Skip to content
CAI
Software that uses CAICheck a score

rust-lang/cargo

69.4

Adequate · 28 September 2026

118.6k

lines of production code

Rust

primary language

2

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is the source code for Cargo, the official package manager and build tool for the Rust programming language. It implements the core functionality for managing project dependencies, compiling source code, and publishing packages to registries like crates.io. The codebase also includes internal utility crates for credential management, schema validation, and documentation generation, alongside a comprehensive test suite that validates resolution logic, build processes, and command-line interfaces.

How it got here

2014–2022 — Repository initialization and modularization

36 changes.

This period established the foundational structure of the Cargo repository, including workspace configuration, CI pipelines, and internal utility crates like cargo-platform and mdman. It introduced key user-facing features such as the cargo add command and refactored the CLI architecture, while simultaneously extracting test infrastructure and dependency resolution logic into dedicated, reusable components.

2023 — Credential providers and schema extraction

38 changes.

This period focused on stabilizing the credential process API and introducing platform-specific providers for macOS, Windows, and Linux, alongside experimental support for 1Password. It also involved extracting core schema definitions into a new cargo-util-schemas crate and adding the rustfix library for applying compiler diagnostic suggestions.

2024–2026 — modularization and new diagnostics

54 changes.

This period focused on restructuring Cargo's internal architecture by splitting monolithic modules into dedicated components for operations, sources, and the compiler. It introduced a formal, user-controllable linting system and new commands like \cargo info\ and \cargo report\ to enhance build analysis and package inspection. Significant work also went into stabilizing build script APIs, improving network reliability, and expanding test coverage for workspace and dependency management scenarios.

Features

Add Apache container for network-based test scenarios

The test support suite now includes a new Apache HTTPD container (crates/cargo-test-support/containers/apache) designed to facilitate network container tests. This container is configured to serve a bare Git repository over HTTPS using the git-http-backend, complete with a self-signed SSL certificate and necessary Apache modules (SSL, CGID). It also sets safe.directory permissions to ensure Git operations function correctly within the container environment.

crates/cargo-test-support/containers/apache · high confidence

Add SSHD test container for network tests

Added a new Dockerfile and supporting source file to create an SSHD container image used for network-related tests. The container is based on Alpine 3.24, installs OpenSSH and Git, upgrades libcrypto3, and configures a test user with a pre-initialized bare Git repository to facilitate testing over SSH.

crates/cargo-test-support/containers/sshd · high confidence

Add benchmark utility for global cache last-use data

A new binary utility has been added to the benchmark suite to capture real-world global cache last-use data. This tool scans the system's Cargo home directory (registry cache, source, and git checkouts) to generate a sample database and a random sample of 500 crates, providing realistic input data for the global cache tracker benchmarks.

benches/benchsuite/src/bin · high confidence

Add built-in Cargo credential providers

The \src/util/credential\ module now includes built-in support for three credential strategies: a token-based provider that reads and writes plaintext tokens from Cargo's configuration (supporting login/logout operations), a basic process provider that executes an external command to retrieve a single-line token from stdout, and a full protocol-based process provider that communicates with external credential helpers via Cargo's credential protocol (v1). This enables users to authenticate with registries using stored tokens or external credential helpers directly within the tool.

src/util/credential · high confidence

Add built-in GNOME libsecret credential provider for Linux

Users on Linux can now authenticate with registries using credentials stored in the GNOME Keyring via the new \cargo-credential-libsecret\ crate, which is built into Cargo as \cargo:libsecret\. This provider dynamically loads \libsecret-1.so.0\ to store, look up, and clear registry tokens using the \org.rust-lang.cargo.registry\ schema, eliminating the need for external credential helpers on supported systems.

credential/cargo-credential-libsecret · high confidence

Add fix-json example for applying code suggestions

A new example binary, fix-json, has been added to the rustfix crate. It allows users to apply code fix suggestions from a JSON file (or stdin) directly to source files, handling the reading of suggestions, grouping them by file, and writing the applied fixes back to disk.

crates/rustfix/examples · high confidence

Add mdman documentation and generated output files

Added the source markdown file (mdman.md) and the generated output artifacts (troff man page, markdown, and plain text) for the mdman tool's own documentation. This includes the manual page content describing the tool's usage, options, and Handlebars template syntax.

crates/mdman/doc · high confidence

Add mdman for generating man pages

Introduces the \mdman\ crate, which provides formatters to convert Markdown documentation into man page, plain text, and HTML outputs. The implementation includes a \ManFormatter\ that renders Markdown into roff macros (handling headings, lists, code blocks, and tables), a \TextFormatter\ for plain-text TTY output, and an \MdFormatter\ for HTML generation with specific handling for option blocks and cross-references.

crates/mdman/src/format · high confidence

Added Windows Credential Manager support for Cargo registry authentication

Users on Windows can now authenticate with Cargo registries using the system's Windows Credential Manager. This change introduces the \cargo-credential-wincred\ crate, which implements the credential provider interface to store, retrieve, and delete registry tokens via Windows API calls (\CredReadW\, \CredWriteW\, \CredDeleteW\). On non-Windows platforms, this component gracefully degrades to an unsupported credential handler, ensuring cross-platform compatibility without breaking existing workflows.

credential/cargo-credential-wincred · high confidence

Added example credential providers for file storage and I/O testing

Two new example implementations are now available in the cargo-credential crate to help developers build and test custom credential providers. The \file-provider.rs\ example demonstrates a basic provider that stores credentials in a local JSON file, supporting get, login, and logout actions for crates.io. The \stdout-redirected.rs\ example illustrates how to handle standard I/O redirection, specifically showing how to write informational messages to stderr while ensuring that interactive prompts read from stdin and written to stdout correctly reach the console.

credential/cargo-credential/examples · high confidence

Added platform matching example

A new example demonstrating how to filter a Platform based on the current host target has been added to the cargo-platform crate. This example shows how to parse platform specifications and check if they match the current system configuration.

crates/cargo-platform/examples · high confidence

Added shell completion scripts for Cargo

Added zsh and bash completion scripts for the Cargo command-line tool to the \etc/\ directory. The new \etc/\_cargo\ file provides zsh completion definitions, while \etc/cargo.bashcomp.sh\ provides bash completion, enabling tab-completion for Cargo commands, flags, and arguments in supported shells.

