Warn about security advisories for cratres being added with cargo add
#10654
Labels
C-feature-request
Category: proposal for a feature. Before PR, ping rust-lang/cargo if this is not `Feature accepted`
Command-add
S-triage
Status: This issue is waiting on initial triage.
Problem
A user can add a crate with a security advisory and not know it unless they know of the third-party
cargo audit
, install it, and run it.Proposed Solution
Integrate
cargo audit
checks intocargo add
when adding a new registry dependencyNotes
Inspired by conversation on zulip about checking it in cargo
It looks like we
We might be blocked on rustsec/rustsec#490
The text was updated successfully, but these errors were encountered: