Build provenance: This package is built and distributed by Astral as part of
astral-dev-toolchain. It packagescargo-shearfrom tagv1.13.4at commit1fdd1d97b964162cc8142c2945e18e0a54cd0f92.
Cargo Shear ✂️ 🐑
Detect and fix issues in Rust projects:
- Unused dependencies in
Cargo.toml - Misplaced dependencies (dev/build dependencies in wrong sections)
- Unlinked source files (Rust files not reachable from any module tree)
[!NOTE] This tool is considered feature-complete. We continue to welcome contributions that focus on bug fixes, dependency upgrades, and UI/UX improvements.
Installation
# Install from pre-built binaries.
cargo binstall cargo-shear
# Build from source.
cargo install cargo-shear
# Install from brew.
brew install cargo-shear
Usage
Check for issues without making changes:
cargo shear
Automatically fix unused dependencies:
cargo shear --fix
Treat warnings as errors (exit with failure code):
cargo shear --deny-warnings
This is useful for CI/CD pipelines to enforce strict checking of warnings such as empty files, unlinked files, and unused optional dependencies.
Generate machine-readable JSON output:
cargo shear --format=json
This is particularly useful for CI/CD pipelines and custom tooling that need to programmatically process the results.
Detect mismatches between [lib] target settings and source content:
cargo shear --check-test-targets
When set, cargo-shear warns when test = false is paired with source that contains tests (or doctest = false with source that contains doc tests), and — within a workspace — when test / doctest are left at their default of true for lib targets that contain none. Disabled by default; pair with --fix to automatically reconcile the flags.
Limitations
[!IMPORTANT]
cargo shearcannot detect "hidden" imports from macro expansions without the--expandflag (nightly only). This is becausecargo shearuses rust-analyzer's parser to parse files and does not expand macros by default.
To expand macros:
cargo shear --expand --fix
The --expand flag uses cargo expand, which requires nightly and is significantly slower.
[!IMPORTANT] Misplaced dependency detection only works for integration tests, benchmarks, and examples. Unit tests dependencies within
#[cfg(test)]cannot be detected as misplaced.
Configuration
Ignore false positives
False positives can be ignored by adding them to the package's Cargo.toml:
[package.metadata.cargo-shear]
ignored = ["crate-name"]
Ignore unlinked files
Unlinked files can be ignored using glob patterns:
[package.metadata.cargo-shear]
ignored-paths = ["src/proto/*.rs", "examples/old/*"]
Both options work in workspace Cargo.toml as well:
[workspace.metadata.cargo-shear]
ignored = ["crate-name"]
ignored-paths = ["*/proto/*.rs"]
Ignore scope
- Package ignore (
[package.metadata.cargo-shear]) applies only to that package. - Workspace ignore (
[workspace.metadata.cargo-shear]) applies to every member and to the workspace dependency itself.ignored-pathsglobs are matched relative to the workspace root.
An ignore that suppresses nothing is reported as redundant so it can be removed. A workspace ignore is considered redundant only when no member needs it — a dependency that is used in one crate but unused in another stays covered by the workspace ignore.
cargo-hakari workspace-hack crates
cargo-hakari generates a workspace-hack crate that declares many dependencies it never imports (to unify Cargo features) and is depended on by every workspace member without being imported. cargo shear detects such a crate automatically — via the ### BEGIN HAKARI SECTION marker in its Cargo.toml — and skips both the crate itself and the dependency edges pointing at it, so no ignored configuration is needed.
Otherwise please report the issue as a bug.
CI
[!NOTE]
cargo shearuses static analysis and operates on source code without compiling. This means it only needs to run once on a single platform (e.g., Linux) to detect issues across all target platforms, including those with platform-specific dependencies and conditional compilation.The only exception is when using the
--expandflag, which invokescargo buildand may produce platform-specific results.
- name: Install cargo-binstall
uses: cargo-bins/cargo-binstall@main
- name: Install cargo-shear
run: cargo binstall --no-confirm cargo-shear
- run: cargo shear
JSON Output for CI Integration
For CI systems that require structured output, use the --format=json flag:
- name: Check for unused dependencies
run: cargo shear --format=json > shear-results.json
The JSON output includes:
- summary: Counts of errors, warnings, and fixes
- findings: Detailed information about each issue including:
code: The diagnostic code (e.g.,shear/unused_dependency)severity: Error or warning levelmessage: Human-readable descriptionfile: Path to the file with the issuelocation: Byte offset and length within the filehelp: Suggested fixfixable: Boolean indicating if issue can be auto-fixed with--fix
Exit Code (for CI)
| Exit Code | Without --fix |
With --fix |
|---|---|---|
| 0 | No issues found | No issues found, no changes made |
| 1 | Issues found | Issues found and fixed |
| 2 | Error during processing | Error during processing |
Strict Mode with --deny-warnings
By default, warnings (such as empty files, unlinked files, and unused optional dependencies) exit with code 0. Use the --deny-warnings flag to treat warnings as errors for stricter CI enforcement:
| Exit Code | Without --deny-warnings |
With --deny-warnings |
|---|---|---|
| 0 | No errors (warnings allowed) | No errors or warnings |
| 1 | Errors found | Errors or warnings found |
| 2 | Error during processing | Error during processing |
GitHub Actions Example:
- name: cargo-shear
shell: bash
run: |
if ! cargo shear --fix; then
cargo check
fi
Strict CI Example with --deny-warnings:
- name: cargo-shear (strict)
run: cargo shear --deny-warnings
Technique
- Use the
cargo_metadatacrate to list all dependencies specified in[workspace.dependencies]and[dependencies] - Iterate through all package targets (
lib,bin,example,testandbench) to locate all Rust files - Use rust-analyzer's parser (
ra_ap_syntax) to parse these Rust files and extract imports- Alternatively, use the
--expandoption withcargo expandto first expand macros and then parse the expanded code (though this is significantly slower)
- Alternatively, use the
- Find the difference between the imports and the package dependencies
Prior Art
- est31/cargo-udeps
- it collects dependency usage by compiling your project and find them from the
target/directory - does not seem to work anymore with the latest versions of
cargo - does not work with cargo workspaces
- it collects dependency usage by compiling your project and find them from the
- bnjbvr/cargo-machete
- it collects dependency usage by running regex patterns on source code
- does not detect all usages of a dependency
- does not remove unused dependencies from the workspace root
- cargo and clippy
- There was intention to add similar features to cargo or clippy, but the progress is currently stagnant
- See https://github.com/rust-lang/rust/issues/57274 and https://github.com/rust-lang/rust-clippy/issues/4341
Trophy Cases
- -7 lines from oxc
- -59 lines from rspack
- -39 lines from rolldown
- -12 lines ast-grep commit1 commit2
- -66 lines biome
- -164 lines astral-sh/uv
- -86 lines reqsign
- -184 lines from turbopack
- -625 lines from openai/codex
- -69 lines from uutils/coreutils
- -1,588 lines from vinhnx/vtcode
Sponsored By
Release files for astral-dev-toolchain-cargo-shear 1.13.4
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Built distributions (wheels)
| File | Reset | |||
|---|---|---|---|---|
| astral_dev_toolchain_cargo_shear-1.13.4-py3-none-win_arm64.whl | Python 3 | none | Windows ARM64 | Details |
| astral_dev_toolchain_cargo_shear-1.13.4-py3-none-win_amd64.whl | Python 3 | none | Windows x86-64 | Details |
| astral_dev_toolchain_cargo_shear-1.13.4-py3-none-manylinux_2_17_x86_64.manylinux2014_x86_64.whl | Python 3 | none | Linux glibc 2.17+ x86-64 | Details |
| astral_dev_toolchain_cargo_shear-1.13.4-py3-none-manylinux_2_17_aarch64.manylinux2014_aarch64.whl | Python 3 | none | Linux glibc 2.17+ ARM64 | Details |
| astral_dev_toolchain_cargo_shear-1.13.4-py3-none-macosx_11_0_arm64.whl | Python 3 | none | macOS 11.0+ ARM64 | Details |
| astral_dev_toolchain_cargo_shear-1.13.4-py3-none-macosx_10_12_x86_64.whl | Python 3 | none | macOS 10.12+ x86-64 | Details |
Total release size: 8.7 MB
Release files / astral_dev_toolchain_cargo_shear-1.13.4-py3-none-win_arm64.whl
| Download URL | astral_dev_toolchain_cargo_shear-1.13.4-py3-none-win_arm64.whl |
|---|---|
| Size | 1.4 MB |
| Tags | Python 3 Windows ARM64 |
|
SHA-256 checksum How to use checksums |
91874654b0dcb2b0333a615f81e3cde3f9c10d3148b180254764fce606930af0
|
|
BLAKE2b-256 checksum How to use checksums |
fc7e62dc9d09eec545a555030fbe8fdb117006ad5684ebe8da4dad8c81a6a251
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
uv/0.12.6 {"installer":{"name":"uv","version":"0.12.6","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"24.04","id":"noble","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Aug 25, 2026.
