https://github.com/timweri/cargo-oxidate
Check Cargo dependency freshness - flags packages that are too new or too old
https://github.com/timweri/cargo-oxidate
Last synced: about 1 month ago
JSON representation
Check Cargo dependency freshness - flags packages that are too new or too old
- Host: GitHub
- URL: https://github.com/timweri/cargo-oxidate
- Owner: timweri
- License: mit
- Created: 2026-05-25T20:15:58.000Z (2 months ago)
- Default Branch: main
- Last Pushed: 2026-05-26T02:21:04.000Z (about 2 months ago)
- Last Synced: 2026-05-26T02:31:23.170Z (about 2 months ago)
- Language: Rust
- Size: 28.3 KB
- Stars: 0
- Watchers: 0
- Forks: 0
- Open Issues: 0
-
Metadata Files:
- Readme: README.md
- License: LICENSE
Awesome Lists containing this project
README
# cargo-oxidate
Check `Cargo.lock` for packages that are too new (supply chain risk) or too old (staleness/CVE risk).
## Installation
```sh
cargo install cargo-oxidate
```
## Usage
```sh
# As a cargo subcommand
cargo oxidate --min-age-days 14 --max-age-days 730
# Direct invocation
cargo-oxidate Cargo.lock --min-age-days 14 --max-age-days 730
```
## Options
| Flag | Description |
|------|-------------|
| `--min-age-days N` | Flag packages newer than N days (supply chain security) |
| `--max-age-days N` | Flag packages older than N days (staleness) |
| `--exempt pkg1,pkg2` | Comma-separated packages to skip |
| `--exclude-missing` | Don't flag packages with unknown publish dates |
| `--timeout N` | HTTP timeout in seconds (default: 10) |
| `--suggest-fix` | For "too new" violations, suggest `cargo update` commands to downgrade |
| `--cache-path PATH` | Enable response caching at PATH (or set `CARGO_OXIDATE_CACHE_PATH`) |
| `--cache-max-age-hours N` | Max age for cached version listings (default: 24) |
At least one of `--min-age-days` or `--max-age-days` must be specified.
## Exit Codes
- `0` — No violations found
- `1` — Violations detected
- `2` — Runtime error
## Caching
Repeat runs can reuse crates.io API responses by passing `--cache-path`:
```sh
cargo oxidate --cache-path .cache/oxidate.json --min-age-days 14
```
Per-version publish dates are cached indefinitely (they're immutable on crates.io). Per-crate version listings expire after `--cache-max-age-hours` (default 24h) so newly published versions are picked up.
## GitHub Action
This tool is also available as a GitHub Action. See [examples/usage.yml](examples/usage.yml) or use it in your workflow:
```yaml
- uses: timweri/cargo-oxidate@v0.1.5
with:
min-age-days: 14
max-age-days: 730
cache-responses: true # default; set to 'false' to disable
```
When `cache-responses` is enabled (the default), the action wires up `actions/cache` keyed on the `Cargo.lock` hash so subsequent runs skip already-fetched crates.io responses.
## License
MIT