NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
crates.io · #3587 most downloaded on crates.io
Library for retrieving and interacting with the crates.io index
Last release 1 months ago
03 Sep 2026
Release timing varies
gaps range from 2 weeks to 5 months
Nearly every release is documented
notes for 56 of the last 60 stable releases
40 versions withdrawn
withdrawn after publishing
11 years old
104 releases · first in 2015
Add a new IndexConfig::download_url_with_checksum() method, and pro…
Add a new IndexConfig::download_url_with_checksum() method, and pro…
Add a new IndexConfig::download_url_with_checksum() method, and produce more conformant download URLs in general.
<csr-read-only-do-not-edit/>
<csr-read-only-do-not-edit/>
<details><summary>view details</summary>
One column per quarter.
4 commits contributed to the release.
Add pubtime field to Version.
Add pubtime field to Version.
<csr-read-only-do-not-edit/>
<csr-read-only-do-not-edit/>
<details><summary>view details</summary>
upgrade gix for security advisory
<csr-read-only-do-not-edit/>
<csr-read-only-do-not-edit/>
<details><summary>view details</summary>
1 commit contributed to the release.
<csr-id-71771472d6ae56ff3a9c3868f22583881cd9f0e6/>
<csr-read-only-do-not-edit/>
<csr-read-only-do-not-edit/>
<details><summary>view details</summary>
4 commits contributed to the release.
Fix docs.rs documentation.
Fix docs.rs documentation.
<csr-read-only-do-not-edit/>
<csr-read-only-do-not-edit/>
<details><summary>view details</summary>
Update dependencies, including gix to v0.77.
Update dependencies, including gix to v0.77.
Update dependencies, including gix to v0.77.
<csr-read-only-do-not-edit/>
<csr-read-only-do-not-edit/>
<details><summary>view details</summary>
cd6a407)91aa246)e0f29d3)b7c91e5)86083f2)a95a6d6)e87de83)88b9148)c67857d)
</details>feat: update gix to v0.72.1. by @Byron in #191
gix to v0.72.1. by @Byron in #191Full Changelog: v3.10.0...v3.11.0
<csr-id-d99121572056cceacd8f90c976de4bd2aaf26c63/> <csr-id-55fedf14e184043c9098c84872ae8d94e5de31e3/>
Update depndencies, notably gix to v0.73.
<csr-read-only-do-not-edit/>
<csr-read-only-do-not-edit/>
<details><summary>view details</summary>
e3428db)704d849)a1dbd05)97a11b2)d991215)55fedf1)21d927a)
</details>1 commit contributed to the release.
gix to v0.72.1.gix to v0.72.1. (52c2d2d)gix to v0.72.1.<csr-read-only-do-not-edit/>
<csr-read-only-do-not-edit/>
<details><summary>view details</summary>
This release contains the upgrade to gix v0.71.
This release contains the upgrade to gix v0.71.
This release contains the upgrade to gix v0.71.
<csr-read-only-do-not-edit/>
<csr-read-only-do-not-edit/>
<details><summary>view details</summary>
Add git-https-reqwest feature That way it's possible to build rust-crates-index without curl .
git-https-reqwest featurerust-crates-index without curl.git-https-reqwest feature
That way it's possible to build rust-crates-index without curl.<csr-read-only-do-not-edit/>
<csr-read-only-do-not-edit/>
<details><summary>view details</summary>
Update ureq example to version 3.0
gix to v0.70gix to v0.70 (aac3115)<csr-id-707342ab8e821e55b857674a8d675c6aebc77c94/>
gix to v0.70<csr-read-only-do-not-edit/>
<csr-read-only-do-not-edit/>
<details><summary>view details</summary>
d588ccf)ccaed89)9d3625f)0bf18b3)7a6179e)gix to v0.70 (aac3115)34e7610)857c063)4b00dd2)707342a)
</details>Add support for new index cargo hash implementation. This also adds dirs::local_path_and_canonical_url_with_hash_kind() and SparseIndex::with_path_and
dirs::local_path_and_canonical_url_with_hash_kind()SparseIndex::with_path_and_hash_kind() to controlClippy helped 1 time to make code idiomatic.
dirs::local_path_and_canonical_url_with_hash_kind()
and SparseIndex::with_path_and_hash_kind() to control
which hash is used.<csr-read-only-do-not-edit/>
<csr-read-only-do-not-edit/>
Clippy helped 1 time to make code idiomatic.
