Skip to main content

Build provenance: This package is built and distributed by Astral as part of astral-dev-toolchain. It packages cargo-audit from tag cargo-audit/v0.22.2 at commit 281452c35cf0870969042374110f099a411bc185.


RustSec: cargo audit

Latest Version Build Status Safety Dance MSRV Apache 2.0 OR MIT licensed Project Chat

Audit your dependencies for crates with security vulnerabilities reported to the RustSec Advisory Database.

Related Experimental Tool

If you want additional function-level reachability context, see reachsec, an experimental standalone companion to cargo audit.

Requirements

cargo audit requires Rust 1.74 or later.

Installation

Packaging status

cargo audit is a Cargo subcommand and can be installed with cargo install:

$ cargo install cargo-audit

Once installed, run cargo audit at the toplevel of any Cargo project.

Alpine Linux

# apk add cargo-audit

Arch Linux

# pacman -S cargo-audit

MacOS

$ brew install cargo-audit

OpenBSD

# pkg_add cargo-audit

Screenshot

Screenshot

cargo audit fix subcommand

This tool supports an experimental feature to automatically update Cargo.toml to fix vulnerable dependency requirements.

To enable it, install cargo audit with the fix feature enabled:

$ cargo install cargo-audit --features=fix

Once installed, run cargo audit fix to automatically fix vulnerable dependency requirements in your Cargo.toml:

Screenshot

This will modify Cargo.toml in place. To perform a dry run instead, which shows a preview of what dependencies would be upgraded, run cargo audit fix --dry-run.

cargo audit bin subcommand

Run cargo audit bin followed by the paths to your binaries to audit them:

Screenshot

You can scan a directory recursively using fd:

fd --type=executable --exec-batch cargo audit bin

If your programs have been compiled with cargo auditable, the audit is fully accurate because all the necessary information is embedded in the compiled binary.

For binaries that were not compiled with cargo auditable it will recover a part of the dependency list by parsing panic messages. This will miss any embedded C code (e.g. OpenSSL) as well as roughly half of the Rust dependencies because the Rust compiler is very good at removing unnecessary panics, but that's better than having no vulnerability information whatsoever.

Ignoring advisories

The first and best way to fix a vulnerability is to upgrade the vulnerable crate.

But there may be situations where an upgrade isn't available and the advisory doesn't affect your application. For example the advisory might involve a cargo feature or API that is unused.

In these cases, you can ignore advisories using the --ignore option.

$ cargo audit --ignore RUSTSEC-2017-0001

This option can also be configured via the audit.toml file.

Using cargo audit on Travis CI

To automatically run cargo audit on every build in Travis CI, you can add the following to your .travis.yml:

language: rust
cache: cargo # cache cargo-audit once installed
before_script:
  - cargo install --force cargo-audit
  - cargo generate-lockfile
script:
  - cargo audit

Using cargo audit on GitHub Action

Please use audit-check action directly.

Reporting Vulnerabilities

Report vulnerabilities by opening pull requests against the RustSec Advisory Database GitHub repo:

Report Vulnerability

License

Licensed under either of:

at your option.

Contribution

Unless you explicitly state otherwise, any contribution intentionally submitted for inclusion in the work by you shall be dual licensed as above, without any additional terms or conditions.

Release files for astral-dev-toolchain-cargo-audit 0.22.2

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Built distributions (wheels)

Table of built distributions (wheels) for astral-dev-toolchain-cargo-audit 0.22.2
File
astral_dev_toolchain_cargo_audit-0.22.2-py3-none-win_arm64.whl Python 3 none Windows ARM64 Details
astral_dev_toolchain_cargo_audit-0.22.2-py3-none-win_amd64.whl Python 3 none Windows x86-64 Details
astral_dev_toolchain_cargo_audit-0.22.2-py3-none-manylinux_2_17_x86_64.manylinux2014_x86_64.whl Python 3 none Linux glibc 2.17+ x86-64 Details
astral_dev_toolchain_cargo_audit-0.22.2-py3-none-manylinux_2_17_aarch64.manylinux2014_aarch64.whl Python 3 none Linux glibc 2.17+ ARM64 Details
astral_dev_toolchain_cargo_audit-0.22.2-py3-none-macosx_11_0_arm64.whl Python 3 none macOS 11.0+ ARM64 Details
astral_dev_toolchain_cargo_audit-0.22.2-py3-none-macosx_10_12_x86_64.whl Python 3 none macOS 10.12+ x86-64 Details

Total release size: 38.9 MB

Release files / astral_dev_toolchain_cargo_audit-0.22.2-py3-none-win_arm64.whl

Download URL astral_dev_toolchain_cargo_audit-0.22.2-py3-none-win_arm64.whl
Size 6.4 MB
Tags Python 3 Windows ARM64
SHA-256 checksum
How to use checksums
1295c810c2fd3716f711edb89f17102e2c5843e1e168b33363cad000758c0e40
BLAKE2b-256 checksum
How to use checksums
ea2f5b89f6fc21b7cf71f7beab7c3971637e8de332aa44a389410dcd33c406f1
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via uv/0.12.6 {"installer":{"name":"uv","version":"0.12.6","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"24.04","id":"noble","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Aug 25, 2026.

