Build provenance: This package is built and distributed by Astral as part of
astral-dev-toolchain. It packagescargo-denyfrom tag0.20.2at commitbca0dde53651ee946720e4540b5ce2610bec8f06.
See the book 📕 for in-depth documentation.
To run on CI as a GitHub Action, see cargo-deny-action.
Please Note: This is a tool that we use (and like!) and it makes sense to us to release it as open source. However, we can’t take any responsibility for your use of the tool, if it will function correctly or fulfil your needs. No functionality in - or information provided by - cargo-deny constitutes legal advice.
Quickstart
cargo install --locked cargo-deny && cargo deny init && cargo deny check
Usage
Install cargo-deny
If you want to use cargo-deny without having cargo installed, build cargo-deny with the standalone feature. This can be useful in Docker Images.
cargo install --locked cargo-deny
# Or, if you're an Arch user
pacman -S cargo-deny
Initialize your project
cargo deny init
Check your crates
cargo deny check
Licenses
The licenses check is used to verify that every crate you use has license terms you find acceptable.
cargo deny check licenses
Bans
The bans check is used to deny (or allow) specific crates, as well as detect and handle multiple versions of the same crate.
cargo deny check bans
Advisories
The advisories check is used to detect issues for crates by looking in an advisory database.
cargo deny check advisories
Sources
The sources check ensures crates only come from sources you trust.
cargo deny check sources
Pre-commit hook
You can use cargo-deny with pre-commit. Add it to your local .pre-commit-config.yaml as follows:
- repo: https://github.com/EmbarkStudios/cargo-deny
rev: 0.19.9 # choose your preferred tag
hooks:
- id: cargo-deny
args: ["--all-features", "check"] # optionally modify the arguments for cargo-deny (default arguments shown here)
Contributing
We welcome community contributions to this project.
Please read our Contributor Guide for more information on how to get started.
License
Licensed under either of
- Apache License, Version 2.0, (LICENSE-APACHE or http://www.apache.org/licenses/LICENSE-2.0)
- MIT license (LICENSE-MIT or http://opensource.org/licenses/MIT)
at your option.
Contribution
Unless you explicitly state otherwise, any contribution intentionally submitted for inclusion in the work by you, as defined in the Apache-2.0 license, shall be dual licensed as above, without any additional terms or conditions.
Release files for astral-dev-toolchain-cargo-deny 0.20.2
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Built distributions (wheels)
| File | Reset | |||
|---|---|---|---|---|
| astral_dev_toolchain_cargo_deny-0.20.2-py3-none-win_arm64.whl | Python 3 | none | Windows ARM64 | Details |
| astral_dev_toolchain_cargo_deny-0.20.2-py3-none-win_amd64.whl | Python 3 | none | Windows x86-64 | Details |
| astral_dev_toolchain_cargo_deny-0.20.2-py3-none-manylinux_2_17_x86_64.manylinux2014_x86_64.whl | Python 3 | none | Linux glibc 2.17+ x86-64 | Details |
| astral_dev_toolchain_cargo_deny-0.20.2-py3-none-manylinux_2_17_aarch64.manylinux2014_aarch64.whl | Python 3 | none | Linux glibc 2.17+ ARM64 | Details |
| astral_dev_toolchain_cargo_deny-0.20.2-py3-none-macosx_11_0_arm64.whl | Python 3 | none | macOS 11.0+ ARM64 | Details |
| astral_dev_toolchain_cargo_deny-0.20.2-py3-none-macosx_10_12_x86_64.whl | Python 3 | none | macOS 10.12+ x86-64 | Details |
Total release size: 28.8 MB
Release files / astral_dev_toolchain_cargo_deny-0.20.2-py3-none-win_arm64.whl
| Download URL | astral_dev_toolchain_cargo_deny-0.20.2-py3-none-win_arm64.whl |
|---|---|
| Size | 4.7 MB |
| Tags | Python 3 Windows ARM64 |
|
SHA-256 checksum How to use checksums |
8cb16bf1ce1039f1c2cd4693cbba0e716b269270355261195b7b5af4b23f9e04
|
|
BLAKE2b-256 checksum How to use checksums |
ae809362dbb0c9b0ab998c0beac2bace6c9463a3de637108fbc466c0cac67738
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
uv/0.12.15 {"installer":{"name":"uv","version":"0.12.15","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"24.04","id":"noble","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Sep 15, 2026.
Transparency logRelease files / astral_dev_toolchain_cargo_deny-0.20.2-py3-none-win_amd64.whl
| Download URL | astral_dev_toolchain_cargo_deny-0.20.2-py3-none-win_amd64.whl |
|---|---|
| Size | 4.9 MB |
| Tags | Python 3 Windows x86-64 |
|
SHA-256 checksum How to use checksums |
fa38a4783426db539c456db9319911d81418bbe0e5d1c8da757c4965b9fab44e
|
|
BLAKE2b-256 checksum How to use checksums |
c6d068c33ddc7424e43187836b1a924d1895a1f89d3a438a4dd28c2ed92cc40b
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
uv/0.12.15 {"installer":{"name":"uv","version":"0.12.15","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"24.04","id":"noble","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Sep 15, 2026.
Transparency logRelease files / astral_dev_toolchain_cargo_deny-0.20.2-py3-none-manylinux_2_17_x86_64.manylinux2014_x86_64.whl
| Download URL | astral_dev_toolchain_cargo_deny-0.20.2-py3-none-manylinux_2_17_x86_64.manylinux2014_x86_64.whl |
|---|---|
| Size | 4.9 MB |
| Tags | Linux glibc 2.17+ x86-64 Python 3 |
|
SHA-256 checksum How to use checksums |
ae708f458c23ce1eecfd8f169befbb47424bdc21ecf0965e36db3b1d98400fee
|
|
BLAKE2b-256 checksum How to use checksums |
09407f110ab4ca7b05f2ea91bf55a2642353f9dcb780a567e5ccd030a219f55e
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
uv/0.12.15 {"installer":{"name":"uv","version":"0.12.15","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"24.04","id":"noble","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Sep 15, 2026.
Transparency logRelease files / astral_dev_toolchain_cargo_deny-0.20.2-py3-none-manylinux_2_17_aarch64.manylinux2014_aarch64.whl
| Download URL | astral_dev_toolchain_cargo_deny-0.20.2-py3-none-manylinux_2_17_aarch64.manylinux2014_aarch64.whl |
|---|---|
| Size | 4.7 MB |
| Tags | Linux glibc 2.17+ ARM64 Python 3 |
|
SHA-256 checksum How to use checksums |
0e42259c537b2432f5655b3413940e899906033354c5838e367c6837b467a141
|
|
BLAKE2b-256 checksum How to use checksums |
d02a79d869d8d22a5812028d90369ce6c4735dd47cfe3e5de321aa869c32fae8
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
uv/0.12.15 {"installer":{"name":"uv","version":"0.12.15","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"24.04","id":"noble","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Sep 15, 2026.
Transparency logRelease files / astral_dev_toolchain_cargo_deny-0.20.2-py3-none-macosx_11_0_arm64.whl
| Download URL | astral_dev_toolchain_cargo_deny-0.20.2-py3-none-macosx_11_0_arm64.whl |
|---|---|
| Size | 4.6 MB |
| Tags | Python 3 macOS 11.0+ ARM64 |
|
SHA-256 checksum How to use checksums |
8741971eda68ec4018b891bf4eb97e4e53a16974bf43b7fe9903048919592bb7
|
|
BLAKE2b-256 checksum How to use checksums |
7a51ec56268418cf3a002822b47351dc3f15b89b7300706f6a70b6c46ffdf50f
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
uv/0.12.15 {"installer":{"name":"uv","version":"0.12.15","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"24.04","id":"noble","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Sep 15, 2026.
Transparency logRelease files / astral_dev_toolchain_cargo_deny-0.20.2-py3-none-macosx_10_12_x86_64.whl
| Download URL | astral_dev_toolchain_cargo_deny-0.20.2-py3-none-macosx_10_12_x86_64.whl |
|---|---|
| Size | 4.8 MB |
| Tags | Python 3 macOS 10.12+ x86-64 |
|
SHA-256 checksum How to use checksums |
985935f3757bbe9a0267c94b6e0813fc80c9ba13ba55b207525ee86b05618357
|
|
BLAKE2b-256 checksum How to use checksums |
5d3ba6f62f063d65f5470f8867ed2d701398f3e4f69257403290d9f8a6e8b84e
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
uv/0.12.15 {"installer":{"name":"uv","version":"0.12.15","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"24.04","id":"noble","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Sep 15, 2026.
Transparency log