etc · high confidence

Automated generation of Cargo lint documentation

A new \xtask-lint-docs\ tool has been added to automatically generate the Cargo lint reference documentation. This tool reads lint metadata from \cargo::diagnostics\ and writes a structured Markdown file (\doc/book/src/reference/lints.md\) that includes configuration instructions, a table of lint groups with their default levels, and individual lint details such as their primary group, default level, and MSRV. The tool supports a \--check\ mode to verify that the generated documentation matches the current source, ensuring the docs stay in sync with code changes.

crates/xtask-lint-docs · high confidence

Cargo library API documentation and version reporting

The \src\ directory now includes \lib.rs\, \macros.rs\, and \version.rs\, establishing the public API surface for the Cargo library. \lib.rs\ provides the main module structure and exports key types like \GlobalContext\ and \CliError\, while also documenting the internal architecture for external tool developers. \version.rs\ implements the \version()\ function, which reports the Cargo version string (synced with rustc), release channel, and commit information, enabling users to accurately identify their build environment.

src · high confidence

Introduce \`build-rs\` crate for typed build script APIs

The \build-rs\ crate provides a strongly typed interface to the Cargo build script protocol, allowing build scripts to access inputs (such as environment variables, manifest metadata, and configuration flags) and emit outputs (such as \rerun-if-changed\ and \rustc-link-lib\ directives) via Rust functions instead of parsing strings. This release stabilizes the \cargo\_cfg\_target\_has\_atomic\_primitive\_alignment\ function and adds support for \cargo\_makeflags\, \cargo\_manifest\_path\, and the \error\ directive, while also introducing \trim-paths\ input access and ensuring \CARGO\_CFG\_DEBUG\_ASSERTIONS\ is passed based on the profile setting.

crates/build-rs · high confidence

Introduce \`cargo add\` subcommand for managing dependencies

A new \cargo add\ command is available to add dependencies to a \Cargo.toml\ manifest file. It supports adding packages by name or version, specifying local paths or Git repositories, and configuring features, default features, and dependency types (dev, build, or target-specific). The command also allows renaming dependencies and marking them as optional or public.

src/bin/cargo/commands · high confidence

Introduce cargo-util as a shared utility crate

Cargo now includes a new internal \cargo-util\ crate that consolidates shared support code previously scattered across the codebase. This new location provides a \du\ function for estimating disk usage, a \Sha256\ wrapper for file hashing, and a \ProcessBuilder\ for managing external process execution. It also centralizes path-handling utilities (such as \normalize\_path\ and \join\_paths\), dynamic library path resolution, and registry path generation, making these capabilities available for reuse within Cargo.

crates/cargo-util · high confidence

Introduce cargo-util-terminal crate for shared terminal output logic

A new internal crate, \cargo-util-terminal\, has been added to centralize terminal output handling. It provides a \Shell\ abstraction for managing console output, verbosity, and color choices, along with a \style\ module defining standard ANSI styles for status messages, errors, and dependency updates. The crate also re-exports \annotate-snippets\ as \report\ to standardize diagnostic reporting. This change consolidates terminal-related code previously scattered across the codebase into a single, reusable component.

crates/cargo-util-terminal · high confidence

Introduce experimental 1Password credential provider for Cargo

Users can now use 1Password to store and retrieve Cargo registry credentials via the new \cargo-credential-1password\ crate. This experimental tool integrates with the 1Password CLI (\op\) to sign in and fetch tokens, supporting configuration of specific accounts and vaults through \--account\ and \--vault\ arguments. It is not built-in by default; users must install the \op\ CLI, configure Cargo to use the provider in their config file, and run \cargo login\ to save tokens. The crate is maintained as an experiment, with no long-term maintenance guarantee.

credential/cargo-credential-1password · high confidence

Introduce home crate with canonical directory resolution and testable environment abstractions

The \crates/home/src\ location now contains the \home\ crate, providing canonical functions to resolve the user's home directory, Cargo's storage directory (\cargo\_home\), and rustup's storage directory (\rustup\_home\). This implementation replaces the standard library's \home\_dir\ on Windows to avoid discrepancies in emulation environments like Cygwin or MinGW. It also introduces an \Env\ trait and \OsEnv\ implementation in \env.rs\, allowing the environment source to be parameterized for in-process testing by tools like rustup and Cargo.

crates/home/src · high confidence

Introduce mdman for generating man pages from Markdown

A new \mdman\ crate has been added to convert Markdown source files into man pages, Markdown, or plain text. The tool uses Handlebars templates to process input and \pulldown-cmark\ to parse Markdown, supporting features like smart punctuation and cross-references between man pages via a \--man\ mapping argument. It is designed primarily for internal use by the Cargo team to generate documentation.

crates/mdman/src · high confidence

Introduce xtask-spellcheck for automated typos linting

A new \xtask-spellcheck\ tool has been added to the repository. This utility automates the spell-checking process by reading the required \typos\ CLI version from the GitHub Actions workflow configuration, ensuring the correct version is installed (via \cargo install\ if necessary), and executing the spell-checker against the codebase. It supports standard flags for output control, including \--color\, \--quiet\, \--verbose\, and \--write-changes\.

crates/xtask-spellcheck · high confidence

New JSON Schema files for Cargo.toml, Cargo.lock, index, and registry config

The \cargo-util-schemas\ crate now ships with generated JSON Schema files (\manifest.schema.json\, \lockfile.schema.json\, \index.schema.json\, and \registry\_config.schema.json\) that define the structure of Cargo's configuration and index formats. These schemas provide a machine-readable contract for validating \Cargo.toml\ manifests, \Cargo.lock\ files, index entries (including the new \pubtime\ field), and registry configuration files, enabling external tools and editors to offer better validation and autocomplete support.

crates/cargo-util-schemas · high confidence

New \`\#\[cargo\_test\]\` macro with advanced test configuration options

The \crates/cargo-test-macro\ crate introduces the \\#\[cargo\_test\]\ attribute, a replacement for the standard \\#\[test\]\ that provides a sandboxed filesystem environment and supports various configuration rules. Users can now enforce minimum Rust versions (e.g., \\>=1.64\), require specific external commands (e.g., \requires = "rustfmt"\), restrict tests to nightly toolchains, or opt-in to network, container, or \build-std\ tests via environment variables. This macro centralizes test setup and conditional execution logic for Cargo's integration test suite.

