#cargo-subcommand #security #audit #vulnerability

bin+lib cargo-audit

Audit Cargo.lock for crates with security vulnerabilities

16 releases (8 breaking)

✓ Uses Rust 2018 edition

0.8.0 Aug 16, 2019
0.7.0 Jul 15, 2019
0.6.1 Dec 16, 2018
0.5.2 Jul 29, 2018
0.2.0 Mar 6, 2017

#12 in Cargo plugins

Download history 1014/week @ 2019-05-03 1219/week @ 2019-05-10 1390/week @ 2019-05-17 1354/week @ 2019-05-24 1447/week @ 2019-05-31 1601/week @ 2019-06-07 1500/week @ 2019-06-14 1872/week @ 2019-06-21 1494/week @ 2019-06-28 1525/week @ 2019-07-05 1584/week @ 2019-07-12 1787/week @ 2019-07-19 1652/week @ 2019-07-26 1475/week @ 2019-08-02 1448/week @ 2019-08-09

6,655 downloads per month

Apache-2.0 OR MIT

89KB
425 lines

cargo audit

Latest Version Build Status Appveyor Status Safety Dance Rust 1.35+ Apache 2.0 OR MIT licensed Gitter Chat

Audit Cargo.lock files for crates with security vulnerabilities reported to the RustSec Advisory Database.

Requirements

cargo audit requires Rust 1.35 or later.

Installation

cargo audit is a Cargo subcommand and can be installed with cargo install:

$ cargo install cargo-audit

Once installed, run cargo audit at the toplevel of any Cargo project.

Using cargo audit on Travis CI

To automatically run cargo audit on every build in Travis CI, you can add the following to your .travis.yml:

language: rust
cache: cargo # cache cargo-audit once installed
before_script:
  - cargo install --force cargo-audit
  - cargo generate-lockfile
script:
  - cargo audit

Reporting Vulnerabilities

Report vulnerabilities by opening pull requests against the RustSec Advisory Database GitHub repo:

Report Vulnerability

Screenshot

Screenshot

License

Licensed under either of:

at your option.

Contribution

Unless you explicitly state otherwise, any contribution intentionally submitted for inclusion in the work by you shall be dual licensed as above, without any additional terms or conditions.

Dependencies

~13MB
~287K SLoC