Transparency logRelease files / astral_dev_toolchain_cargo_shear-1.13.4-py3-none-win_amd64.whl
| Download URL | astral_dev_toolchain_cargo_shear-1.13.4-py3-none-win_amd64.whl |
|---|---|
| Size | 1.5 MB |
| Tags | Python 3 Windows x86-64 |
|
SHA-256 checksum How to use checksums |
b682608009b22130ff3b99ab782ce7ee3555711989c2a84ed627be1a016643d6
|
|
BLAKE2b-256 checksum How to use checksums |
caf5db879c8c71810df57b290af915fd4e4cd588d4b8161267d593d45100d7a1
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
uv/0.12.6 {"installer":{"name":"uv","version":"0.12.6","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"24.04","id":"noble","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Aug 25, 2026.
Transparency logRelease files / astral_dev_toolchain_cargo_shear-1.13.4-py3-none-manylinux_2_17_x86_64.manylinux2014_x86_64.whl
| Download URL | astral_dev_toolchain_cargo_shear-1.13.4-py3-none-manylinux_2_17_x86_64.manylinux2014_x86_64.whl |
|---|---|
| Size | 1.6 MB |
| Tags | Linux glibc 2.17+ x86-64 Python 3 |
|
SHA-256 checksum How to use checksums |
bb239c6e9f4abe609b02dbf2933113378bdce845bcaa5ee0000bc7d04750a5ad
|
|
BLAKE2b-256 checksum How to use checksums |
a44fbc9865a14140f5a990f9bbb7ff5b36e2e0f9151d819570fedb516c26fdd6
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
uv/0.12.6 {"installer":{"name":"uv","version":"0.12.6","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"24.04","id":"noble","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Aug 25, 2026.
Transparency logRelease files / astral_dev_toolchain_cargo_shear-1.13.4-py3-none-manylinux_2_17_aarch64.manylinux2014_aarch64.whl
| Download URL | astral_dev_toolchain_cargo_shear-1.13.4-py3-none-manylinux_2_17_aarch64.manylinux2014_aarch64.whl |
|---|---|
| Size | 1.5 MB |
| Tags | Linux glibc 2.17+ ARM64 Python 3 |
|
SHA-256 checksum How to use checksums |
97e9e5ca2854a3b12e511e4f30f47c49fa36aafae79c65c2badf14c4caf47998
|
|
BLAKE2b-256 checksum How to use checksums |
637d1b7e465833026658ffad9f7a504b5f2d6e2b0977000f06faa14192acce3d
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
uv/0.12.6 {"installer":{"name":"uv","version":"0.12.6","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"24.04","id":"noble","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Aug 25, 2026.
Transparency logRelease files / astral_dev_toolchain_cargo_shear-1.13.4-py3-none-macosx_11_0_arm64.whl
| Download URL | astral_dev_toolchain_cargo_shear-1.13.4-py3-none-macosx_11_0_arm64.whl |
|---|---|
| Size | 1.3 MB |
| Tags | Python 3 macOS 11.0+ ARM64 |
|
SHA-256 checksum How to use checksums |
359e17bbfb1b388633dc87277dd6ed13f99d987923c40a574377e44b7449b3d7
|
|
BLAKE2b-256 checksum How to use checksums |
c6dacbf7407c2c9391a986ebd8a05fe2c4aa72c0228723650062928e68f376e9
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
uv/0.12.6 {"installer":{"name":"uv","version":"0.12.6","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"24.04","id":"noble","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Aug 25, 2026.
Transparency logRelease files / astral_dev_toolchain_cargo_shear-1.13.4-py3-none-macosx_10_12_x86_64.whl
| Download URL | astral_dev_toolchain_cargo_shear-1.13.4-py3-none-macosx_10_12_x86_64.whl |
|---|---|
| Size | 1.5 MB |
| Tags | Python 3 macOS 10.12+ x86-64 |
|
SHA-256 checksum How to use checksums |
2142f359d3aa21a1e996ca6f89683f5b990fa568ec24e60036761c225300c35d
|
|
BLAKE2b-256 checksum How to use checksums |
b37d6f44e9e1d0e29b9cd2903eeee8e9cc7612241cd195c7628841f3f9034409
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
uv/0.12.6 {"installer":{"name":"uv","version":"0.12.6","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"24.04","id":"noble","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Aug 25, 2026.
Transparency log