crates/cargo-test-macro/src · high confidence

New \`cargo info\` command to display package details

Users can now run \cargo info \<package\>\ to view detailed information about a crate, including its version, license, MSRV, dependencies, and features. The command intelligently prefers local workspace members over registry versions when available, validates MSRV compatibility against the current Rust toolchain, and provides helpful suggestions like \cargo tree\ for non-workspace packages. This new operation is implemented in \src/ops/registry/cargo\_info\ alongside other registry operations like login, logout, owner management, publish, search, and yank.

src/ops/registry · high confidence

New \`cargo report\` subcommands for build analysis

This change introduces the \cargo report\ command family, providing new ways to inspect build logs generated with \-Z build-analysis\. It adds \cargo report sessions\ to list available build sessions, \cargo report timings\ to generate an HTML performance report of compilation times, and \cargo report rebuilds\ to identify which units were rebuilt and why. These commands parse the JSONL log files created during the build to offer deeper visibility into build performance and dependency changes.

_src/ops/cargo\report · high confidence

New \`cargo-util-schemas\` crate for Cargo format definitions

A new \cargo-util-schemas\ crate has been introduced to centralize low-level schema definitions for Cargo's internal formats. This module provides structured types and serialization logic for \Cargo.lock\ files (including \TomlLockfile\ and \TomlLockfileSourceId\), the crates.io index (\IndexPackage\ and \RegistryDependency\), and JSON messages (such as \PackageList\). It also includes validation helpers for restricted names and profiles, and exposes JSON schema generation for these structures when the \unstable-schema\ feature is enabled.

crates/cargo-util-schemas/src · high confidence

New capture utility for archiving workspace manifests

A new tool has been added at benches/capture to capture and archive Cargo.toml files from a workspace. It creates a deterministic .tgz archive containing the workspace's Cargo.toml, Cargo.lock, and relevant manifest files, while stripping out local development sections like \[lib\], \[bin\], \[example\], \[test\], \[bench\], and \[profile\]. The tool also records Git repository information (commit SHA, remote URL, and path) into a .cargo\_vcs\_info.json file within the archive.

benches/capture · high confidence

New fingerprinting module for tracking build freshness

The \src/compiler/fingerprint\ module has been introduced to manage how Cargo determines whether a build unit is 'dirty' (needs recompilation) or 'fresh'. This new module replaces previous inline logic with dedicated components: \dep\_info.rs\ handles the parsing and storage of dependency information files (including a new binary format for faster reading and checksum support), \dirty\_reason.rs\ provides detailed, serializable explanations for why a build was triggered, and \rustdoc.rs\ implements specific fingerprinting for documentation generation to prevent mixing incompatible \.js\/\.html\/\.css\ files across different rustdoc versions. The \mod.rs\ file documents the overall strategy, including mtime tracking, checksum freshness, and the distinction between Fingerprint and Metadata hashes.

src/compiler/fingerprint · high confidence

New in-place Cargo.toml editing utilities

The \src/workspace/editor\ module has been introduced to provide utilities for directly editing Cargo.toml manifest files. This includes a \Dependency\ struct for managing dependency metadata (such as features, default features, and sources) and a \Manifest\ struct that allows parsing and modifying the TOML structure, including support for standard and target-specific dependency tables. These tools enable programmatic, in-place updates to manifest files without requiring full workspace resolution.

src/workspace/editor · high confidence

New lint rules for manifest naming conventions and workspace configuration

This change introduces several new diagnostic rules in the \src/diagnostics/rules\ directory to help users maintain consistent and idiomatic Cargo manifests. The \non\_kebab\_case\_bins\, \non\_kebab\_case\_features\, \non\_kebab\_case\_packages\, \non\_snake\_case\_features\, and \non\_snake\_case\_packages\ lints detect names that do not follow kebab-case or snake-case conventions, providing suggestions to rename them. The \manual\_readme\ lint (in the \pedantic\ group) warns when \package.readme\ is explicitly set to a default value like \README.md\ that can be inferred. The \missing\_lints\_inheritance\ lint alerts users when a package lacks a \\[lints\]\ table despite the workspace defining \workspace.lints\, preventing the common mistake of assuming implicit inheritance. Additionally, the \blanket\_hint\_mostly\unused\ lint warns against applying the \hint-mostly-unused\ profile option to all dependencies (\\\), which can degrade build performance, and the \missing\_lints\_features\ lint errors when unstable lints are used without their required feature gates.

src/diagnostics/rules · high confidence

New registry authentication module with credential provider support

Added src/util/auth/mod.rs, introducing a new registry authentication subsystem that manages credential providers for remote registries. This module implements logic to resolve credential providers from global and registry-specific configurations, supports token-based and process-based credentials, and handles environment variable discovery for registry names and tokens. It integrates with the existing GlobalContext and SourceId types to provide a unified interface for registry authentication.

src/util/auth · high confidence

New resolver implementation with optimized conflict caching and lockfile versioning

The dependency resolution logic in \src/resolver\ has been restructured into a new modular architecture, introducing dedicated files for context management (\context.rs\), dependency caching (\dep\_cache.rs\), and conflict tracking (\conflict\_cache.rs\). This change adds a \ConflictCache\ using a trie structure to efficiently detect and skip known conflicting dependency combinations during backtracking, improving resolution performance. Additionally, the resolver now supports a new \Cargo.lock\ format version (V5), gated behind the \-Znext-lockfile-bump\ unstable flag, allowing for future serialization improvements while maintaining backward compatibility with V1–V4 formats.

src/resolver · high confidence

New rustfix library for applying compiler diagnostic suggestions

The \crates/rustfix/src\ directory now contains the core implementation of the rustfix library, which allows tools to parse \rustc\ JSON diagnostic output and apply suggested code fixes to source files. This change introduces the public API for collecting suggestions from compiler diagnostics, filtering them by applicability (e.g., \MachineApplicable\), and applying replacements to in-memory source code. It includes the data structures for representing diagnostics, spans, and suggestions, as well as the internal logic for safely replacing code ranges and handling conflicts.

crates/rustfix/src · high confidence

New semver compatibility test runner for documentation examples

A new \semver-check\ tool has been added to the workspace to validate the Rust code examples in the semver compatibility documentation. This tool parses annotated code blocks from the reference manual, automatically handling mdbook hidden lines (prefixed with \\# \), and verifies that examples compile or run as expected based on annotations like \MINOR\, \run-fail\, and \dont-deny\. It ensures that code snippets remain valid across version boundaries and are correctly formatted.

crates/semver-check · high confidence

New source configuration and implementation modules

The \src/sources\ directory now contains dedicated modules for managing package sources, including \config.rs\ which parses \\[source.\*\]\ TOML configuration keys into a \SourceConfigMap\ for source replacement, \directory.rs\ implementing \DirectorySource\ for vendored dependencies, \path.rs\ implementing \PathSource\ for local filesystem packages, \replaced.rs\ handling source replacement redirection, and \overlay.rs\ providing an internal overlay mechanism for dependency confusion mitigation. These modules collectively define the \Source\ trait and its built-in implementations, enabling Cargo to query, download, and manage packages from various origins.

src/sources · high confidence

New stale-label check for autolabel trigger files

A new \stale-label\ xtask has been added to detect and report stale paths defined in the \trigger\_files\ sections of \triagebot.toml\ autolabel definitions. This tool scans the repository to identify any trigger file paths that no longer exist, helping maintain the accuracy of automatic labeling rules.

crates/xtask-stale-label · high confidence

New utility modules for caching, locking, and diagnostics

The \src/util\ directory now includes several new modules that support core Cargo operations. \cache\_lock.rs\ introduces a \CacheLocker\ with \DownloadExclusive\, \Shared\, and \MutateExclusive\ lock modes to coordinate concurrent access to package and index caches, ensuring safe parallel builds and downloads. \canonical\_url.rs\ adds a \CanonicalUrl\ type to normalize URLs (e.g., stripping \.git\ extensions, lowercasing GitHub paths) for consistent internal hashing and comparison. \diagnostic\_server.rs\ implements a TCP-based diagnostic server for the \cargo fix\ command, allowing child processes to report migration and fixing status to a parent collector. Additionally, \flock.rs\ provides low-level file locking abstractions (\FileLock\, \Filesystem\) used by the cache locker, while \cpu.rs\ and \counter.rs\ add system CPU idle percentage detection and metrics rate calculation utilities respectively.

src/util · high confidence

New xtask-build-man tool for generating man pages

A new \xtask-build-man\ crate has been added to automate the generation of manual pages for both \mdman\ and \cargo\. This tool reads markdown sources from \crates/mdman/doc/mdman.md\ and \doc/man/cargo\*.md\, processes them using the \mdman\ package, and outputs the results in multiple formats (man, txt, md) to \crates/mdman/doc/out\, \etc/man\, and \doc/book/src/commands\ respectively.

crates/xtask-build-man · high confidence

New xtask-bump-check utility for CI version validation

Adds a new \xtask-bump-check\ crate that serves as a CI tool to detect when workspace members have changed but their versions have not been bumped. The tool compares a base commit against a head commit, identifies changed packages, and verifies that their versions have increased relative to a referenced commit (typically the last published version). It supports GitHub Actions output formatting and excludes specific crates like \cargo\ and \home\ from certain checks to reduce false positives.

crates/xtask-bump-check · high confidence

Repository initialization with configuration and documentation scaffolding

The repository has been initialized with essential configuration files and documentation. This includes a \build.rs\ script to embed git commit information and compress man pages, a \windows.manifest.xml\ for Windows compatibility, and configuration files for \clippy\, \rustfmt\, \deny\, \typos\, and \triagebot\. Documentation scaffolding is provided via \CONTRIBUTING.md\, \CODE\_OF\_CONDUCT.md\, \LICENSE-APACHE\, \LICENSE-MIT\, and \LICENSE-THIRD-PARTY\. A \publish.py\ script is added to automate publishing to crates.io, and a \.git-blame-ignore-revs\ file is created to ignore formatting commits.

(repo-wide) · high confidence

Stabilize cargo lints with structured linting system

The diagnostics module has been restructured to introduce a formal, user-controllable linting system for Cargo. This change adds a new \lint.rs\ module defining \Lint\ and \LintLevel\ (Allow, Warn, Deny, Forbid) types, enabling users to configure specific cargo lints via the \\[lints.cargo\]\ section in their \Cargo.toml\. The system supports feature gates and MSRV checks to conditionally enable lints, and integrates with a new pass-based architecture (\passes.rs\) that evaluates these lints during the parse phase. This provides users with granular control over warning and error levels for cargo-specific issues, moving them from implicit behavior to explicit, configurable diagnostics.

src/diagnostics · high confidence

Stabilized credential-process and registry-auth support

The \cargo-credential\ library is now stable, providing a public API for ecosystem developers to build credential helpers that integrate with Cargo's credential process and registry authentication. This release introduces a \Credential\ trait for implementing providers, a \Secret\ type to safely handle tokens without accidental logging, and robust error handling via \thiserror\. It also ensures interactive providers work correctly by resetting stdin and stdout to the console during execution, and includes protocol improvements like \serde(other)\ for future-proofing enum deserialization.

credential/cargo-credential · high confidence

Support for embedded Cargo manifests in Rust scripts

The workspace parser now supports parsing Cargo manifests embedded directly within Rust source files (scripts). When the \-Zscript\ unstable feature is enabled, Cargo recognizes \.rs\ files (or files without extensions) as potential manifests. It extracts TOML configuration from frontmatter (e.g., \---cargo ... ---\) or shebangs, sanitizes package names for CLI conventions, and validates that only \\[\[bin\]\]\ targets are used. This allows users to define dependencies and build configurations inline in their scripts without needing a separate \Cargo.toml\ file.

src/workspace/parser · high confidence

Support for the unstable \`-Zfix-edition\` flag

Users can now use the \-Zfix-edition\ flag to automatically migrate Rust crate editions. This feature adds a new \fix\_edition\ module that handles the migration workflow: it verifies the current edition, applies fixes using \cargo fix\, updates the \edition\ field in \Cargo.toml\ manifests to the target version, and adds the \unstable-editions\ feature if the target edition is unstable. The implementation ensures that packages are only migrated if they are at the expected starting edition and verifies the build succeeds after the change.