<csr-read-only-do-not-edit/>
<details><summary>view details</summary>
4f907a6)1f3b4b0)bdd7919)fd3aecd)973f2e5)55ff57a)ec3c643)
</details>3 commits contributed to the release.
gix to v0.69<csr-read-only-do-not-edit/>
<csr-read-only-do-not-edit/>
<details><summary>view details</summary>
6 commits contributed to the release.
gix to v0.68<csr-read-only-do-not-edit/>
<csr-read-only-do-not-edit/>
<details><summary>view details</summary>
A release to update dependencies, namely gix is now at version 0.67.
A release to update dependencies, namely gix is now at version 0.67.
<csr-read-only-do-not-edit/>
<csr-read-only-do-not-edit/>
<details><summary>view details</summary>
2 commits contributed to the release.
gix to v0.66<csr-read-only-do-not-edit/>
<csr-read-only-do-not-edit/>
<details><summary>view details</summary>
7 commits contributed to the release.
<csr-id-704225198d5ada22863f4f20eac0c193b1c0c4a3/>
gix to v0.64<csr-read-only-do-not-edit/>
<csr-read-only-do-not-edit/>
<details><summary>view details</summary>
upgrade http to v1.0 It's breaking as http types are in our public API with the sparse feature enabled.
http to v1.0
It's breaking as http types are in our public API with the sparse feature enabled.<csr-read-only-do-not-edit/>
<csr-read-only-do-not-edit/>
<details><summary>view details</summary>
Revert "Upgrade to http 1" - this was a breaking change (`451026b`)
This release fixes v2.10 which broke the sparse feature due to the upgrade to http 1.0, which was present in the public API.
This release uses http 0.2 again, whereas the upcoming v3.0 will be for http 1.0.
http crate to make more obvious we are using it in the public API<csr-read-only-do-not-edit/>
<csr-read-only-do-not-edit/>
<details><summary>view details</summary>
upgrade gix to v0.63 for security fixes
gix to v0.63 for security fixes<csr-read-only-do-not-edit/>
<csr-read-only-do-not-edit/>
<details><summary>view details</summary>
dba8b14)217bb86)gix to v0.63 for security fixes (6223b70)gix to version 0.63.0 (2dc7734)eae6947)a925945)4be1703)4e23a38)
</details>Nothing published for this version
4 commits contributed to the release.
<csr-id-07c23f363d7a0494b52e0741794d6dfa96fd65a1/>
<csr-read-only-do-not-edit/>
<csr-read-only-do-not-edit/>
<details><summary>view details</summary>
add SparseIndex::make_config_request() and SparseIndex::parse_config_request(). That way it's possible to handle the case where no sparse index exists
SparseIndex::make_config_request() and SparseIndex::parse_config_request().
That way it's possible to handle the case where no sparse index exists yet.<csr-read-only-do-not-edit/>
<csr-read-only-do-not-edit/>
<details><summary>view details</summary>
3 commits contributed to the release.
<csr-id-110d4a8096b781e1cde8a35c08cb8c68d7a69612/>
<csr-read-only-do-not-edit/>
<csr-read-only-do-not-edit/>
<details><summary>view details</summary>
assure Git index updates to refs are actually written. The remote git repository may alter its references in such a way that local fast-forwards aren'
<csr-id-4d75232a72cb5f87b6dafa042898b7249123b88a/> assure Git index updates to refs are actually written. The remote git repository may alter its references in such a way that local fast-forwards aren't possible anymore.
This happens regularly as the history will be squashed on the remote.
Now we forcefully store the updated references, which resolves
the issue that calling update() didn't seem to do anything despite
being busy (i.e. downloading a possibly huge pack, and resolving it).
<csr-read-only-do-not-edit/>
<csr-read-only-do-not-edit/>
<details><summary>view details</summary>
3 commits contributed to the release.
<csr-id-5960658acef322349d9c8e9ac291365321b6add0/>
gix-0.58<csr-read-only-do-not-edit/>
<csr-read-only-do-not-edit/>
<details><summary>view details</summary>
10 commits contributed to the release over the course of 53 calendar days.
<csr-id-81f70d7cbcac5d4dbef6477cd803b1d103099347/> <csr-id-4ffad17947228bfeff47200d1ca969ae637c35cb/> <csr-id-39d9fb66270d38d4a3933e0f52edd3e0afcad143/>
<csr-read-only-do-not-edit/>
<csr-read-only-do-not-edit/>
<details><summary>view details</summary>
b84f4b9)3ae82f5)be03b1f)c237796)gix to v0.57 (81f70d7)2920beb)61f3090)4ffad17)39d9fb6)239b009)
</details>4 commits contributed to the release.
