Skip to content

Feature request: easier reviewing of newer versions #761

@kpreid

Description

@kpreid

Right now, cargo crev is heavily oriented towards reviewing the current versions of one’s current dependencies. It would be nice if the user interface provided easy ways to review dependencies before updating or adding them; this would avoid risks of executing possibly-malicious code (via some Cargo command on the modified project) before a review of the new dependencies has been completed.

I don't have any specific ideas of how to improve the situation when doing a full review of a not-yet-added dependency (just taking the latest in the index feels a bit fragile), but cargo crev crate diff could have an option to specify a future version to compare, whereas it currently seems to always diff the locked version against the last-reviewed version.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions