manifests/cargo-vet.json tops out at 0.10.0 (latest = 0.10.0) as of v2.87.7. There is no manifest entry for cargo-vet 0.10.2, which has been released upstream (https://crates.io/crates/cargo-vet/0.10.2) for some time.
Consequence: consumers who pin tool: cargo-vet@0.10.2 get a manifest miss. With the default fallback: cargo-binstall, that miss is silently absorbed by installing from QuickInstall — a third-party rebuild service — rather than the verified upstream release artifact. For a supply-chain auditing tool specifically, that means the tool that verifies a project's dependency provenance is itself the one thing not installed from a verified upstream source.
Downgrading the pin to 0.10.0 to work around the gap is not viable for projects using crates.io's newer trusted-publisher format in supply-chain/imports.lock (entries like trusted-publisher = "github:..." with no user-id field) — cargo-vet 0.10.0 predates that schema and fails to parse such lockfiles ("missing field user-id"). So affected consumers can't downgrade around the gap either; they're stuck relying on the QuickInstall fallback until a manifest entry exists.
Could a manifest entry for cargo-vet 0.10.2 be added to manifests/cargo-vet.json?
manifests/cargo-vet.json tops out at 0.10.0 (latest = 0.10.0) as of v2.87.7. There is no manifest entry for cargo-vet 0.10.2, which has been released upstream (https://crates.io/crates/cargo-vet/0.10.2) for some time.
Consequence: consumers who pin
tool: cargo-vet@0.10.2get a manifest miss. With the defaultfallback: cargo-binstall, that miss is silently absorbed by installing from QuickInstall — a third-party rebuild service — rather than the verified upstream release artifact. For a supply-chain auditing tool specifically, that means the tool that verifies a project's dependency provenance is itself the one thing not installed from a verified upstream source.Downgrading the pin to 0.10.0 to work around the gap is not viable for projects using crates.io's newer trusted-publisher format in
supply-chain/imports.lock(entries liketrusted-publisher = "github:..."with nouser-idfield) — cargo-vet 0.10.0 predates that schema and fails to parse such lockfiles ("missing fielduser-id"). So affected consumers can't downgrade around the gap either; they're stuck relying on the QuickInstall fallback until a manifest entry exists.Could a manifest entry for cargo-vet 0.10.2 be added to manifests/cargo-vet.json?