NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
crates.io · #2954 most downloaded on crates.io
Audit Cargo.lock for crates with security vulnerabilities
Last release 4 months ago
05 Jun 2026
Release timing varies
gaps range from 2 weeks to 8 months
Nearly every release is documented
notes for 51 of 54 stable releases
1 version withdrawn
withdrawn after publishing
10 years old
60 releases · first in 2017
Disable embedded file timestamps in rust-embed by @kpcyrd in #1554
One column per quarter.
Nothing published for this version
Nothing published for this version
Upgraded to rustsec v0.30.2 to fix an incompatibility with Rust v1.85 and later ([#1333])
rustsec v0.30.2 to fix an incompatibility with Rust v1.85 and later (#1333)Upgraded cargo-lock to fix an issue with Cargo.lock v4 format parsing in presence of git tags ([#1298])
cargo audit bin can now audit WebAssembly ([#1182])
Nothing published for this version
Nothing published for this version
Fix build for cargo install --locked by bumping time crate in Cargo.lock to work around a breaking change in rustc.
cargo install --locked by bumping time crate in Cargo.lock to work around a breaking change in rustc.Completely rewritten cargo audit fix subcommand ([#1113])
cargo audit fix subcommand (#1113)
Cargo.lock as opposed to Cargo.toml, and performs only semver-compatible upgrades.cargo update, migrating away from the unmaintained cargo-edit-9 crate.fix feature.tame-index 0.9.3 or later, fixing issues with some enterprise firewalls. (#1103)Fix --color=auto always printing terminal escape sequences ([#1057])
Fix a deadlock when the Cargo.lock file is missing. It only occurs with rustsec v0.28.3 or later. ([#1051])
Cargo.lock file is missing. It only occurs with rustsec v0.28.3 or later. (#1051)Fix RUSTSEC-2023-0064 security issue by requiring rustsec 0.28.2 or higher.
rustsec 0.28.2 or higher.Release workflow: don't enable fix and vendored-openssl features ([#980])
fix and vendored-openssl features (#980)no more reports of Windows-only unsoundness in ELF binaries). Previously this was implemented for vulnerabilities, but not warnings. ([#964])
cargo audit bin no longer shows warnings not applicable to the binary type (e.g. no more reports of Windows-only unsoundness in ELF binaries). Previously this was implemented for vulnerabilities, but not warnings. (#964)rustsec v0.28, bringing performance, security and compatibility improvements, but also temporarily dropping support for CPU platforms other than x86 and ARM. See the rustsec changelog for details.Nothing published for this version
When scanning binary files, the binary's platform is taken into account. This prevents scenarios such as Windows-only vulnerabilities being reported o…
cargo-lock v9.0.0, which enables support for sparse registries.cargo audit itself are no longer printed multiple times when scanning multiple files (#848)Vulnerability severity is now included in the cargo audit output, if known ([#825])
cargo audit output, if known (#825)informational = unsound are now reported by default, but only as warnings (#819). They do not cause the audit to fail, i.e. the exit code of the process is still 0. This behavior can be suppressed through the configuration file.Checks for yanked crates were broken since 0.17.0. This release restores them and adds tests to prevent future regressions.
binary-scanning feature.…(exit code 2) as opposed to reporting them as vulnerabilities in the scanned binary (exit code 1). They are treated as warnings by default, so --deny=…
cargo audit bin now attempts to detect dependencies in binaries not built with cargo auditable by parsing the panic messages (#729). This only detects about a half of the dependency list and never detects C code such as OpenSSL, but works on any Rust binaries built with cargo.--deny=warnings flag.cargo audit bin --deny=warnings no longer exits after finding the first binary with warnings.cargo audit bin when scanning multiple files thanks to caching crates.io index lookups (implemented in rustsec crate).cargo audit or rustsec will now result in a scanning error being reported (exit code 2) as opposed to reporting them as vulnerabilities in the scanned binary (exit code 1). They are treated as warnings by default, so --deny=warnings is required to observe the new behavior.binary-scanning feature that adds the cargo audit bin subcommand is now enabled by default, but is not documented as such.Fixed the screenshot URL in README.md
Initial support for scanning binaries built with `cargo auditable`
cargo auditableDeprecated --deny-warnings CLI option ([#545])
Bump rustsec dependency to v0.25; MSRV 1.52 ([#480])
vendored-libgit2 feature ([#432])
vendored-libgit2 feature (#432)Pin thiserror and zeroize to avoid MSRV breakages ([#415])
thiserror and zeroize to avoid MSRV breakages (#415)New exit status (2) for Cargo.lock parsing errors ([#368])
Generate release builds with github actions ([#337])
When running in no-fetch mode, allow accessing a non-git repo ([#315])
Split -D/--deny and --deny-warnings ([#278])
-D/--deny and --deny-warnings (#278)rustsec crate to v0.22.2 ([#277])Support for project specific config directories ([#252])
Pin smol_str to v0.1.16 to ensure MSRV 1.41 compatibility ([#255], [#258])
Update rustsec crate to v0.20 ([#221])
Improve yanked crate auditing messages and config ([#200])
Add vendored-openssl feature ([#193])
vendored-openssl feature (#193)Update rustsec crate to v0.17 release; MSRV 1.39+ ([#186], [#188])
Upgrade rustsec to v0.16; new self-audit system ([#155])
Update to rustsec crate v0.15.2 ([#149])
Update to rustsec crate v0.15 ([#138])
rustsec crate v0.15 (#138)Update to rustsec crate v0.14.1 ([#134])
rustsec crate v0.14.1 (#134)Add --deny-warnings option ([#128])
--deny-warnings option (#128)rustsec crate v0.14 (#126)~/.cargo/audit.toml (#123, #125)--help (#113)rustsec crate versions (#112)Nothing published for this version
Nothing published for this version
[#101]: https://github.com/RustSec/cargo-audit/pull/101
--version (#101)Produce valid JSON when no vulnerabilities are detected ([#77])
[#64]: https://github.com/RustSec/cargo-audit/pull/64
Update to Rust 2018 edition ([#61])
Have cargo audit version exit with status 0 ([#38])
cargo audit version exit with status 0 (#38)Refactoring and UI improvements ([#37])
Upgrade rustsec crate to 0.9 ([#36])
rustsec crate to 0.9 (#36)Honor the affected_platforms attribute ([#35])
README.md: Use tag for screenshot so it renders on crates.io ([#28])
<img> tag for screenshot so it renders on crates.io (#28)Use OR delimiter to display patched versions ([#25])
Near rewrite of cargo-audit using rustsec 0.7.0 ([#22])
rustsec 0.7.0 (#22)Use crate isatty to resolve Windows build errors ([#14])
Upgrade to rustsec 0.6.0 crate ([#12])
Make cargo-audit a proper cargo subcommand ([#2])
- Initial release
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →