rust-lang/cargo · error

all dependencies must have a version requirement specified…

Error message

all dependencies must have a version requirement specified when {}.
dependency `{}` does not specify a version
Note: The {} dependency will use the version from {},
the `{}` specification will be removed from the dependency declaration.

What it means

Thrown by `check_dep_has_version` during `cargo package` or `cargo publish` when a path or git dependency does not specify a version requirement (`specified_req()` is false) and the dependency is transitive (will be included in the published artifact). Path/git dependencies need a version field so that when the path/git source is stripped on publish, the registry version can fill in.

Solutions

  1. Add a `version` key to the dependency declaration in Cargo.toml.
  2. If the dependency is dev-only, move it under `[dev-dependencies]` so it is not transitive.
  3. If optional, mark it `optional = true` so it is not required for publish.

Example fix

# Cargo.toml (before)
[dependencies]
my-crate = { path = "../my-crate" }

# Cargo.toml (after)
[dependencies]
my-crate = { path = "../my-crate", version = "1.0" }
Defensive patterns

Strategy: validation

Validate before calling

fn check_path_git_deps_have_version(manifest: &toml::Value) -> Result<(), String> {
    let deps = manifest.get("dependencies").and_then(|d| d.as_table());
    if let Some(deps) = deps {
        for (name, val) in deps {
            if let Some(t) = val.as_table() {
                let has_path_or_git = t.contains_key("path") || t.contains_key("git");
                let has_version = t.contains_key("version");
                let optional = t.get("optional").and_then(|o| o.as_bool()).unwrap_or(false);
                if has_path_or_git && !has_version && !optional {
                    return Err(format!("dependency `{}` has path/git but no version requirement", name));
                }
            }
        }
    }
    Ok(())
}

Prevention

When it happens

Trigger: Running `cargo package` or `cargo publish` on a crate that has a `[dependencies]` entry with `path = "..."` or `git = "..."` but no `version = "..."` key, and that dependency is non-optional and non-dev-only (transitive).

Common situations: Workspace members referencing each other by path without a version; a git dependency declared without a version field; prototyping with path deps and forgetting to add versions before publishing.

Related errors


AI-assisted analysis of rust-lang/cargo@495c385d08 (2026-08-11). Data as JSON: /api/errors/5d7d07f7d7967ec3. Report an issue: GitHub.

Appendix: source

Thrown at src/ops/mod.rs:101

/// This check is performed on dependencies before publishing or packaging
fn check_dep_has_version(
    dep: &crate::workspace::Dependency,
    publish: bool,
) -> crate::CargoResult<bool> {
    let which = if dep.source_id().is_path() {
        "path"
    } else if dep.source_id().is_git() {
        "git"
    } else {
        return Ok(false);
    };

    if !dep.specified_req() && dep.is_transitive() {
        let dep_version_source = dep.registry_id().map_or_else(
            || CRATES_IO_DOMAIN.to_string(),
            |registry_id| registry_id.display_registry_name(),
        );
        anyhow::bail!(
            "all dependencies must have a version requirement specified when {}.\n\
             dependency `{}` does not specify a version\n\
             Note: The {} dependency will use the version from {},\n\
             the `{}` specification will be removed from the dependency declaration.",
            if publish { "publishing" } else { "packaging" },
            dep.package_name(),
            if publish { "published" } else { "packaged" },
            dep_version_source,
            which,
        )
    }
    Ok(true)
}

View on GitHub (pinned to 495c385d08)