Issues found
Based on crates you own that have been published to crates.io. The best way to monitor these issues is to subscribe to the atom feed in your RSS reader.
arbit
Dependency opentelemetry ^0.26 is significantly outdated
Upgrade to 0.32.0 to get all the fixes, and avoid causing duplicate dependencies in projects.
In Cargo, different 0.x versions are considered incompatible, so this is a semver-major upgrade.
Dependency opentelemetry-otlp ^0.26 is significantly outdated
Upgrade to 0.32.0 to get all the fixes, and avoid causing duplicate dependencies in projects.
Dependency opentelemetry_sdk ^0.26 is significantly outdated
Upgrade to 0.32.1 to get all the fixes, and avoid causing duplicate dependencies in projects.
Dependency serde_yaml ^0.9 has issues
It may not be actively developed any more. Consider changing the dependency.
Dependency tracing-opentelemetry ^0.27 is significantly outdated
Upgrade to 0.33.0 to get all the fixes, and avoid causing duplicate dependencies in projects.
Imprecise dependency requirement anyhow = ^1
Cargo does not always pick latest versions of dependencies! Specify the version as
anyhow = "1.0.104". IfCargo.lockends up having an unexpectedly old version of the dependency, you might get a dependency that lacks features/APIs or important bugfixes that you depend on. This is most likely to happen when using theminimal-versionsflag, used by users of old Rust versions.This crate does not bump semver-minor when adding new features, so to be safe you get all the features/APIs/fixes that your crate depends on, require a more specific patch version.
Published crate doesn't match its repository
Verified 79 out of 80 files (includes 1 Cargo-generated).
- error: Manifest properties don't match: Number of [[bin]] inconsistent; published=2; orig=3; ed=Set(E2024).
Fetched
https://github.com/nfvelten/arbit.gittaggedarbit-0.18.0(753b0c2f4408eb9a879778ceae07d273a4a880d0).Checked on 2026-04-05
This check is experimental.
Dependency axum-server ^0.7 is outdated
Upgrade to 0.8.0 to get all the fixes, and avoid causing duplicate dependencies in projects.
Dependency base64 ^0.22 is a bit outdated
Consider upgrading to 0.23.1 to get all the fixes and improvements.
Dependency jsonschema ^0.18 is outdated
Upgrade to 0.49.8 to get all the fixes, and avoid causing duplicate dependencies in projects.
Dependency jsonwebtoken ^10 is outdated
Upgrade to 11.0.0 to get all the fixes, and avoid causing duplicate dependencies in projects.
Easy way to bump dependencies:
cargo install cargo-edit; cargo upgrade -i; Also check out Dependabot service on GitHub.Dependency lru ^0.16.3 is outdated
Upgrade to 0.18.2 to get all the fixes, and avoid causing duplicate dependencies in projects.
Dependency regorus ^0.2 is outdated
Upgrade to 0.11.0 to get all the fixes, and avoid causing duplicate dependencies in projects.
Dependency reqwest ^0.12 is outdated
Upgrade to 0.13.4 to get all the fixes, and avoid causing duplicate dependencies in projects.
Dependency rusqlite ^0.31 is outdated
Upgrade to 0.40.2 to get all the fixes, and avoid causing duplicate dependencies in projects.
Dependency sha2 ^0.10 is a bit outdated
Consider upgrading to 0.11.0 to get all the fixes and improvements.
Dependency which ^7 is outdated
Upgrade to 8.0.5 to get all the fixes, and avoid causing duplicate dependencies in projects.
Dependency x509-parser ^0.16 is outdated
Upgrade to 0.18.1 to get all the fixes, and avoid causing duplicate dependencies in projects.
mcp-shield
Dependency opentelemetry ^0.26 is significantly outdated
Upgrade to 0.32.0 to get all the fixes, and avoid causing duplicate dependencies in projects.
Dependency opentelemetry-otlp ^0.26 is significantly outdated
Upgrade to 0.32.0 to get all the fixes, and avoid causing duplicate dependencies in projects.
Dependency opentelemetry_sdk ^0.26 is significantly outdated
Upgrade to 0.32.1 to get all the fixes, and avoid causing duplicate dependencies in projects.
Dependency serde_yaml ^0.9 has issues
It may not be actively developed any more. Consider changing the dependency.
Dependency tracing-opentelemetry ^0.27 is significantly outdated
Upgrade to 0.33.0 to get all the fixes, and avoid causing duplicate dependencies in projects.
Imprecise dependency requirement anyhow = ^1
Cargo does not always pick latest versions of dependencies! Specify the version as
anyhow = "1.0.104". IfCargo.lockends up having an unexpectedly old version of the dependency, you might get a dependency that lacks features/APIs or important bugfixes that you depend on. This is most likely to happen when using theminimal-versionsflag, used by users of old Rust versions.Dependency axum-server ^0.7 is outdated
Upgrade to 0.8.0 to get all the fixes, and avoid causing duplicate dependencies in projects.
Dependency jsonwebtoken ^9 is outdated
Upgrade to 11.0.0 to get all the fixes, and avoid causing duplicate dependencies in projects.
Dependency prometheus ^0.13 is outdated
Consider upgrading to 0.14.0 to get all the fixes and improvements.
Dependency reqwest ^0.12 is outdated
Upgrade to 0.13.4 to get all the fixes, and avoid causing duplicate dependencies in projects.
Dependency rusqlite ^0.31 is outdated
Upgrade to 0.40.2 to get all the fixes, and avoid causing duplicate dependencies in projects.
arbitus
Dependency opentelemetry ^0.26 is significantly outdated
Upgrade to 0.32.0 to get all the fixes, and avoid causing duplicate dependencies in projects.
Dependency opentelemetry-otlp ^0.26 is significantly outdated
Upgrade to 0.32.0 to get all the fixes, and avoid causing duplicate dependencies in projects.
Dependency opentelemetry_sdk ^0.26 is significantly outdated
Upgrade to 0.32.1 to get all the fixes, and avoid causing duplicate dependencies in projects.
Dependency serde_yaml ^0.9 has issues
It may not be actively developed any more. Consider changing the dependency.
Dependency tracing-opentelemetry ^0.27 is significantly outdated
Upgrade to 0.33.0 to get all the fixes, and avoid causing duplicate dependencies in projects.
Imprecise dependency requirement anyhow = ^1
Cargo does not always pick latest versions of dependencies! Specify the version as
anyhow = "1.0.104". IfCargo.lockends up having an unexpectedly old version of the dependency, you might get a dependency that lacks features/APIs or important bugfixes that you depend on. This is most likely to happen when using theminimal-versionsflag, used by users of old Rust versions.Dependency axum-server ^0.7 is outdated
Upgrade to 0.8.0 to get all the fixes, and avoid causing duplicate dependencies in projects.
Dependency base64 ^0.22 is a bit outdated
Consider upgrading to 0.23.1 to get all the fixes and improvements.
Dependency jsonschema ^0.18 is outdated
Upgrade to 0.49.8 to get all the fixes, and avoid causing duplicate dependencies in projects.
Dependency jsonwebtoken ^10 is outdated
Upgrade to 11.0.0 to get all the fixes, and avoid causing duplicate dependencies in projects.
Dependency lru ^0.16.3 is outdated
Upgrade to 0.18.2 to get all the fixes, and avoid causing duplicate dependencies in projects.
Dependency regorus ^0.2 is outdated
Upgrade to 0.11.0 to get all the fixes, and avoid causing duplicate dependencies in projects.
Dependency reqwest ^0.12 is outdated
Upgrade to 0.13.4 to get all the fixes, and avoid causing duplicate dependencies in projects.
Dependency rusqlite ^0.31 is outdated
Upgrade to 0.40.2 to get all the fixes, and avoid causing duplicate dependencies in projects.
Dependency sha2 ^0.10 is a bit outdated
Consider upgrading to 0.11.0 to get all the fixes and improvements.
Dependency which ^7 is outdated
Upgrade to 8.0.5 to get all the fixes, and avoid causing duplicate dependencies in projects.
Dependency x509-parser ^0.16 is outdated
Upgrade to 0.18.1 to get all the fixes, and avoid causing duplicate dependencies in projects.
Failed to verify create's content against its repository
Verified 82 out of 90 files (includes 3 Cargo-generated).
- warning: Crate tarball has been published from the commit 1efdb2422671afc73d2e26925cfdf43fea93f895, which is not in the repository.
- Create git tags after comitting any changes, and commit changes after bumping versions and running
cargo update.
- Create git tags after comitting any changes, and commit changes after bumping versions and running
- warning: Crate tarball has been published from a different commit than the commit tagged by git tag 'v0.19.1'.
- error: Manifest properties don't match: Number of [[bin]] inconsistent; published=2; orig=3; ed=Set(E2024).
- warning: Cargo.toml.orig from crates.io is not an exact match with the repository.
Files in the crates.io crate compared to the repository:
Cargo.lockdoes not match the repository.Cargo.tomlexists, but elsewhere in the repo.Cargo.toml.origdoes not match the repository.config.rsdoes not match the repository.arbitus.rsdoes not match the repository.http.rsdoes not match the repository.tests/e2e.shdoes not match the repository.streamable_http.rsexists, but elsewhere in the repo.http_gateway.rsdoes not match the repository.
mod.rsdoes not match the repository.
Fetched
https://github.com/nfvelten/arbitus.gittaggedv0.19.1(89be649399f8ac1e56c0a6b68dfb100402738283).Checked on 2026-04-12
- warning: Crate tarball has been published from the commit 1efdb2422671afc73d2e26925cfdf43fea93f895, which is not in the repository.
If some of these crates are unmaintained and shouldn't be checked, yank them or add [badges.maintenance] to their
status = "deprecated"Cargo.toml.