Sitelet https://github.com/taiki-e/install-action/issues/1997
Skip to content

cargo-vet 0.10.2 missing from manifests/cargo-vet.json #1997

Description

@ajit-zer07

manifests/cargo-vet.json tops out at 0.10.0 (latest = 0.10.0) as of v2.87.7. There is no manifest entry for cargo-vet 0.10.2, which has been released upstream (https://crates.io/crates/cargo-vet/0.10.2) for some time.

Consequence: consumers who pin tool: cargo-vet@0.10.2 get a manifest miss. With the default fallback: cargo-binstall, that miss is silently absorbed by installing from QuickInstall — a third-party rebuild service — rather than the verified upstream release artifact. For a supply-chain auditing tool specifically, that means the tool that verifies a project's dependency provenance is itself the one thing not installed from a verified upstream source.

Downgrading the pin to 0.10.0 to work around the gap is not viable for projects using crates.io's newer trusted-publisher format in supply-chain/imports.lock (entries like trusted-publisher = "github:..." with no user-id field) — cargo-vet 0.10.0 predates that schema and fails to parse such lockfiles ("missing field user-id"). So affected consumers can't downgrade around the gap either; they're stuck relying on the QuickInstall fallback until a manifest entry exists.

Could a manifest entry for cargo-vet 0.10.2 be added to manifests/cargo-vet.json?

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    C-upstream-bugCategory: This is a bug of upstream (the fix may require action in the upstream)

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions