CratesReport
A web dashboard that gathers Rust crates from crates.io alongside the output of various program-analysis and security tools, so you can assess a dependency before you trust it.
CratesReport is a website I developed and maintain for the Davis Programming Languages group that collects security information about Rust crates in one place. It pulls crates from crates.io and pairs each one with the output of several program-analysis and security tools, download statistics, and other signals that help you decide whether a dependency is safe to pull into your project.
Why I built it
Deciding whether a crate is trustworthy usually means hopping between crates.io, GitHub, advisory databases, and whatever analysis tooling you happen to run yourself. CratesReport brings those signals together so the question “should I depend on this crate?” has a single place to start.
What it does
- Aggregates crates from crates.io with the results of various program-analysis and security tools.
- Surfaces download statistics and other relevant metadata for each crate.
- Presents everything in a browsable interface so you can assess a dependency before using it.
Explore it live at davispl.github.io/crates.