confidence, and ambiguous matches are labeled instead of hidden. The engine’s README puts it plainly: “An honest unknown beats a confident wrong answer.”
$ arbor callers main
No callers found for 'main' — Python function main (…/src/app.py:4)
Not proof that nothing does: calls through trait objects, function pointers, callbacks, reflection or generated code aren't followed. Confirm with a text search before treating this symbol as unused or changing its signature.We publish the gaps too. Dynamic imports and reflection can hide a call. A call through a subclass instance isn’t yet listed among the base method’s callers. Some small targets over-report their impact. A zero blast radius can mean an unresolved edge, and no Arbor result proves that a change is safe.
Read the known limitsArbor Cloud
The first Arbor Cloud was a GitHub App that posted blast-radius comments on pull requests. We closed it on September 23, 2026 to rebuild it, and the open-source engine kept shipping: v3.0.3 followed on September 29.
The rebuilt Cloud opened on October 7, 2026. It analyzes a pull request you choose with the engine’s open-source libraries and saves the result as a private report for your workspace. Your first analyses are free.
About Arbor CloudTell us what Arbor missed
The most useful message names a real change: what you asked Arbor, what it answered, and what it missed or over-reported. Say which language and install channel you used, and whether the answer came from the CLI, an MCP client, or a receipt. Engine bugs belong in the GitHub issue tracker.
support@getarbor.devSupported through startup programs
Credits, tools, and program benefits.
