Automic VaultAutomic Vault

brew

cargo-deny mit Homebrew, apk, dnf, Nix, pacman installieren

Prüfe Installationswege, Executables, Metadaten und Sicherheitshinweise für cargo-deny in AI-Agent-Workflows.

Installation

Weitere Installationsbefehle

macOS

Homebrewverifiziert · 100%
brew install cargo-deny

local Homebrew formula metadata

Linux

Alpine Linux apkverifiziert · 92%
sudo apk add cargo-deny

Alpine Linux edge package indexes · cargo-deny · Quelle: dl-cdn.alpinelinux.org

Fedora dnfverifiziert · 92%
sudo dnf install cargo-deny

Fedora Rawhide package metadata · cargo-deny · Quelle: dl.fedoraproject.org

Nixverifiziert · 92%
nix profile install nixpkgs#cargo-deny

nixpkgs package indexes · pkgs/by-name/ca/cargo-deny/package.nix · Quelle: api.github.com

Arch Linux pacmanverifiziert · 92%
sudo pacman -S cargo-deny

Arch Linux sync databases · cargo-deny · Quelle: geo.mirror.pkgbuild.com

Überblick

Paketzusammenfassung

Cargo plugin for linting your dependencies

Befehle und Aliase

  • cargo-deny

Verlauf

Projektgeschichte und Nutzung

cargo-deny is an Embark Studios Cargo plugin for linting Rust dependency graphs. It checks advisories, license policy, banned crates, duplicate versions, and allowed package sources from a project-level deny.toml file.

Projektgeschichte

Embark Studios created the repository and published the crate in May 2019. The README frames cargo-deny as an open-source release of a tool Embark uses internally, with a dedicated book for in-depth documentation.

The project grew into one of the standard Rust dependency-policy tools, with docs organized around checks for licenses, bans, advisories, and sources. Its repository topics and README both present it as a Cargo subcommand for dependency linting.

Adoptionsgeschichte

cargo-deny has broad adoption for Rust CI because it covers policy decisions that Cargo itself intentionally does not enforce: which licenses are acceptable, whether multiple versions are allowed, whether vulnerable advisories should fail builds, and which registries or git sources are trusted.

The tool is packaged in apk, Homebrew, dnf, Nix, and pacman, and crates.io metadata shows more than four million downloads by June 2026. The README also points to cargo-deny-action for GitHub Actions use.

Wie es verwendet wird

The quickstart is `cargo install --locked cargo-deny && cargo deny init && cargo deny check`. The init command creates a deny.toml template in the current working directory unless a path is supplied.

Users commonly run `cargo deny check` in CI, or run targeted checks such as `cargo deny check licenses`, `cargo deny check bans`, `cargo deny check advisories`, and `cargo deny check sources`.

Warum Paket-Nerds sich dafür interessieren

cargo-deny is package-nerd infrastructure because it makes dependency policy executable. Instead of tracking license allowlists, source restrictions, duplicate-version rules, and advisories in prose, teams can encode them in deny.toml and fail builds consistently.

It is also an example of Cargo's external-tool model handling ecosystem governance concerns without bloating Cargo itself.

Zeitleiste

  • 2019: GitHub repository created and first crates.io publication recorded.
  • 2019-2020: Early 0.6.x tags show rapid iteration on dependency linting.
  • 2024-2026: Release stream continues through 0.19.x.
  • 2026: crates.io metadata shows more than four million downloads and version 0.19.9 current in the sampled registry data.

Related projects

  • cargo-deny-action packages cargo-deny for GitHub Actions workflows.
  • RustSec advisory data is part of the broader ecosystem behind advisory checking.
  • SPDX license identifiers and license lists are central to the licenses check documented by cargo-deny.

Sicherheitslage

Noch keine Protected-Tool-Abdeckung gefunden

Für cargo-deny wurde kein passendes lokales Secret-Handling-Manifest gefunden. Nucleus-Paketmetadaten bleiben hier veröffentlicht, damit künftige Abdeckung eine stabile Paket-URL hat.

Installationsverhalten

  • In den Formelmetadaten ist kein Homebrew-Post-install-Hook erfasst.
  • Homebrew-Bottle-Metadaten sind für 6 Plattformziele verfügbar.
  • Build-Metadaten listen 2 Build-Abhängigkeiten.

Empfohlene Prüfung

Prüfe vor unbeaufsichtigter Agent-Nutzung, ob das Tool Klartext-Credentials liest, Remote-Zustand schreibt, Artefakte veröffentlicht oder Plugins ausführt.

local files

Configuration and credential file locations

These source-backed paths show where this package keeps local settings or durable credentials. Automic Vault can use them as review targets for secret scanning, migration, and command approval.

Configuration files

Config paths the tool may read or write during local use.

Unix
<cwd>/deny.toml

Executables

Installierte Executables

BefehlArtSichtbarkeitHinweis
cargo-denycliglobales Executable

Aktualität

Version und Aktualität

Diese Signale trennen das Alter der Seitengenerierung, Aktivität des Paketmanagers und Upstream-Release-Vergleich. Versionsrückstand wird nur gemeldet, wenn eine Evidenz-URL und vergleichbare Versionen vorhanden sind.