Transparency log

Release files / astral_dev_toolchain_cargo_audit-0.22.2-py3-none-win_amd64.whl

Download URL astral_dev_toolchain_cargo_audit-0.22.2-py3-none-win_amd64.whl
Size 6.7 MB
Tags Python 3 Windows x86-64
SHA-256 checksum
How to use checksums
ca4cc785faa108091a955d2f8d322e97438a0a9f1dc329b0f28f4cc3f84f2af5
BLAKE2b-256 checksum
How to use checksums
966f41b634c4ec2301c2aa06395ad9edbc668ffd1fa6c0671d3cafafe793e52f
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via uv/0.12.6 {"installer":{"name":"uv","version":"0.12.6","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"24.04","id":"noble","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Aug 25, 2026.

Transparency log

Release files / astral_dev_toolchain_cargo_audit-0.22.2-py3-none-manylinux_2_17_x86_64.manylinux2014_x86_64.whl

Download URL astral_dev_toolchain_cargo_audit-0.22.2-py3-none-manylinux_2_17_x86_64.manylinux2014_x86_64.whl
Size 6.8 MB
Tags Linux glibc 2.17+ x86-64 Python 3
SHA-256 checksum
How to use checksums
08c93fa1f2548f39fd56614496b3629388ccb7df1962f3c6cf9913940e60c40e
BLAKE2b-256 checksum
How to use checksums
2a19daf2941c20e19f423da48b6eb03969c76be2c7031d4ad33ce862d92e64c1
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via uv/0.12.6 {"installer":{"name":"uv","version":"0.12.6","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"24.04","id":"noble","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Aug 25, 2026.

Transparency log

Release files / astral_dev_toolchain_cargo_audit-0.22.2-py3-none-manylinux_2_17_aarch64.manylinux2014_aarch64.whl

Download URL astral_dev_toolchain_cargo_audit-0.22.2-py3-none-manylinux_2_17_aarch64.manylinux2014_aarch64.whl
Size 6.4 MB
Tags Linux glibc 2.17+ ARM64 Python 3
SHA-256 checksum
How to use checksums
9a1079816e0a8dc7bb944e6330e17f3ced31b6f42148dd4771571e65bfd8b127
BLAKE2b-256 checksum
How to use checksums
1acfcf09555b25879fc0dfee061fd50d0e293087be55c65dfa9a55a7a7ed36c3
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via uv/0.12.6 {"installer":{"name":"uv","version":"0.12.6","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"24.04","id":"noble","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Aug 25, 2026.

Transparency log

Release files / astral_dev_toolchain_cargo_audit-0.22.2-py3-none-macosx_11_0_arm64.whl

Download URL astral_dev_toolchain_cargo_audit-0.22.2-py3-none-macosx_11_0_arm64.whl
Size 6.2 MB
Tags Python 3 macOS 11.0+ ARM64
SHA-256 checksum
How to use checksums
c03a59d970ed80b985d06be7aeac8d762f887b6a309f093bcb9943f5fe0108bd
BLAKE2b-256 checksum
How to use checksums
bb1063aac1ed165b6aadf1a02e4691546f58927f2490627e1c051655cb7ab930
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via uv/0.12.6 {"installer":{"name":"uv","version":"0.12.6","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"24.04","id":"noble","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Aug 25, 2026.

Transparency log

Release files / astral_dev_toolchain_cargo_audit-0.22.2-py3-none-macosx_10_12_x86_64.whl

Download URL astral_dev_toolchain_cargo_audit-0.22.2-py3-none-macosx_10_12_x86_64.whl
Size 6.5 MB
Tags Python 3 macOS 10.12+ x86-64
SHA-256 checksum
How to use checksums
f010ac148da38fb562934e3a91e56cf14771c59e569ad2e12268791b02edf81b
BLAKE2b-256 checksum
How to use checksums
a67c9716acf566440a6eb0b173f50a0b0e9b96f4d1f5ddfe649e4b902d95557a
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via uv/0.12.6 {"installer":{"name":"uv","version":"0.12.6","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"24.04","id":"noble","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Aug 25, 2026.

Transparency log

Release history Release notifications | RSS feed

This release

0.22.2 This release

6 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page