Network
Code Guardian sends no telemetry and calls no Provimedia server. Two exceptions still apply: a freshness check of its own repository, and optional registry lookups by the dependency tools.
What does not happen
- No telemetry.
- No call to a Provimedia server.
Freshness check
On every prompt, at most every 10 minutes, a git fetch runs in the background against the upstream of the project's own repository. Its only purpose is to detect whether the local state is behind the remote one.
If .code-guardian-deploy.yml sets live_ssh (or, as a fallback, ssh) together with live_path, an additional SSH call git rev-parse HEAD follows against the customer's own server.
This version has no off switch, only throttling through the CG_FRISCHE_TTL environment variable, in seconds.
Dependency audits
composer audit and npm audit query their respective package registries, but only when the dependency tool actually runs.
Update check
Whether a new version is available is something the customer checks deliberately, through the update API (its own chapter). Code Guardian does not reconcile this automatically in the background.
In one sentence
Code Guardian does not phone home, but it does fetch the freshness state of its own repository in the background, and of the customer's own server when configured.