This review is from Crev, a distributed system for code reviews. To add your review, set up cargo-crev.

0.3.0 (current) Rating: Positive Thoroughness: Low Understanding: Low

by kpreid on 2023-12-16

  • Contains no unsafe code.
  • Contains no IO.
  • I have examined the code to check that it is not obviously malicious or obfuscated.

One concern: a global AtomicUsize counter is used to assign Variable IDs. This counter could be overflowed on 32 or 16-bit platforms; it would be better to use an AtomicU64 or some other strategy.


These reviews are from cargo-vet. To add your review, set up cargo-vet and submit your URL to its registry.

0.3.0 (current) safe-to-run

From kornelski/crev-proofs copy of salsa.debian.org.

Packaged for Debian (stable). Changelog:

  • Package cassowary 0.3.0 from crates.io using debcargo 2.4.2
  • No-op source-only re-upload for Debian Testing Migration.

cargo-vet does not verify reviewers' identity. You have to fully trust the source the audits are from.

safe-to-run

This crate can be compiled, run, and tested on a local workstation or in controlled automation without surprising consequences. More…

unknown

May have been packaged automatically without a review


Crates in the crates.io registry are tarball snapshots uploaded by crates' publishers. The registry is not using crates' git repositories. There is absolutely no guarantee that the repository URL declared by the crate belongs to the crate, or that the code in the repository is the code inside the published tarball.

To review the actual code of the crate, it's best to use cargo crev open cassowary. Alternatively, you can download the tarball of cassowary v0.3.0 or view the source online.