<csr-id-82002e7d8362b5e0736f994a1569d002333c7fad/>
<csr-read-only-do-not-edit/>
<csr-read-only-do-not-edit/>
<details><summary>view details</summary>
be less strict when determining if the crates-index remote matches the target URL. Previously a trailing slash could have caused it to think ti's not
gix to v0.54<csr-read-only-do-not-edit/>
<csr-read-only-do-not-edit/>
<details><summary>view details</summary>
Allow using git::URL without git feature active
<csr-id-72796a91835d05099fc20f9f5895288d9d3ff715/>
<csr-read-only-do-not-edit/>
<csr-read-only-do-not-edit/>
<details><summary>view details</summary>
add GitIndex::try_new*() and GitIndex::try_with_path() to open without cloning. These methods are naturally read-only and thus have no issues in concu
<csr-id-421de3512465f135af8d63ed276ceba9e882f8f3/>
GitIndex::try_new*() and GitIndex::try_with_path() to open without cloning.
These methods are naturally read-only and thus have no issues in concurrent contexts, while
not providing an option to not auto-clone a whole index.Names iterator as building block for fuzzy-lookups.
It creates all allowed permutations regarding - and _ in the crate name,
so it should be possible to find a crate even if the name doesn't have the correct
hyphens or underscores set.<csr-id-28ab782c1ece77af4885e58104fc28b2c8687b0e/> GitIndex::new_*() will not discover the git repository anymore.
Previously, discovery was used which may traverse the directory structure
upwards to find the index. This may be error prone as the index location is
supposed to be well-known.
Now the index path provided must either be .../index or .../index.git to be
opened successfully.
<csr-id-c67033d2c1653eef69e791de0266c15cb7f6321e/> remove the usage of file locks in preference for documentation when opening a git index. Previously, to allow concurrently opening and possibly updating a crates-index, a file-lock was used for synchronization. However, it was rather specific to what the test-suite needed while adding another failure mode for production code which could leave lock-files behind that then lock the crates-index forever for this library at least.
Instead, appropriate locking will be used in tests only, while the documentation of all
open methods of GitIndex was adjusted to inform about ways to protect concurrent accesses
on application level.
<csr-id-3bb46abf5a07db3c4b98dabc7efe6ddebc2174ff/> always use / for sparse URLs
Previously on windows, backslashes could have snuck in which may cause problems.
<csr-read-only-do-not-edit/>
<csr-read-only-do-not-edit/>
<details><summary>view details</summary>
4919cb2)a9b6065)d8fc1c1)GitIndex::try_new*() and GitIndex::try_with_path() to open without cloning. (639b081)GitIndex::new_*() will not discover the git repository anymore. (28ab782)c67033d)6f8aa18)list_recent_versions. (421de35)dc6537a)fdf663e)5f73acd)6125624)2ef9dac)f755b0f)7b8683e)Names (6ab652e)a20138d)6b66356)b63ec37)254d21e)c8aa392)Names iterator (5272d41)Names iterator as building block for fuzzy-lookups. (abe5d70)797081e)61ddff0)1f542a5)a7801b0)Names iterator to fail creation if too many permutations are possible (9b88659)95308c8)bc16839)1429c4e)a0bba1c)5f1f245)/ for sparse URLs (3bb46ab)e322e13)2b6e070)1d8a895)
</details>This is a major release with many breaking changes to make the overall package structure, type-names and feature names more consistent.
<csr-id-c293e35e43650bebbdbd869c4c9d01bfb2e836c0/> <csr-id-2c5d33a51604f032ff1538b16cf0408a8fe2568a/> <csr-id-7e86e3c625944cdeba55dda6086617796fb061e3/> <csr-id-a8953e0939711940f2ef554155edcf3853030df3/> <csr-id-260c103409ff08a96c465568363675d6dc8a2fa7/> <csr-id-235e175022647f9ab63b024ca0780c907b9fd6ec/> <csr-id-beb9f12885703574ba3c3307c368fb84c1a05028/> <csr-id-42d89c2e84f0e81da3db046864be379a2ae9eb15/> <csr-id-965f6e98788a62c380ed1daa61867817685d7371/>
This is a major release with many breaking changes to make the overall package structure, type-names and feature names more consistent.
