Skip to content

Warn about security advisories for cratres being added with cargo add #10654

Open

Description

Problem

A user can add a crate with a security advisory and not know it unless they know of the third-party cargo audit, install it, and run it.

Proposed Solution

Integrate cargo audit checks into cargo add when adding a new registry dependency

Notes

Inspired by conversation on zulip about checking it in cargo

It looks like we

We might be blocked on rustsec/rustsec#490

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Assignees

No one assigned

    Labels

    C-feature-requestCategory: proposal for a feature. Before PR, ping rust-lang/cargo if this is not `Feature accepted`Command-add

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions