PkgRadar

Cargo · crates.io

cargo-truce

Rs Build Time Command: Process spawn (std::process::Command) at build time.

Why PkgRadar flagged 0.58.1

SeveritySignalEvidence
mediumRs Build Time CommandProcess spawn (std::process::Command) at build time. · cargo-truce-0.58.1/src/util/build.rs

Scanned versions

VersionVerdictScoreScanned (UTC)
0.58.1Review302026-06-13
0.58.0Review302026-06-13
0.57.2Review302026-06-10
0.57.1Review302026-06-08
0.57.0Review302026-06-08
0.56.0Review302026-06-06
0.55.0Review302026-06-05
0.53.0Review302026-06-05
0.52.0Review302026-06-04
0.49.23Review302026-06-03
0.49.22Review302026-06-01
0.49.21Review302026-06-01
0.49.20Review302026-05-31
0.49.19Review302026-05-30
0.49.18Review302026-05-30
0.49.17Review302026-05-30
0.49.16Review302026-05-29
0.49.15Review302026-05-29
0.49.14Review302026-05-28
0.49.13Review302026-05-28
0.49.12Review302026-05-28
0.49.10Review302026-05-28
0.49.8Review302026-05-28
0.49.7Review302026-05-27
0.49.6Review302026-05-27
0.49.4Review302026-05-27

Block this in CI

PkgRadar gates cargo-truce (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem cargo [email protected]