_src/ops/cargo\fix · high confidence

Workspace module reorganization and new cache management features

The \src/workspace\ module has been reorganized, moving internal implementation files (such as dependency, features, manifest, and package handling) into dedicated submodules. This change introduces a new automatic garbage collection system for the global cache, including a SQLite-based tracker to monitor file usage and clean up unused sources, crates, and git data based on configurable age and size limits. Additionally, the workspace now exposes a \SerializedFeature\ structure in package metadata, enabling better serialization of feature information for tools and consumers.

src/workspace · high confidence

macOS Keychain credential provider implementation

The \cargo-credential-macos-keychain\ crate is introduced to handle registry authentication on macOS by storing and retrieving tokens in the system Keychain. This provider, accessible as \cargo:macos-keychain\, implements the standard credential interface to support getting, setting, and removing registry tokens, allowing users to authenticate with registries using their macOS Keychain credentials.

credential/cargo-credential-macos-keychain · high confidence

Removals

Removal of the cargo-rustc command

The \cargo-rustc\ command has been removed from the project. This command previously acted as a wrapper to delegate arguments directly to the \rustc\ compiler, capturing and printing its standard output and error streams. Users relying on this specific command-line interface will no longer have access to this functionality.

commands · high confidence

Security

SSH host key validation for Git sources

Added \known\_hosts.rs\ to validate SSH host keys when fetching Git repositories, mitigating [CVE redacted] by checking against bundled GitHub keys and revocations, and providing user-friendly error messages for key mismatches or missing entries.

src/sources/git · high confidence

Architecture

Cargo ops module reorganized into individual command files

The \src/ops\ directory has been restructured so that each Cargo subcommand (clean, config, doc, fetch, install, metadata, new, pkgid, read\_manifest, remove, run, test) is implemented in its own dedicated source file. This change improves code organization and maintainability by isolating the logic for each command, making it easier to locate and modify specific functionality without navigating a monolithic file.

src/ops · high confidence

Extracted core schema types into cargo-util-schemas

The core schema types—PackageIdSpec, PartialVersion, and SourceKind—have been extracted into the new cargo-util-schemas crate. This refactoring centralizes the parsing and validation logic for package identifiers, partial version requirements, and source kinds (including Git, Registry, and Builtin sources), making these components reusable across the Cargo codebase while preserving existing parsing behavior and error handling.

crates/cargo-util-schemas/src/core · high confidence

Extracted platform and cfg parsing into a standalone \`cargo-platform\` crate

The platform definition and cfg expression parsing logic has been extracted from Cargo into a new, standalone \cargo-platform\ crate. This crate now provides the \Platform\ type, which supports both named targets (e.g., \x86\_64-apple-darwin\) and cfg expressions (e.g., \cfg(any(target\_os = "macos"))\). It includes a dedicated parser for cfg expressions, supporting raw identifiers (e.g., \r\#async\) and boolean literals, along with validation logic that warns against using unsupported cfg keys like \test\, \debug\_assertions\, or \feature\ in dependency specifications. The crate also implements serialization and deserialization via \serde\_core\.

crates/cargo-platform/src · high confidence

Extracted test support utilities into a dedicated crate

The \cargo-test-support\ library has been reorganized into a dedicated crate, extracting shared testing utilities from the main test suite. This change introduces new modules for managing test paths (\paths\), comparing and diffing output (\compare\), handling git repositories (\git\), testing \cargo install\ (\install\), validating package publishing (\publish\), and simulating local registries (\registry\). It also adds support for cross-compilation testing (\cross\_compile\) and Docker container-based tests (\containers\), providing a structured foundation for Cargo's integration tests.

crates/cargo-test-support/src · high confidence

Restructure build context and target information into a dedicated module

The \BuildContext\ struct and target platform information (including \TargetInfo\, \RustcTargetData\, and file type definitions) have been moved into a new \src/compiler/build\_context\ module. This change organizes the static information required for a build task, such as workspace details, profiles, dependency graphs, and rustc target capabilities, into a dedicated location to improve code structure and maintainability.

_src/compiler/build\context · high confidence

Behavioural changes

Benchsuite now uses the crates.io-index-archive for consistent benchmarking

The benchmarking infrastructure in benches/benchsuite/src has been updated to clone the crates.io index from the new crates.io-index-archive repository (https://github.com/rust-lang/crates.io-index-archive) instead of the previous source. This change ensures consistent benchmark results by pinning the index to a specific commit (85f7bfd61ea4fee08ec68c468762e886b2aebec6) and handles git initialization quirks in newer git versions (2.48.0+) by forcing the main branch. The lib.rs file establishes the fixture setup, including creating a local cargo home that points to this local snapshot index, unpacking workspace skeletons, and initializing the GlobalContext for benchmarks.

benches/benchsuite/src · high confidence

Cargo CLI is refactored into a new modular structure with native completions and improved alias handling

The Cargo binary entry point has been restructured into separate \main.rs\ and \cli.rs\ modules, introducing a new \GlobalContext\ for configuration management and integrating \tracing-subscriber\ for logging. This change enables native shell completions via \clap\_complete\ on nightly channels, improves the \cargo --list\ output by including descriptions for well-known external commands like \clippy\ and \fmt\, and refactors alias resolution to support both user-defined and built-in aliases (such as \b\ for \build\ and \rm\ for \remove\) with better error handling for empty or recursive aliases.

src/bin/cargo · high confidence

Clarify internal status and fix build warnings for test-support crates

The \cargo-test-support\ and \cargo-test-macro\ crates now include explicit README warnings stating they are internal tools not intended for external use and may change without notice. Additionally, a new \build.rs\ script was added to \cargo-test-support\ to declare the \emulate\_second\_only\_system\ configuration check, resolving \check-cfg\ warnings during compilation.

crates/cargo-test-support · high confidence

Compiler module reorganization and artifact environment variable support

The compiler source code has been reorganized into a top-level module structure, moving files such as \artifact.rs\, \build\_config.rs\, \compilation.rs\, and \build\_runner/mod.rs\ into \src/compiler\. This refactoring introduces a new \artifact\ module that generates specific environment variables (e.g., \CARGO\_BIN\EXE\\, \CARGO\_CDYLIB\DIR\\) for build scripts based on unit dependencies, and updates the \BuildConfig\ to include new fields like \sbom\ and \compile\_time\_deps\_only\. The \Compilation\ structure now explicitly tracks \lint\_warning\_count\ and manages rustc process wrappers, while \BuildRunner\ centralizes mutable build state including job server management and fingerprint caching.

