{"record":{"id":"fb3cda3ad4cf8426","repo":"rust-lang/cargo","slug":"all-versions-of-crate-dependency-are-too-new-p","errorCode":null,"errorMessage":"all versions of crate `{dependency}` are too new per `min-publish-age`","messagePattern":"all versions of crate `(.+?)` are too new per `min-publish-age`","errorType":"exception","errorClass":"anyhow::Error","httpStatus":null,"severity":"error","filePath":"src/ops/cargo_add/mod.rs","lineNumber":895,"sourceCode":"                        false\n                    }\n                    None => true,\n                });\n                if possibilities.is_empty() && has_candidates {\n                    too_new.sort_by(|(a, _), (b, _)| a.cmp(b));\n                    let mut msg = format!(\n                        \"all versions of crate `{dependency}` are too new per `min-publish-age`\"\n                    );\n                    for (version, violation) in &too_new {\n                        let note = violation.note();\n                        let _ = write!(&mut msg, \"\\n  version {version} is too new ({note})\",);\n                    }\n                    let _ = write!(\n                        &mut msg,\n                        \"\\nhelp: to add the latest version anyways, \\\n                         re-run with `CARGO_RESOLVER_INCOMPATIBLE_PUBLISH_AGE=allow`\"\n                    );\n                    anyhow::bail!(msg);\n                }\n            }\n\n            possibilities.sort_by_key(|s| {\n                // Fallback to a pre-release if no official release is available by sorting them as\n                // less.\n                let stable = s.version().pre.is_empty();\n                (stable, s.version().clone())\n            });\n\n            let mut latest = possibilities.last().ok_or_else(|| {\n                anyhow::format_err!(\n                    \"the crate `{dependency}` could not be found in registry index.\"\n                )\n            })?;\n\n            if honor_rust_version.unwrap_or(true) {\n                let (req_msrv, is_msrv) = spec","sourceCodeStart":877,"sourceCodeEnd":913,"githubUrl":"https://github.com/rust-lang/cargo/blob/98a09e7e7d62850f14e5b6132101fc1edd19a16f/src/ops/cargo_add/mod.rs#L877-L913","documentation":"Thrown by get_latest_dependency() during cargo add when all published versions of the target crate are newer than the threshold set by the min-publish-age policy. This is a supply-chain security measure: freshly published crate versions are treated as potentially malicious until they have aged past the configured grace period. The error lists each too-new version and its violation reason.","triggerScenarios":"Running `cargo add foo` where every version of crate 'foo' in the registry index was published within the min-publish-age window (default is typically a few days), so all candidates are filtered out by PublishAgePolicy::too_new().","commonSituations":"Adding a crate that was just published minutes or hours ago. A security policy with a conservative min-publish-age. A crate whose entire history falls within the age window (very new crates).","solutions":["Override the policy for this invocation: `CARGO_RESOLVER_INCOMPATIBLE_PUBLISH_AGE=allow cargo add foo`","Wait until the crate version ages past the min-publish-age threshold","Adjust the min-publish-age configuration in config.toml if the policy is too restrictive for your workflow","Pin to a specific older version if one exists that predates the age window"],"exampleFix":"# before\ncargo add foo\n# error: all versions of crate `foo` are too new per `min-publish-age`\n\n# after — override for this invocation\nCARGO_RESOLVER_INCOMPATIBLE_PUBLISH_AGE=allow cargo add foo","handlingStrategy":"fallback","validationCode":"// Check publish age policy before adding\nfn check_publish_age(crate_name: &str) -> Result<(), String> {\n    // If min-publish-age is configured, warn the user\n    let policy = std::env::var(\"CARGO_RESOLVER_INCOMPATIBLE_PUBLISH_AGE\").unwrap_or_default();\n    if policy != \"allow\" {\n        eprintln!(\"note: if all versions are too new, set CARGO_RESOLVER_INCOMPATIBLE_PUBLISH_AGE=allow\");\n    }\n    Ok(())\n}","typeGuard":null,"tryCatchPattern":"// Retry with publish age override on first failure\nlet result = std::process::Command::new(\"cargo\")\n    .args([\"add\", crate_name]).status();\nif result.is_err() || !result.unwrap().success() {\n    eprintln!(\"Retrying with CARGO_RESOLVER_INCOMPATIBLE_PUBLISH_AGE=allow...\");\n    std::process::Command::new(\"cargo\")\n        .env(\"CARGO_RESOLVER_INCOMPATIBLE_PUBLISH_AGE\", \"allow\")\n        .args([\"add\", crate_name]).status()?;\n}","preventionTips":["For brand-new crates, proactively set CARGO_RESOLVER_INCOMPATIBLE_PUBLISH_AGE=allow if you trust the publisher","Understand the min-publish-age default and adjust it in config.toml if your workflow requires fresh crates","Pin to a specific older version of the crate if one exists outside the age window","Review the error output for the help line suggesting the override env var"],"tags":["cargo-add","security","publish-age","registry","supply-chain"],"backgroundTag":null,"analyzedSha":"98a09e7e7d62850f14e5b6132101fc1edd19a16f","analyzedAt":"2026-08-11T17:42:36.556Z","contentChangedAt":"2026-08-11T17:42:36.556Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}