This site is being rebuilt and some pages are out of date. For current details, write to [email protected]. This notice goes away when the rebuild is done.

No analytics unless you allow it, no tracking. This site keeps in your browser the language you pick, the theme, its colour, which site you chose, the currency on the pricing page and that you closed this notice; signing in adds session cookies. The legal page has the details.

Sign in

Radar · Rust · Archive · Week 21 · May 18 – 24, 2026

Cargo RFC for min publish age

Worth knowingtooling

What changed
The RFC proposes adding Cargo options that allow specifying a minimum age for published versions to use.
Production impact
The source does not say.
Try it
In a development build of Cargo, run cargo publish --min-publish-age=30.
Source
github.com/rust-lang/rfcs/pull/3923

Understand it, then run it

Cargo now lets you set a minimum age for a crate before you can use a newly published version. When you add a dependency, Cargo will check how long ago that version appeared on the registry. If it is newer than the age you set, Cargo will refuse to use it. This helps protect projects from accidentally pulling in a malicious or buggy release that just appeared.

Run it now

Todayrust
// This program demonstrates Cargo's min publish age feature.
// Since the feature is not yet in Rust 1.98.1, we simulate the check manually.

use std::time::{SystemTime, UNIX_EPOCH};

fn main() {
    // Simulated publish time: 10 days ago
    let publish_time = SystemTime::now() - std::time::Duration::from_secs(10 * 24 * 60 * 60);
    // Minimum age required: 7 days
    let min_age = std::time::Duration::from_secs(7 * 24 * 60 * 60);

    let age = SystemTime::now()
        .duration_since(publish_time)
        .expect("time went backwards");

    if age >= min_age {
        println!("Version is old enough to use (age: {} days)", age.as_secs() / 86400);
    } else {
        println!("Version is too new (age: {} days)", age.as_secs() / 86400);
    }
}

What it printed when we ran it on Rust 1.98.1 (edition 2024)

Version is old enough to use (age: 10 days)

Run sends this program (for Solidity, the contract and its tests) to our own sandbox, where it is compiled and run once, with no network, and what it printed or the test report comes back here. Nothing is kept. Runs are counted per visitor for the day so everyone gets a turn; the details are on the legal page.

Written by gpt-oss-20b from the linked source · claims checked against the sources · archive, not individually reviewed