FALLOW_FORMAT
Set the default output format so you don’t need to pass--format every time.
--format CLI flag takes precedence over FALLOW_FORMAT when both are set.
FALLOW_QUIET
Suppress progress bars and status messages. Useful in CI environments or when piping output.--quiet on every command.
FALLOW_BIN
Path to the fallow binary. Used by the MCP server (fallow-mcp) to locate the fallow CLI.
fallow on PATH when not set.
FALLOW_EXTENDS_TIMEOUT_SECS
Timeout in seconds for fetching remote configs viahttps:// URLs in the extends field.
5 seconds when not set.
FALLOW_CACHE_DIR
Directory for the persistent extraction cache. Wins over thecache.dir config field when both are set.
.fallow/cache.bin under the project root. Use this env var when the project checkout is read-only, when CI has a dedicated cache volume, or when multiple workspace copies should share a stable cache location.
--no-cache disables the cache entirely; this env var is then irrelevant.
FALLOW_CACHE_MAX_SIZE
Maximum on-disk extraction cache (.fallow/cache.bin) size in megabytes. Wins over the cache.maxSizeMb config field when both are set.
256 (MB) when not set. The cache triggers LRU eviction when its serialized size crosses 80% of the cap and evicts down to 60%. Intended for CI runners with disk quotas; local dev machines on full-size disks rarely need to touch this knob.
--no-cache disables the cache entirely; this env var is then irrelevant.
FALLOW_AUDIT_BASE
Pins thefallow audit comparison base. It takes effect only when neither --base nor --changed-since is passed, so the precedence is --base flag, then FALLOW_AUDIT_BASE, then auto-detection.
fallow audit auto-detects the base as the git merge-base (fork point) against the branch’s upstream or the remote default (origin/HEAD, then origin/main, then origin/master). That is the right answer for most repositories, but two cases want an explicit pin:
- Forks. On a fork,
originis your fork (which can lag the real upstream), so setFALLOW_AUDIT_BASE=upstream/mainto compare against the true upstream. - The agent gate.
fallow hooks install --target agentgenerates a hook that runs barefallow audit. If your team works entirely ingit worktrees and never updates the local default branch, the env var lets you pin the base without editing the generated script (which is regenerated on reinstall).
2 rather than being silently ignored, so a typo surfaces immediately.
FALLOW_AUDIT_CACHE_MAX_AGE_DAYS
Maximum age (in whole days, since last reuse or fresh create) of a persistent reusablefallow audit base-snapshot worktree cache. Older entries are removed at the top of the next fallow audit invocation. Wins over the audit.cacheMaxAgeDays config field when both are set.
30 days when not set. Setting the value to 0 disables the GC entirely (escape hatch for CI runners that prune /tmp out-of-band). Invalid values (non-integer, negative) silently fall back to the config field / default; a typo in a runner env var does not fail audits.
The sweep runs once per fallow audit invocation, walks git-registered worktrees only (not raw /tmp content), and never removes a cache entry that another in-flight fallow audit is using (per-entry kernel flock(2) guard). On reclaim, fallow writes a single fallow: reclaimed N stale base-snapshot caches line to stderr (unless --quiet is set) so the disk-space recovery is observable.
FALLOW_IMPACT_STORE_MAX_AGE_DAYS
Reclaim per-projectfallow impact stores that have not been touched in this many whole days. Impact keeps one small history file per project in your user config directory; over time, projects you delete from disk leave their stores behind. Set this so a recorded run prunes them.
0 and invalid values are treated the same way (no sweep), so a typo never deletes history. Age is the store file’s modification time, and any recorded run rewrites the file, so an actively-tracked project never ages out. The sweep never touches the project you just recorded, never deletes the advisory .lock sidecars, and never the global impact.json opt-in toggle. Because impact only records on developer machines (never in CI), this is purely local housekeeping.
FALLOW_UPDATE_CHECK
Local human runs can show a one-line upgrade hint when a cached latest-version check says the installed fallow is stale. The hint is suppressed for machine formats, CI, quiet runs, and non-TTY agent paths. SetFALLOW_UPDATE_CHECK=off to disable both the hint and the background latest-version check on that machine. DO_NOT_TRACK and FALLOW_TELEMETRY_DISABLED also suppress it.
FALLOW_SUGGESTIONS
dead-code, health, dupes, bare fallow, and audit add a top-level next_steps[] array of read-only follow-up commands to their --format json output (and a one-line Next: hint to bare fallow’s human output on a TTY), computed from the run’s findings. Set FALLOW_SUGGESTIONS=off (or 0/false/no/disabled) to suppress it; this is the escape hatch for CI consumers that snapshot-diff raw JSON output. The variable is inherited by the MCP-spawned CLI, so it also disables next_steps on MCP responses.
FALLOW_PRODUCTION and per-analysis overrides
FALLOW_PRODUCTION mirrors the --production CLI flag and turns production mode on for every analysis. The per-analysis vars (FALLOW_PRODUCTION_DEAD_CODE, FALLOW_PRODUCTION_HEALTH, FALLOW_PRODUCTION_DUPES) target a single analysis when running bare combined mode (fallow with no subcommand) or fallow audit.
- CLI flags (
--production,--production-{dead-code,health,dupes}) - Per-analysis env var (
FALLOW_PRODUCTION_HEALTH, etc.) - Global env var (
FALLOW_PRODUCTION) - Config (
production: truelegacy form, orproduction: { health: true, ... }per-analysis form)
FALLOW_PRODUCTION=false FALLOW_PRODUCTION_HEALTH=true runs health in production mode and the other analyses in non-production mode. Single-subcommand runs (e.g. fallow health) still respect FALLOW_PRODUCTION_HEALTH even though the per-analysis CLI flag is rejected with a subcommand: pass --production or set the per-analysis env var.
FALLOW_COVERAGE
Path to Istanbul coverage data (coverage-final.json) used for accurate per-function CRAP scores in fallow health, fallow audit, and bare fallow. The --coverage CLI flag wins when both are set. Standalone health and bare fallow fall back to health.coverage when both CLI and env inputs are omitted.
FALLOW_COVERAGE_ROOT
Absolute prefix to strip from Istanbul coverage paths before matching files. Use it when coverage was generated in a different checkout root, such as CI or Docker. The--coverage-root CLI flag wins when both are set. Standalone health and bare fallow fall back to health.coverageRoot when both CLI and env inputs are omitted.
FALLOW_MAX_FILE_SIZE
Per-file size ceiling in megabytes for source discovery (default5; 0 = no limit). Source files strictly larger are skipped before parsing, guarding against out-of-memory blowups from a single multi-megabyte generated or bundled file. The --max-file-size CLI flag wins when both are set. Declaration files (.d.ts) are always analyzed.
Review and PR-comment formats
These variables tune thereview-github / review-gitlab / pr-comment-github / pr-comment-gitlab output formats. The bundled GitHub Action and GitLab CI template set them for you; set them yourself only when rendering these formats outside the bundled integrations.
License and cloud
These variables configure the paid runtime intelligence layer and fallow cloud connectivity. See fallow license and fallow coverage.Telemetry
Telemetry is opt-in and off by default. Full reference: fallow telemetry.MCP server
Set these in the MCP server’senv block; the spawned CLI inherits them. Full reference: MCP integration.
The complete machine-readable list ships in the
environment_variables block of fallow schema.See also
MCP server
AI agent integration using the Model Context Protocol.
fallow dead-code
Full CLI reference including all output format options.