Skip to main content
Sign in to Arbor CloudSign in

Arbor Cloud

Pull request analysis, on GitHub.

Arbor Cloud analyzes a pull request you choose on GitHub and saves the result as a private report. Sign in with GitHub to start; your first 3 analyses are free.

No card for the trial. Each run asks GitHub for read-only access to the one repository it analyzes.

Current availability

Where things stand.

Open-source engine
Available on GitHub, MIT licensed
Arbor Cloud
Open
Trial
3 completed analyses per GitHub account, no card
Developer
$19 a month per workspace
Team
$79 a month per workspace
Previous Cloud
Closed September 23, 2026
How it works

What a run does.

The engine answers on your machine, for the branch you have checked out. Cloud answers for a pull request on GitHub.

  1. You ask for it

    A run starts only when someone in your workspace asks for one. Cloud doesn’t analyze every pull request or post comments.

  2. Arbor checks with GitHub

    It confirms the pull request’s base and head commits and rechecks that you can read the repository.

  3. It checks out the head commit

    No build or package scripts run. The checkout is analyzed in a separate worker process with limits on time and memory.

  4. It maps the change

    It builds the graph and blast radius with the same open-source engine libraries as the CLI, then adds its own entry-point, dependency and code-pattern checks.

  5. It saves a private report

    Only people in your workspace who can see the repository on GitHub can open it. It expires within 90 days.

What a report holds.

Keeps

  • How many symbols changed, and the code upstream and downstream of them
  • The most central changed symbols and the entry points that lead to them
  • Known vulnerabilities from OSV in dependencies pinned in Cargo.lock, package-lock.json and npm-shrinkwrap.json; other lockfiles, such as yarn.lock and pnpm-lock.yaml, are listed as unchecked
  • File paths, symbol names and counts

Doesn’t keep

  • Your source code
  • Patches or diff text
  • The checkout, which is deleted when the run ends

What it asks of GitHub.

Sign-in
Your GitHub profile and email address.
Repositories
Connected through Arbor’s GitHub App. Each run gets a fresh token for that one repository, with read-only access to contents, metadata and pull requests.
Access checks
Before a run and every time a report opens, Arbor asks GitHub whether you can still see the repository.
How Cloud handles tokens and checkouts

Used the previous Cloud?

The first Cloud was a GitHub App that posted blast-radius comments on pull requests. It closed on September 23, 2026. This Cloud is a new service: sign in again to start a workspace.

Closing the website does not itself delete existing data. For an earlier account, its data, or billing, email support@getarbor.dev with your GitHub username.

Prefer to stay local?

The engine is free, MIT licensed, and needs no account. Install it, index a repository, and compare your branch with main to see what it reaches. Or explore the recorded Python sample first.

Use the engine