src/compiler · high confidence

Compiler timing reports now only track units actually executed by the job queue

The compiler's timing report generation has been corrected to exclude units that were not actually processed by the job queue. Previously, the timing module may have recorded data for units that were skipped or handled differently, leading to inaccurate build timelines. This fix ensures that the HTML timing report and associated JSON data reflect only the units that genuinely ran, providing a more accurate view of compilation performance for users analyzing build bottlenecks.

src/compiler/timings · high confidence

Crates.io client library restructured and modernized

The crates-io crate has been moved into a new 'crates' directory structure and updated to use modern Rust error handling (thiserror) and HTTP libraries (http crate). The public API now exposes a generic HttpClient trait for transport abstraction, supports alternative registry authentication via asymmetric tokens, and includes improved error reporting with HTTP headers and status codes in API errors. New fields for binary dependencies and rust version are supported in publish requests.

crates/crates-io · high confidence

Documentation restructured into dedicated book and contributor guides

The documentation source has been reorganized into two distinct mdBook projects: the main Cargo Book (in doc/book) and the Cargo Contributor Guide (in doc/contrib). This move introduces specific build configurations, including a custom CSS theme for the book and a .gitignore to exclude generated output. To support this restructuring, the book.toml files define new repository URLs and edit templates, while extensive redirect rules are added to maintain compatibility with existing documentation links (e.g., mapping old target-triple references to target-tuple and updating deprecated command links). Additionally, man pages for various Cargo subcommands are introduced or updated in doc/man, reflecting current command options and behaviors.

doc · high confidence

Home crate documentation and metadata updates for 0.5.11

The \crates/home\ directory now includes a changelog, license symlinks, and an updated README. The README clarifies that the crate is maintained by the Cargo team primarily for internal use by Cargo and rustup, not for external consumption, and notes that \home\_dir\ now forwards to the standard library implementation available since Rust 1.85.0. The changelog records version 0.5.11, which updates the minimum Rust version to 1.81, updates the \windows-sys\ dependency to 0.59, and adds a notice advising users to use the standard library's \home\_dir\ instead.

crates/home · high confidence

Man pages moved to etc/man and updated for current Cargo commands

The manual pages for Cargo subcommands (such as cargo-add, cargo-bench, cargo-build, cargo-check, cargo-clean, cargo-doc, cargo-fetch, cargo-fix, and cargo-generate-lockfile) have been relocated from src/etc/ to etc/. The documentation has been refreshed to reflect current command-line options, including the addition of the --profile flag for cargo-bench and cargo-doc, the removal of the unstable --breaking flag from cargo-update, and the clarification that cargo-add uses the 'highest' version strategy rather than 'latest'.

etc/man · high confidence

New CI scripts for environment diagnostics, man page validation, and version bump checks

The CI pipeline now includes several new shell scripts and a Python utility to improve build reliability and maintenance. \dump-environment.sh\ displays system and CPU information to aid in debugging, while \clean-test-output.sh\ removes temporary build artifacts to free up disk space. Man page integrity is enforced via \validate-man.sh\, which ensures generated pages match the source, and \validate-version-bump.sh\ integrates \cargo bump-check\ to detect when crate versions need updating. Additionally, \fetch-smoke-test.sh\ verifies that dependency fetching works with static linking, and \generate.py\ creates HTML redirect pages for documentation.

ci · high confidence

New modular HTTP client and retry utilities in src/util/network

This change introduces a new, modular networking layer under \src/util/network\, replacing the previous ad-hoc HTTP handling. It adds \http.rs\ for configuring synchronous libcurl handles (including proxy, SSL, and timeout settings) and \http\_async.rs\ for an asynchronous client that multiplexes requests over a dedicated worker thread. A new \retry.rs\ module provides configurable exponential-backoff retry logic for transient network errors, supporting HTTP 429 and 503 responses with \Retry-After\ header parsing. Proxy configuration now prioritizes Cargo's \http.proxy\ setting, then falls back to Git's \http.proxy\, and finally environment variables. These components collectively improve reliability, performance via HTTP/2 multiplexing, and configurability for network operations.

src/util/network · high confidence

Redesigned configuration system with typed schemas and improved error reporting

Cargo's configuration system has been refactored to use a new internal architecture. Configuration values are now parsed into a typed \ConfigValue\ representation that tracks their source location, enabling richer error messages that pinpoint exactly where a config key was defined. A new custom serde deserializer converts these values into target types, supporting complex structures like \PathAndArgs\ and \ConfigRelativePath\ with proper resolution logic. The system now includes explicit schema definitions for configuration sections such as \\[cache\]\, \\[cargo-new\]\, \\[source\]\, and \\[target\]\, allowing for structured validation and deserialization of settings like cache cleaning frequencies, version control preferences, and target-specific build flags.

src/context · high confidence

Refactor dependency addition logic and improve crate name parsing

The \cargo add\ command's internal implementation has been restructured to improve maintainability and user experience. A new \CrateSpec\ module now handles the parsing of crate names and version requirements, providing clearer error messages when users omit the \@\ separator between a package name and a version. The core \add\ function has been refactored to better manage dependency resolution and feature validation, ensuring that unrecognized features are reported with helpful suggestions based on edit distance. These changes streamline the process of adding dependencies and make error feedback more actionable for users.

_src/ops/cargo\add · high confidence

Refactored compilation target selection and added build-started JSON logging

The compilation logic has been restructured to use a new \CompileFilter\ system (in \compile\_filter.rs\) that explicitly manages which targets (lib, bins, tests, examples, benches) are included, replacing the previous implicit filtering. This change also introduces a \BuildStarted\ JSON message emitted to the shell output at the beginning of a build, containing a \run\_id\ and build metadata, which aids in tracking and correlating build events.

