Skip to content

About

Check Cargo dependency for packages that are too new or too old

Resources

Stars

2 stars

Watchers

0 watching

Forks

Use this GitHub action with your project
Add this Action to an existing workflow or create a new one
View on Marketplace

Latest commit

 

History

94 Commits

Folders and files

Repository files navigation

cargo-oxidate

Check Cargo.lock for packages that are too new (supply chain risk) or too old (staleness/CVE risk).

Installation

cargo install cargo-oxidate --locked

Usage

# As a cargo subcommand
cargo oxidate --min-age-days 14 --max-age-days 730

# Direct invocation
cargo-oxidate Cargo.lock --min-age-days 14 --max-age-days 730

Options

Flag Description
--min-age-days N Reject packages newer than N days (supply chain security)
--max-age-days N Reject packages older than N days (staleness)
--exempt pkg1,pkg2 Packages to skip
--exclude-missing Accept packages with unknown publish dates
--timeout N HTTP timeout in seconds (default: 10)
--suggest-fix For "too new" violations, suggest cargo update commands to downgrade
--include-prerelease Modifier for --suggest-fix. Consider prerelease versions as suggestion candidates.
--cache-path PATH Enable response caching at PATH (or set CARGO_OXIDATE_CACHE_PATH)
--cache-max-age-hours N Max age for cached version listings (default: 24)
--quiet Suppress start and per-package progress messages
--verbose Show each package as it is checked
--format text|json Render the final result as text (default) or JSON

At least one of --min-age-days or --max-age-days must be specified.

--suggest-fix

--suggest-fix prints a cargo update --precise command for the newest eligible downgrade of each package that is too new. It checks dependency requirements it can verify from Cargo.lock and workspace manifests.

Registry requirements come from the crates.io index. An optional registry declaration that cannot be confirmed active is shown as unverified. Target-specific registry declarations are enforced. For local and workspace manifests, the tool does not determine feature or target activation, so it treats every declared requirement, including optional and target-specific ones, as mandatory.

Suggestions are best effort. The tool does not run Cargo's resolver or build your project, so Cargo can still reject a suggested command. Apply suggestions in order, then run the command again and run your tests.

Exit Codes

Code Meaning
0 No dependency age violations
1 Dependency age violations found
2 Invalid input or incomplete required check

Caching

Repeat runs can reuse crates.io API responses by passing --cache-path:

cargo oxidate --cache-path .cache/oxidate.json --min-age-days 14

Per-version publish dates are cached indefinitely (they're immutable on crates.io). Per-crate version listings expire after --cache-max-age-hours (default 24h) so newly published versions are picked up.

GitHub Action

This tool is also available as a GitHub Action. See examples/usage.yml or use it in your workflow:

- uses: timweri/cargo-oxidate@v0.2.1
  with:
    min-age-days: 14
    max-age-days: 730
    cache-responses: true  # default; set to 'false' to disable

When cache-responses is enabled (the default), the action caches crates.io responses using the selected Cargo.lock hash. Its compiled binary is cached separately by the referenced cargo-oxidate action version, so dependency changes in the consuming repository do not trigger a rebuild of this tool.

License

MIT

About

Check Cargo dependency for packages that are too new or too old

Resources

Stars

2 stars

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors

Languages