Seite generiert2026-07-25
Manager-Version0.20.2
Manager aktualisiert2026-07-09
lokale DatenOK
Upstreamaktuell
neueste erkannte Version0.20.2

https://github.com/EmbarkStudios/cargo-deny

  • OKEs wurden keine Aktualitätswarnungen generiert.

Installationsmetadaten

Paketmetadaten

Paketschlüsselbrew:cargo-deny
Version0.20.2
PaketmanagerHomebrew
Paketmanager-Seitehttps://formulae.brew.sh/formula/cargo-deny
Homepagehttps://github.com/EmbarkStudios/cargo-deny
Repositoryhttps://github.com/EmbarkStudios/cargo-deny
Upstream-Dokumentationhttps://embarkstudios.github.io/cargo-deny
LizenzApache-2.0 OR MIT
Quellarchivhttps://github.com/EmbarkStudios/cargo-deny/archive/refs/tags/0.20.2.tar.gz
Zuletzt aktualisiert2026-07-09T22:03:47Z
Pulseupdated
Build-Abhängigkeitenpkgconf, rust
Bottleverfügbar (auf arm64_linux, arm64_sequoia, arm64_sonoma, arm64_tahoe, sonoma, x86_64_linux)
Homebrew post-installnicht definiert
Dienstkeiner deklariert

Registry-Fakten

Details aus der Quelldatenbank

Source DatabaseHomebrew formula API
Taphomebrew/core
Full Namecargo-deny
Version Scheme0
Revision0
Head VersionHEAD
Bottle Stable Root URLhttps://ghcr.io/v2/homebrew/core
Deprecatedno
Disabledno
Keg Onlyno
URL Keys
  • head
  • stable

Source-Datenbank-Treffer

Andere Paketmanager-Einträge

Treffer stammen aus externen Paketmanager-Indizes und bleiben von lokalen Automic-Vault-Paketlinks getrennt.

Nix95%

cargo-deny

nix profile install nixpkgs#cargo-deny
  • normalized package name match
  • Abgeglichen nach: Cargo Deny
nixpkgs package indexes · api.github.com · nixpkgs package indexes: pkgs/by-name/ca/cargo-deny/package.nix from https://api.github.com/repos/NixOS/nixpkgs/git/trees/master?recursive=1
apk95%

cargo-deny 0.18.6-r0

Cargo plugin for linting your dependencies

https://github.com/EmbarkStudios/cargo-deny

sudo apk add cargo-deny
  • License: MIT OR Apache-2.0
  • Architecture: x86_64
  • Source Package: cargo-deny
  • 1 Abhängigkeiten
  • 1 stellt bereit
  • normalized package name match
  • Abgeglichen nach: Cargo Deny
Alpine Linux edge package indexes · dl-cdn.alpinelinux.org · Alpine Linux edge package indexes: cargo-deny from https://dl-cdn.alpinelinux.org/alpine/edge/community/x86_64/APKINDEX.tar.gz
dnf95%

cargo-deny 0.18.9-5.fc45

Cargo plugin to help you manage large dependency graphs

https://crates.io/crates/cargo-deny

sudo dnf install cargo-deny
  • License: Apache-2.0 AND Apache-2.0 WITH LLVM-exception AND BSD-3-Clause AND CC0-1.0 AND CDLA-Permissive-2.0 AND ISC AND MIT AND Unicode-3.0 AND Unicode-DFS-2016 AND
  • Category: Unspecified
  • Architecture: x86_64
  • Source Package: rust-cargo-deny
  • 4 Abhängigkeiten
  • 1 stellt bereit
  • normalized package name match
  • Abgeglichen nach: Cargo Deny
Fedora Rawhide package metadata · dl.fedoraproject.org · Fedora Rawhide package metadata: cargo-deny from https://dl.fedoraproject.org/pub/fedora/linux/development/rawhide/Everything/x86_64/os/repodata/e5ca8ce900cd68f5419e1c39ae517343100b306336cbaeb70a3c153121d95094-primary.xml.zst
pacman95%

cargo-deny 0.19.8-1

Cargo plugin for linting your dependencies

https://github.com/EmbarkStudios/cargo-deny

sudo pacman -S cargo-deny
  • License: MIT AND Apache-2.0
  • Architecture: x86_64
  • 4 Abhängigkeiten
  • normalized package name match
  • Abgeglichen nach: Cargo Deny
Arch Linux sync databases · geo.mirror.pkgbuild.com · Arch Linux sync databases: cargo-deny from https://geo.mirror.pkgbuild.com/extra/os/x86_64/extra.db.tar.gz

Quellspur

Aus Repository-Daten generiert

Diese Seite wird von av-web aus dem privaten Paket-SQLite-Artefakt bereitgestellt, das scripts/generate-pkg-sqlite.py erstellt.

Verwendete Quellen

  • Geiger risk classifier
  • Nucleus package database
  • av.db category and tag curation
  • cross-ecosystem install command graph
  • curated configuration and credential file locations
  • curated package history
  • external package-manager database matches
  • package relationship graph
  • package version freshness
  • package-page enrichment