About CratesReport
A directory of Rust crates from crates.io enriched with cargo-sherlock trust analysis, cargo-scan side effects, and RustSec advisories.
Who builds this
Built by the DavisPL programming-languages research group at UC Davis. Maintained by Muhammad Hassnain — mhassnain@ucdavis.edu.
Frequently asked questions
What is CratesReport?
CratesReport is a directory of Rust crates from crates.io enriched with security and trust analysis: cargo-sherlock trust modelling, cargo-scan side-effect analysis, and RustSec advisories — collected in one place, one page per crate.
What is cargo-sherlock?
cargo-sherlock models trust in a software supply chain, producing a per-crate trust and distrust assessment along with the assumptions behind it.
What is cargo-scan?
cargo-scan finds side effects (I/O, FFI, unsafe, process, network, and more) in a Rust crate's source, summarising them by effect kind and by file.
Where does the advisory data come from?
Security advisories come from the RustSec advisory database, refreshed periodically and matched to each crate version.
How do I get a crate or version analysed?
Search for the crate on the home page. If we don't have it yet, use the request form — the analysis runs and the report appears here automatically.