_src/ops/cargo\compile · high confidence

Refactored manifest schema module and introduced dedicated RustVersion type

The manifest schema definitions in \crates/cargo-util-schemas/src/manifest\ have been reorganized into a dedicated module structure, extracting \RustVersion\ handling into its own file. This change introduces a specific \RustVersion\ type for parsing and validating the \rust-version\ field, replacing previous ad-hoc logic. The \TomlManifest\ struct is updated to reflect these structural changes, including the addition of a \hints\ field and adjustments to how package fields are resolved and normalized. Users will see these changes as internal refactoring that improves the maintainability and type safety of manifest parsing without altering the external \Cargo.toml\ syntax.

crates/cargo-util-schemas/src/manifest · medium confidence

Refactored registry source implementation into modular components

The registry source logic in \src/sources/registry\ has been reorganized into distinct modules to improve maintainability and clarity. Download logic for crate tarballs is now centralized in \download.rs\, shared between \HttpRegistry\ and \GitRegistry\. The \git\_remote.rs\ and \http\_remote.rs\ files now explicitly implement the \GitRegistry\ and \HttpRegistry\ types respectively, with \HttpRegistry\ serving as the default for HTTP-based registries. Index management is split into \index/mod.rs\ for core query logic and \index/cache.rs\ for the on-disk summary cache, which optimizes null build performance by avoiding repeated JSON parsing. A new \local.rs\ module handles local filesystem registries, verifying checksums and unpacking \.crate\ files. These changes clarify the separation of concerns between index loading, package downloading, and registry-specific protocols without altering the external behavior of registry resolution.

src/sources/registry · high confidence

Restructured \`cargo package\` implementation into modular source files

The \cargo package\ operation has been refactored by splitting its implementation into three distinct modules: \mod.rs\ (core packaging logic), \vcs.rs\ (Git repository state and VCS info generation), and \verify.rs\ (crate verification and build-script integrity checks). This change reorganizes the existing functionality without altering user-facing behavior, moving code from a monolithic structure into a more maintainable layout while preserving all current features such as dirty-worktree detection, symlink warnings, and build-script modification checks.

_src/ops/cargo\package · high confidence

Rustfix crate documentation and license structure updated

The rustfix crate now includes a formal CHANGELOG.md documenting its history from version 0.4.0 to 0.4.6, and its license files (LICENSE-APACHE and LICENSE-MIT) have been converted to symlinks pointing to the root repository licenses. The README.md remains in place, clarifying that rustfix is a low-level library for applying fix suggestions from rustc JSON output and is primarily maintained for internal use by Cargo and the Rust compiler test suite.

crates/rustfix · high confidence

Stabilize cargo-lints warning handling in the compiler job queue

The compiler's job queue now respects the \build.warnings='deny'\ configuration when reporting diagnostics. Specifically, the \JobState\ implementation checks the \WarningHandling\ setting during diagnostic emission; if a lint warning is encountered and the configuration is set to deny, the system logs a warning via the tracing layer instead of emitting it as a standard diagnostic, ensuring that lint warnings are treated as errors in the build output.

_src/compiler/job\queue · high confidence

Test coverage

Add initial benchmarking suite for Cargo; Add mdman man-page generation test fixtures; Added build script execution verification test; Added comprehensive integration tests for -Zbuild-std; Added empty sysroot library for test suite; Added integration tests for cargo-credential examples; Added mock standard library implementations for testing; Added mock-std test fixtures for compiler\_builtins and core; Added property-based and unit tests for the SAT resolver; Added regression test for Issue 14409; Added rustfix integration tests for suggestion edge cases; Added snapshot tests for mdman output and error handling; Added snapshot-based tests for rustfix suggestion application; Added test case for cargo info with default registry configured and specified; Added test case for default registry configuration; Added test case for workspace inherit public detection; Added test fixture for cargo\_add public interface; Added test fixture for invalid dependency removal; Added test fixture for workspace package inheritance logic; Added test fixtures for \--keep-going\ suggestion matching; Added test fixtures for cargo add --public behavior; Added test fixtures for cargo add feature limit handling; Added test fixtures for cargo add name normalization scenarios; Added test fixtures for cargo add overwrite scenarios; Added test fixtures for cargo new workspace member scenarios; Added test fixtures for cargo remove garbage collection scenarios; Added test fixtures for cargo remove workspace scenarios; Added test fixtures for cargo\_add feature preservation; Added test fixtures for gc\_keep\_used\_patch scenario; Added test fixtures for invalid inherited dependency scenario; Added test fixtures for vendored package scenarios; Added test fixtures for workspace member addition scenarios; Added test fixtures for workspace member management scenarios; Added test for inherit default features with 2024 edition; Added test for inherit no default features case; Added test for workspace lint inheritance; Added test for workspace package inheritance behavior; Added tests for \cargo new\ with inherited workspace package table; Added tests for \inherit\_workspace\_package\_table\ scenarios; Added tests for cargo add feature limit errors; Added tests for cargo add path-base handling; Added tests for cargo add rust-version behavior; Added tests for cargo remove; Added tests for cargo-info workspace scenarios; Added tests for cfg expression parsing and matching in cargo-platform; Added tests for feature suggestion scenarios; Added tests for rustc version selection in cargo add; Added tests for workspace-aware cargo new behavior; Expanded test coverage for Cargo's test suite; Extracted resolver test infrastructure into a dedicated crate; Reorganized cargo\_add test fixtures into testsuite; Updated cargo init test fixtures to use u64 for default integer arithmetic; Updated test fixtures for cargo-init scenarios.

Dependencies

Initial workspace setup with Cargo 0.102.0 and Rust 2024 edition

Cargo initializes a new workspace structure with version 0.102.0, adopting the Rust 2024 edition and setting a minimum supported Rust version (MSRV) of 1.95. The project configures a comprehensive set of workspace dependencies, including gix 0.85.0, git2 0.21.0, clap 4.6.0, and curl-sys 0.4.88, and generates a corresponding Cargo.lock file to pin these transitive dependencies.

(dependencies) · high confidence

Housekeeping

The cargo-platform crate now includes a README clarifying that it is maintained by the Cargo team and follows semver compatibility, along with symbolic links to the project's Apache-2.0 and MIT license files.

crates/cargo-platform · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Score

  • CAI 68 → 69 (+1.9)
  • Rubric changed (rubric-2026.09.8 → rubric-2026.09.16) — scores are not directly comparable.