Note that the default features changed, so if you relied on that you will have to change the dependency definition in your cargo manifest
to something like default-features = false, features = ["git-performance", "git-https"]. This is due to the sparse index now being the default,
just like with cargo itself.
Further, now crate_index::Index is crates_index::GitIndex, but when done all should work as before, maybe even a little bit faster thanks to
replacing git2 with gix.
For details about all breaking changes, please take a look at the (BREAKING) paragraphs that follow.
dirs::TBD to make it possible to know where the index should be looked for.
This might be interesting also for tools that deal with the data alone, like cargo-cache.<csr-read-only-do-not-edit/>
<csr-read-only-do-not-edit/>
Clippy helped 1 time to make code idiomatic.
<csr-read-only-do-not-edit/>
<details><summary>view details</summary>
git2 with gix. (2c5d33a)6b95b8f)include directive to allow publish to succeed (40caa8f)d3b0069)365f9dc)dirs::TBD to make it possible to know where the index should be looked for. (0d89352)GitIndex auto-clones any index as needed. (965f6e9)ssh feature, and rename many existing features, change defaults (a8953e0)beb9f12)b0836d1)cargo-diet to optimize package size (2fdf3a8)7e86e3c)changes feature (260c103)testdata to fixtures (aba9606)tests/ where integration tests live (0096b92)CHANGELOG.md for a built-in version of it (42d89c2)thiserror for the error type. (fed6904)5649466)cc6b8f9)7d70f8f)gix release for API improvements (f50308f)cargo fmt on everything that changed in changes.rs (084f226)90da01e)git2 (d649f95)Changes from git2 to gix (beddca6)11a7522)50edb46)ab0f126)gix version to smoothen API usage (940ed59)8939074)gix for update() (ebfda0f)gix (92291cf)gix for implementing crate_() (2cf53dd)gix for index_config() (cd7f910)crates() to gix (fbf169c)gix for crates_parallel() (141285e)9cac8a8)gix as alternative (3fe885c)f234c9b)
</details>git2 is now optional if you use default-features = false. If git-index feature is enabled, git2 v0.17 is required. You'll want to enable https feature
git2 is now optional if you use default-features = false. If git-index feature is enabled, git2 v0.17 is required. You'll want to enable https feature too.SparseIndex.make_cache_request returns request::Builder instead of Request. Call .body(()) on it.<csr-read-only-do-not-edit/>
<csr-read-only-do-not-edit/>
<details><summary>view details</summary>
34c76db)18eb3f4)3b39fab)05e48cc)c44bea2)8042c98)0faf3c8)cf65d09)1f5bd6c)e0157d0)c725849)
</details>2 commits contributed to the release.
<csr-read-only-do-not-edit/>
<csr-read-only-do-not-edit/>
<details><summary>view details</summary>
22 commits contributed to the release.
<csr-id-de7df1cb85b322e0e9cde387a01f426685d8a4a4/> <csr-id-a69a7785347cfc7b5773c73e0b10b8e5b63a1e58/> <csr-id-135179a0e95a97e3e57d16692c7b17c54ffe0d16/>
<csr-read-only-do-not-edit/>
<csr-read-only-do-not-edit/>
<details><summary>view details</summary>
f0f45b7)9ba7cac)cargo check --all-targets --no-default-features (de7df1c)cargo check --all-targets --no-default-features build (8b1c6d8)cdc8fde)276aab2)07476e5)b636afc)20eca12)a69a778)135179a)f09ff32)82c2849)71a76b0)c5f6123)0ffb5bf)a58beb5)8d20801)2b51d50)a7690ef)f645b4c)d1f51bf)
</details>Allow for fetching indexes from private registries via SSH key
<csr-id-8cf14fbe0317ba4fc443eb6926f4a952bf8e7e0e/>
<csr-read-only-do-not-edit/>
<csr-read-only-do-not-edit/>
<details><summary>view details</summary>
8cf14fb)96f8444)1fe05d4)1b1a9bc)8066188)a6f0d85)810fa87)5db0873)05c0bcb)
</details>Add support for 'rust_version' This was added to the index in rust-lang/crates.io#6267. crates.io is automatically injecting it into the index, even w
<csr-id-286b2251ae8a286f8992831f7a845f88227107dd/>
<csr-id-ab8c655d7835a93c87b348c86ecc928ecfaceaea/> Add support for 'rust_version' This was added to the index in rust-lang/crates.io#6267. crates.io is automatically injecting it into the index, even without using the nightly cargo that supports it.
