Tool Open source
cargo-frisk is a Rust command-line tool that checks the files a Cargo package will ship. It builds the .crate archive, compares its contents with `git ls-files`, and reports files that are shipped but not tracked, files tracked but not shipped, and the expected shipped-and-tracked files. Cargo-generated files such as `Cargo.toml.orig`, `.cargo_vcs_info.json`, and `Cargo.lock` are listed separately.
It scans packaged files for provider tokens, private keys, `.env` files, credentials files, editor backups, and other patterns adapted from gitleaks, with additional rules for Cargo packaging. Findings can be adjusted using severity thresholds, entropy checks, path-based severity reductions, inline suppressions, ignored paths, ignored rules, and per-file size limits. Binary or oversized files are reported as not scanned rather than silently skipped.
The tool is installed with `cargo install cargo-frisk` or `cargo binstall cargo-frisk`, then run with `cargo frisk` from a package. Its exit codes distinguish no findings, findings at or above the configured threshold, and tool errors such as a failed `cargo package` operation or malformed archive.
1 use taken from transcripts — each links to the moment in the video.
Checks what a Cargo package actually ships by comparing the built crate with Git-tracked files, then scans the packaged files for leaked secrets.
1 in the library.