killercup / killercup/cargo-edit

Value of adding a --cooldown option to delay adoption of crate versions

Open
#963 2 comments 2 reactions 0 assignees View on GitHub
cargo-upgrade enhancement
Dominant language
Rust
Stars
3.5k
Forks
166
PR merge metrics
No merged PRs in 30d

Description

Supply-chain attacks can exploit Cargo's behavior of resolving a project's Cargo.toml restrictions to the newest compatible versions in Cargo.lock.

Other package managers have similar behavior -- for instance, notoriously, the community has suffered from supply-chain attacks through npm, with [Trivy](https://www.paloaltonetworks.com/blog/cloud-security/trivy-supply-chain-attack/) and [Axios](https://unit42.paloaltonetworks.com/axios-supply-chain-attack/) getting gravely compromised in March of this year.

In May, npm-check-updates added a `--cooldown` option to help prevent most of the impact of such attacks. [Other package managers did or are doing the same](https://nesbitt.io/2026/03/04/package-managers-need-to-cool-down.html).

Indeed, compromised package versions tend to be noticed in a matter of hours or days, the alarm is raised, the compromised versions get pulled. A 10-day cooldown would have protected anyone from both the Axios attack and the Trivy attack. Detection speed being roughly proportional to package popularity, adding a cooldown mechanism is simple and effective for supply chain attack mitigation.

Image

(from https://www.npmjs.com/package/npm-check-updates)

I'm writing this issue to ask you to assess the value (and effort) of adding a `--cooldown` option of your own to cargo-edit, to delay adoption of crate versions and help make software a bit safer.

I'm aware that there's an [RFC](https://github.com/rust-lang/rfcs/pull/3923) currently happening about this topic in the rust-lang repo, so maybe Cargo itself is poised to implement a cooldown feature and cargo-edit doesn't need to. Is that correct?

Thank you for all the free cool stuff

Contributor guide

Open the contributing guide

Research direction

Review the Cargo RFC linked in the issue alongside cargo-edit's existing command-line dependency handling. Determine whether Cargo will provide cooldown support and whether cargo-edit should implement its own --cooldown option; done means a maintainer decision with defined scope.

Written by the indexing model from the issue text.

Assessment

Tech stack
rust
Domain
cli, security
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Quiet
Clarity
Needs clarification
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.