#lock-files #cargo #lock #graph

bin+lib cargo-lock

Self-contained Cargo.lock parser with optional dependency graph analysis

24 releases (15 stable)

10.0.1 Oct 25, 2024
10.0.0-pre.0 Jul 30, 2024
9.0.0 Apr 24, 2023
8.0.3 Dec 1, 2022
0.2.1 Sep 21, 2019

#313 in Parser implementations

Download history 72827/week @ 2024-08-24 69629/week @ 2024-08-31 73530/week @ 2024-09-07 69369/week @ 2024-09-14 65207/week @ 2024-09-21 74028/week @ 2024-09-28 69538/week @ 2024-10-05 72682/week @ 2024-10-12 76877/week @ 2024-10-19 69529/week @ 2024-10-26 74880/week @ 2024-11-02 97844/week @ 2024-11-09 97680/week @ 2024-11-16 84568/week @ 2024-11-23 96865/week @ 2024-11-30 83150/week @ 2024-12-07

378,077 downloads per month
Used in 183 crates (45 directly)

Apache-2.0 OR MIT

78KB
1.5K SLoC

RustSec: cargo-lock crate

Latest Version Docs Build Status Safety Dance MSRV Apache 2.0 OR MIT licensed Project Chat

Self-contained serde-powered Cargo.lock parser/serializer with support for the V1/V2/V3/V4 formats, as well as optional dependency tree analysis features. Used by RustSec.

When the dependency-tree feature of this crate is enabled, it supports computing a directed graph of the dependency tree, modeled using the petgraph crate, along with support for printing dependency trees ala the cargo-tree crate.

Documentation

Minimum Supported Rust Version

Rust 1.70 or higher.

Minimum supported Rust version can be changed in the future, but it will be accompanied by a minor version bump.

SemVer Policy

  • MSRV is considered exempt from SemVer as noted above
  • The cargo lock CLI interface is not considered to have a stable interface and is also exempted from SemVer. We reserve the right to make substantial changes to it at any time (for now)
  • The dependency-tree feature depends on the pre-1.0 petgraph crate. We reserve the right to update petgraph, however when we do it will be accompanied by a minor version bump.

Command Line Interface

This crate provides a cargo lock subcommand which can be installed with:

cargo install cargo-lock --features=cli

It supports the following subcommands:

  • list: list packages in Cargo.lock
  • translate: translate Cargo.lock files between the V1 and V2 formats
  • tree: print a dependency tree from Cargo.lock alone

See the crate documentation for more detailed usage information.

License

Licensed under either of:

at your option.

Contribution

Unless you explicitly state otherwise, any contribution intentionally submitted for inclusion in the work by you shall be dual licensed as above, without any additional terms or conditions.

Dependencies

~2.3–4MB
~67K SLoC