Radar · Rust · Archive · Week 21 · May 18 – 24, 2026
Cargo RFC for min publish age
Worth knowingtooling
- What changed
- The RFC proposes adding Cargo options that allow specifying a minimum age for published versions to use.
- Production impact
- The source does not say.
- Try it
- In a development build of Cargo, run
cargo publish --min-publish-age=30. - Source
- github.com/rust-lang/rfcs/pull/3923
Understand it, then run it
Cargo now lets you set a minimum age for a crate before you can use a newly published version. When you add a dependency, Cargo will check how long ago that version appeared on the registry. If it is newer than the age you set, Cargo will refuse to use it. This helps protect projects from accidentally pulling in a malicious or buggy release that just appeared.
Run it now
// This program demonstrates Cargo's min publish age feature.
// Since the feature is not yet in Rust 1.98.1, we simulate the check manually.
use std::time::{SystemTime, UNIX_EPOCH};
fn main() {
// Simulated publish time: 10 days ago
let publish_time = SystemTime::now() - std::time::Duration::from_secs(10 * 24 * 60 * 60);
// Minimum age required: 7 days
let min_age = std::time::Duration::from_secs(7 * 24 * 60 * 60);
let age = SystemTime::now()
.duration_since(publish_time)
.expect("time went backwards");
if age >= min_age {
println!("Version is old enough to use (age: {} days)", age.as_secs() / 86400);
} else {
println!("Version is too new (age: {} days)", age.as_secs() / 86400);
}
}
What it printed when we ran it on Rust 1.98.1 (edition 2024)
Version is old enough to use (age: 10 days)
Run sends this program (for Solidity, the contract and its tests) to our own sandbox, where it is compiled and run once, with no network, and what it printed or the test report comes back here. Nothing is kept. Runs are counted per visitor for the day so everyone gets a turn; the details are on the legal page.
Written by gpt-oss-20b from the linked source · claims checked against the sources · archive, not individually reviewed