My plan is to use this to make cargo-upgrade more MSRV aware (in version reqs despite the resolver not yet being MSRV aware).
<csr-read-only-do-not-edit/>
<csr-read-only-do-not-edit/>
<details><summary>view details</summary>
1 commit contributed to the release.
<csr-read-only-do-not-edit/>
<csr-read-only-do-not-edit/>
<details><summary>view details</summary>
ae95a95)
</details>12 commits contributed to the release over the course of 11 calendar days.
<csr-read-only-do-not-edit/>
<csr-read-only-do-not-edit/>
<details><summary>view details</summary>
a6b2595)83bb44b)1a0fd59)70b07f5)fb463b8)29bf4ef)d2dc624)846f600)c5682e4)efa9b25)819215d)585b2a6)
</details>2 commits contributed to the release.
<csr-id-34501eae518292acb55a4821214eff9fc03e7aee/>
<csr-read-only-do-not-edit/>
<csr-read-only-do-not-edit/>
<details><summary>view details</summary>
5 commits contributed to the release over the course of 8 calendar days.
<csr-id-6e5d42720fe76834213723ebe95e52e5dd788f15/>
<csr-read-only-do-not-edit/>
<csr-read-only-do-not-edit/>
<details><summary>view details</summary>
2 commits contributed to the release.
<csr-read-only-do-not-edit/>
<csr-read-only-do-not-edit/>
<details><summary>view details</summary>
1 commit contributed to the release.
<csr-read-only-do-not-edit/>
<csr-read-only-do-not-edit/>
<details><summary>view details</summary>
527e72b)
</details>3 commits contributed to the release.
<csr-id-a3407ce2f58217e0b4dc30552cf65d4a11d67d5a/>
<csr-read-only-do-not-edit/>
<csr-read-only-do-not-edit/>
<details><summary>view details</summary>
3 commits contributed to the release.
<csr-read-only-do-not-edit/>
<csr-read-only-do-not-edit/>
<details><summary>view details</summary>
5 commits contributed to the release over the course of 58 calendar days.
<csr-read-only-do-not-edit/>
<csr-read-only-do-not-edit/>
<details><summary>view details</summary>
Nothing published for this version
add support for replaced source in Cargo config.toml
<csr-id-18253ffa6c5d837efdf607718270c5845ee76f70/>
<csr-read-only-do-not-edit/>
<csr-read-only-do-not-edit/>
<details><summary>view details</summary>
3 commits contributed to the release over the course of 55 calendar days.
<csr-read-only-do-not-edit/>
<csr-read-only-do-not-edit/>
<details><summary>view details</summary>
4 commits contributed to the release over the course of 74 calendar days.
<csr-read-only-do-not-edit/>
<csr-read-only-do-not-edit/>
<details><summary>view details</summary>
8 commits contributed to the release.
<csr-read-only-do-not-edit/>
<csr-read-only-do-not-edit/>
<details><summary>view details</summary>
Nothing published for this version
2 commits contributed to the release.
<csr-read-only-do-not-edit/>
<csr-read-only-do-not-edit/>
<details><summary>view details</summary>
4 commits contributed to the release.
<csr-read-only-do-not-edit/>
<csr-read-only-do-not-edit/>
<details><summary>view details</summary>
9 commits contributed to the release over the course of 10 calendar days.
<csr-read-only-do-not-edit/>
<csr-read-only-do-not-edit/>
<details><summary>view details</summary>
3846c73)ccf7a83)aeb596f)d8da78d)c84ff49)49258c8)0eda4d8)3750c75)297a101)
</details>Nothing published for this version
2 commits contributed to the release.
<csr-read-only-do-not-edit/>
<csr-read-only-do-not-edit/>
<details><summary>view details</summary>
Support non-crates.io registries This matches cargo's behavior for registries that are not hosted on GitHub (like Cloudsmith), and uses the configured
<csr-id-9984f8920bea2fbeea999137b33aae8d8eb2f094/>
<csr-read-only-do-not-edit/>
<csr-read-only-do-not-edit/>
<details><summary>view details</summary>
It should work without any code changes. Only the git2 and toml dependencies were updated.
It should work without any code changes. Only the git2 and toml dependencies were updated.
<csr-read-only-do-not-edit/>
<csr-read-only-do-not-edit/>
<details><summary>view details</summary>
0a79562)bc72a0f)17c27a3)868d870)4632408)542669e)17e2462)67181db)eda4e15)c23932d)164e58c)b7f83df)
</details>Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →