Arbor Cloud
Pull request analysis, on GitHub.
Arbor Cloud analyzes a pull request you choose on GitHub and saves the result as a private report. Sign in with GitHub to start; your first 3 analyses are free.
No card for the trial. Each run asks GitHub for read-only access to the one repository it analyzes.
Where things stand.
- Open-source engine
- Available on GitHub, MIT licensed
- Arbor Cloud
- Open
- Trial
- 3 completed analyses per GitHub account, no card
- Developer
- $19 a month per workspace
- Team
- $79 a month per workspace
- Previous Cloud
- Closed September 23, 2026
What a run does.
The engine answers on your machine, for the branch you have checked out. Cloud answers for a pull request on GitHub.
You ask for it
A run starts only when someone in your workspace asks for one. Cloud doesn’t analyze every pull request or post comments.
Arbor checks with GitHub
It confirms the pull request’s base and head commits and rechecks that you can read the repository.
It checks out the head commit
No build or package scripts run. The checkout is analyzed in a separate worker process with limits on time and memory.
It maps the change
It builds the graph and blast radius with the same open-source engine libraries as the CLI, then adds its own entry-point, dependency and code-pattern checks.
It saves a private report
Only people in your workspace who can see the repository on GitHub can open it. It expires within 90 days.
What a report holds.
Keeps
- How many symbols changed, and the code upstream and downstream of them
- The most central changed symbols and the entry points that lead to them
- Known vulnerabilities from OSV in dependencies pinned in Cargo.lock, package-lock.json and npm-shrinkwrap.json; other lockfiles, such as yarn.lock and pnpm-lock.yaml, are listed as unchecked
- File paths, symbol names and counts
Doesn’t keep
- Your source code
- Patches or diff text
- The checkout, which is deleted when the run ends
What it asks of GitHub.
- Sign-in
- Your GitHub profile and email address.
- Repositories
- Connected through Arbor’s GitHub App. Each run gets a fresh token for that one repository, with read-only access to contents, metadata and pull requests.
- Access checks
- Before a run and every time a report opens, Arbor asks GitHub whether you can still see the repository.
Used the previous Cloud?
The first Cloud was a GitHub App that posted blast-radius comments on pull requests. It closed on September 23, 2026. This Cloud is a new service: sign in again to start a workspace.
Closing the website does not itself delete existing data. For an earlier account, its data, or billing, email support@getarbor.dev with your GitHub username.
Prefer to stay local?
The engine is free, MIT licensed, and needs no account. Install it, index a repository, and compare your branch with main to see what it reaches. Or explore the recorded Python sample first.
Use the engine