Tool Open source

cargo-frisk

cargo-frisk is a Rust command-line tool that checks the files a Cargo package will ship. It builds the .crate archive, compares its contents with `git ls-files`, and reports files that are shipped but not tracked, files tracked but not shipped, and the expected shipped-and-tracked files. Cargo-generated files such as `Cargo.toml.orig`, `.cargo_vcs_info.json`, and `Cargo.lock` are listed separately.

View repository Mentioned in 1 video ↓

Overview

It scans packaged files for provider tokens, private keys, `.env` files, credentials files, editor backups, and other patterns adapted from gitleaks, with additional rules for Cargo packaging. Findings can be adjusted using severity thresholds, entropy checks, path-based severity reductions, inline suppressions, ignored paths, ignored rules, and per-file size limits. Binary or oversized files are reported as not scanned rather than silently skipped.

The tool is installed with `cargo install cargo-frisk` or `cargo binstall cargo-frisk`, then run with `cargo frisk` from a package. Its exit codes distinguish no findings, findings at or above the configured threshold, and tool errors such as a failed `cargo package` operation or malformed archive.

What cargo-frisk is used for

1 use taken from transcripts — each links to the moment in the video.

  • Checks what a Cargo package actually ships by comparing the built crate with Git-tracked files, then scans the packaged files for leaked secrets.

Videos mentioning cargo-frisk

1 in the library.