rust-lang/cargo · error · anyhow::Error

all versions of crate

Error message

all versions of crate `{dependency}` are too new per `min-publish-age`

What it means

Thrown by get_latest_dependency() during cargo add when all published versions of the target crate are newer than the threshold set by the min-publish-age policy. This is a supply-chain security measure: freshly published crate versions are treated as potentially malicious until they have aged past the configured grace period. The error lists each too-new version and its violation reason.

Solutions

  1. Override the policy for this invocation: `CARGO_RESOLVER_INCOMPATIBLE_PUBLISH_AGE=allow cargo add foo`
  2. Wait until the crate version ages past the min-publish-age threshold
  3. Adjust the min-publish-age configuration in config.toml if the policy is too restrictive for your workflow
  4. Pin to a specific older version if one exists that predates the age window

Example fix

# before
cargo add foo
# error: all versions of crate `foo` are too new per `min-publish-age`

# after — override for this invocation
CARGO_RESOLVER_INCOMPATIBLE_PUBLISH_AGE=allow cargo add foo
Defensive patterns

Strategy: fallback

Validate before calling

// Check publish age policy before adding
fn check_publish_age(crate_name: &str) -> Result<(), String> {
    // If min-publish-age is configured, warn the user
    let policy = std::env::var("CARGO_RESOLVER_INCOMPATIBLE_PUBLISH_AGE").unwrap_or_default();
    if policy != "allow" {
        eprintln!("note: if all versions are too new, set CARGO_RESOLVER_INCOMPATIBLE_PUBLISH_AGE=allow");
    }
    Ok(())
}

Try / catch

// Retry with publish age override on first failure
let result = std::process::Command::new("cargo")
    .args(["add", crate_name]).status();
if result.is_err() || !result.unwrap().success() {
    eprintln!("Retrying with CARGO_RESOLVER_INCOMPATIBLE_PUBLISH_AGE=allow...");
    std::process::Command::new("cargo")
        .env("CARGO_RESOLVER_INCOMPATIBLE_PUBLISH_AGE", "allow")
        .args(["add", crate_name]).status()?;
}

Prevention

When it happens

Trigger: Running `cargo add foo` where every version of crate 'foo' in the registry index was published within the min-publish-age window (default is typically a few days), so all candidates are filtered out by PublishAgePolicy::too_new().

Common situations: Adding a crate that was just published minutes or hours ago. A security policy with a conservative min-publish-age. A crate whose entire history falls within the age window (very new crates).

Related errors


AI-assisted analysis of rust-lang/cargo@98a09e7e7d (2026-08-11). Data as JSON: /api/errors/fb3cda3ad4cf8426. Report an issue: GitHub.

Appendix: source

Thrown at src/ops/cargo_add/mod.rs:895

                        false
                    }
                    None => true,
                });
                if possibilities.is_empty() && has_candidates {
                    too_new.sort_by(|(a, _), (b, _)| a.cmp(b));
                    let mut msg = format!(
                        "all versions of crate `{dependency}` are too new per `min-publish-age`"
                    );
                    for (version, violation) in &too_new {
                        let note = violation.note();
                        let _ = write!(&mut msg, "\n  version {version} is too new ({note})",);
                    }
                    let _ = write!(
                        &mut msg,
                        "\nhelp: to add the latest version anyways, \
                         re-run with `CARGO_RESOLVER_INCOMPATIBLE_PUBLISH_AGE=allow`"
                    );
                    anyhow::bail!(msg);
                }
            }

            possibilities.sort_by_key(|s| {
                // Fallback to a pre-release if no official release is available by sorting them as
                // less.
                let stable = s.version().pre.is_empty();
                (stable, s.version().clone())
            });

            let mut latest = possibilities.last().ok_or_else(|| {
                anyhow::format_err!(
                    "the crate `{dependency}` could not be found in registry index."
                )
            })?;

            if honor_rust_version.unwrap_or(true) {
                let (req_msrv, is_msrv) = spec

View on GitHub (pinned to 98a09e7e7d)