Lenses

  • Code Health 80 → 81 (+0.4)
  • Architecture 67 → 70 (+3.5)
  • Maturity 62 → 66 (+3.6)
  • Readiness 71 → 66 (-5.5)
  • Security 78 → 81 (+3.3)
  • Domain Modelling 100 → 100 (+0.0)
  • Performance 100 (new)

Resolved (65)

  • Change coupling: blanket_hint_mostly_unused.rs ↔ unknown_lints.rs (src/diagnostics/rules/blanket_hint_mostly_unused.rs)
  • Duplicated block (11 lines × 2) (src/sources/path.rs)
  • Duplicated block (6 lines × 2) (src/context/mod.rs)
  • Duplicated block (6 lines × 2) (src/context/mod.rs)
  • Duplicated block (6 lines × 2) (src/util/credential/paseto.rs)
  • FileTooLong: auth/mod.rs (src/util/auth/mod.rs)
  • FunctionTooLong: cargo::context::save_credentials (src/context/mod.rs)
  • FunctionTooLong: cargo::util::auth::credential_provider (src/util/auth/mod.rs)
  • HackComment (src/workspace/parser/mod.rs)
  • Hotspot: crates/cargo-test-macro/src/lib.rs (crates/cargo-test-macro/src/lib.rs)
  • Hotspot: crates/cargo-test-support/src/registry.rs (crates/cargo-test-support/src/registry.rs)
  • Hotspot: crates/cargo-util-schemas/src/manifest/mod.rs (crates/cargo-util-schemas/src/manifest/mod.rs)
  • Hotspot: crates/cargo-util/src/process_builder.rs (crates/cargo-util/src/process_builder.rs)
  • Hotspot: src/bin/cargo/commands/add.rs (src/bin/cargo/commands/add.rs)
  • Hotspot: src/bin/cargo/commands/install.rs (src/bin/cargo/commands/install.rs)
  • Hotspot: src/bin/cargo/commands/remove.rs (src/bin/cargo/commands/remove.rs)
  • Hotspot: src/bin/cargo/commands/tree.rs (src/bin/cargo/commands/tree.rs)
  • Hotspot: src/compiler/build_runner/compilation_files.rs (src/compiler/build_runner/compilation_files.rs)
  • Hotspot: src/compiler/build_runner/mod.rs (src/compiler/build_runner/mod.rs)
  • Hotspot: src/compiler/fingerprint/dep_info.rs (src/compiler/fingerprint/dep_info.rs)
  • …and 45 more

New (24)

  • Boundary-crossing change coupling: lib.rs ↔ directory.rs (crates/resolver-tests/src/lib.rs)
  • Change coupling clique: blanket_hint_mostly_unused.rs, im_a_teapot.rs, unknown_lints.rs (src/diagnostics/rules/blanket_hint_mostly_unused.rs)
  • Dependency hygiene PARTLY measured — Cargo dependencies read, no committed lock to grade for currency
  • Duplicated block (13 lines × 2) (src/sources/path.rs)
  • FileTooLong: ops/cargo_clean.rs (src/ops/cargo_clean.rs)
  • FunctionTooLong: cargo::bin::cargo::commands::install::exec (src/bin/cargo/commands/install.rs)
  • Hotspot: src/compiler/unused_deps.rs (src/compiler/unused_deps.rs)
  • Inconsistent naming and parameter structure for linking arguments. rustc_link_arg takes a single flag. rustc_link_arg_bin takes a bin name and a flag. However, rustc_link_arg_bins, tests, examples, and benches take only a flag, implying they apply to all targets of that kind. This inconsistency makes it unclear if rustc_link_arg_bin is meant to be the general case for a single target, while the others are bulk operations, or if the naming is just arbitrary.
  • Inconsistent naming for project creation helpers. project creates in a default location, project_in takes a directory, and project_in_home takes a name (presumably relative to home). The naming doesn't clearly convey the relationship between the arguments and the resulting path structure.
  • Inconsistent parameter order for symlink operations. ProjectBuilder methods take dst then src, while Project.symlink takes src then dst. This inconsistency increases the risk of errors when switching between building a project and manipulating an existing one.
  • MethodTooLong: ArgMatchesExt.compile_options (src/util/command_prelude.rs)
  • Off the main sequence: cargo-credential
  • Off the main sequence: cargo-platform
  • Off the main sequence: cargo-util
  • Off the main sequence: cargo-util-schemas
  • Off the main sequence: crates-io
  • Off the main sequence: rustfix
  • Off-boarding risk: anonymized user #1
  • PackageRegistry::query (cyclomatic 16) (src/workspace/registry.rs)
  • Projects may be oversized for their cohesion
  • …and 4 more

Changes since last survey

  • 123 commits — 82 feature/other, 41 fixes

By area

  • tests/testsuite — 32 commits
  • (repo) — 30 commits
  • src/workspace — 13 commits
  • doc/book — 11 commits
  • src/ops — 7 commits
  • src/compiler — 6 commits
  • (root) — 4 commits
  • crates/build-rs — 4 commits
  • src/context — 4 commits
  • src/diagnostics — 4 commits
  • crates/cargo-util-schemas — 3 commits
  • src/sources — 3 commits
  • .github/workflows — 1 commit
  • src/util — 1 commit

Notable commits

  • fix: fix(build-dep): Reject builtin dependencies in build-dependencies
  • fix: fix(build-rs): make unstable compile (#17489)
  • fix: fix(build-rs): make unstable compile
  • fix: fix(builtin-deps): Builtin dependencies manifest validation (#17499)
  • fix: fix(builtin-deps): Reject builtin = false
  • fix: fix(builtin-deps): Reject builtin = true in combination with other sources
  • fix: fix(builtin-deps): Reject builtin when workspace = true
  • fix: fix(builtin-deps): Reject version specifier on builtin deps
  • fix: fix(builtin-deps): Require feature gate for patches in config
  • fix: fix(builtin-deps): Require feature gate when patching with builtins
  • fix: fix(builtin-deps): Require the builtin-dependencies feature
  • fix: fix(builtin-deps): Require unstable feature for unused workspace dependency
  • fix: fix(builtin-deps): Require unstable feature when replacing with builtin
  • fix: fix(compilation): Preventing OUT_DIR env var from leaking into cargo run after build.rs run (#17503)
  • fix: fix(compilation): Preventing OUT_DIR from leaking into cargo run
  • fix: fix(diag): Don't report unused normal deps when static libs are skipped
  • fix: fix(diag): Don't report unused normal deps when static libs are skipped (#17515)
  • fix: fix(git): For git cli, tell users what config we aren't forwarding on error
  • fix: fix(git): For git cli, tell users what config we aren't forwarding on error (#17477)
  • fix: fix(package): preserve feature metadata
  • …and 103 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

rust-lang/cargo was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 28 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 523e530d77cce92813eebbf6ac009a04f2df2ac2 — the exact code this score is about.
  • Scored under rubric-2026.09.16 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-d46da229e3fd.