sl91994/cargo-buildscan

★ 0Forks 0NixGitHub ↗Compare

README

cargo-buildscan

cargo-buildscan — Scan your dependencies' build scripts before they run.

cargo build executes build.rs from every dependency on your machine, with full network and environment access, before your own code is even compiled. In August 2026, a compromised arrayref release added one line to its manifest — a typosquatted dependency whose build script downloaded a payload at compile time.

Existing tools don't cover this. cargo-audit checks known advisories. SonarQube's build-script rules analyze your build.rs, not your dependencies'. cargo-audit-build opens every dependency's build.rs in your editor and asks you to judge — which doesn't scale past a few dozen crates.

cargo-buildscan reads them for you. It parses every dependency's build script with syn, recognizes the idioms that make up the overwhelming majority of legitimate build scripts (rustc version probes, C toolchain detection), and reports only what's left.

It never builds anything. It uses cargo metadata, which does not execute build scripts.

It is not a defense. Static analysis can be evaded, and Cargo's own sandboxing proposal is the real fix. This tool exists to make the unreviewable reviewable: it turns "47 build scripts you'll never read" into "3 you should."

License

This project is dual-licensed under either of the following licenses, at your option:

Contributors

sl91994

Issues