rust-lang/cargo · error · anyhow::Error
all versions of crate
Error message
all versions of crate `{dependency}` are too new per `min-publish-age` What it means
Thrown by get_latest_dependency() during cargo add when all published versions of the target crate are newer than the threshold set by the min-publish-age policy. This is a supply-chain security measure: freshly published crate versions are treated as potentially malicious until they have aged past the configured grace period. The error lists each too-new version and its violation reason.
Solutions
- Override the policy for this invocation: `CARGO_RESOLVER_INCOMPATIBLE_PUBLISH_AGE=allow cargo add foo`
- Wait until the crate version ages past the min-publish-age threshold
- Adjust the min-publish-age configuration in config.toml if the policy is too restrictive for your workflow
- Pin to a specific older version if one exists that predates the age window
Example fix
# before cargo add foo # error: all versions of crate `foo` are too new per `min-publish-age` # after — override for this invocation CARGO_RESOLVER_INCOMPATIBLE_PUBLISH_AGE=allow cargo add foo
Defensive patterns
Strategy: fallback
Validate before calling
// Check publish age policy before adding
fn check_publish_age(crate_name: &str) -> Result<(), String> {
// If min-publish-age is configured, warn the user
let policy = std::env::var("CARGO_RESOLVER_INCOMPATIBLE_PUBLISH_AGE").unwrap_or_default();
if policy != "allow" {
eprintln!("note: if all versions are too new, set CARGO_RESOLVER_INCOMPATIBLE_PUBLISH_AGE=allow");
}
Ok(())
} Try / catch
// Retry with publish age override on first failure
let result = std::process::Command::new("cargo")
.args(["add", crate_name]).status();
if result.is_err() || !result.unwrap().success() {
eprintln!("Retrying with CARGO_RESOLVER_INCOMPATIBLE_PUBLISH_AGE=allow...");
std::process::Command::new("cargo")
.env("CARGO_RESOLVER_INCOMPATIBLE_PUBLISH_AGE", "allow")
.args(["add", crate_name]).status()?;
} Prevention
- For brand-new crates, proactively set CARGO_RESOLVER_INCOMPATIBLE_PUBLISH_AGE=allow if you trust the publisher
- Understand the min-publish-age default and adjust it in config.toml if your workflow requires fresh crates
- Pin to a specific older version of the crate if one exists outside the age window
- Review the error output for the help line suggesting the override env var
When it happens
Trigger: Running `cargo add foo` where every version of crate 'foo' in the registry index was published within the min-publish-age window (default is typically a few days), so all candidates are filtered out by PublishAgePolicy::too_new().
Common situations: Adding a crate that was just published minutes or hours ago. A security policy with a conservative min-publish-age. A crate whose entire history falls within the age window (very new crates).
Related errors
- invalid tarball downloaded, contains a file at
- invalid tarball downloaded, contains an entry at
- cache expected 4 bytes for index schema version
- cannot add ` ` as a dependency to itself
- cannot override workspace dependency with
AI-assisted analysis of rust-lang/cargo@98a09e7e7d (2026-08-11).
Data as JSON: /api/errors/fb3cda3ad4cf8426.
Report an issue: GitHub.
Appendix: source
Thrown at src/ops/cargo_add/mod.rs:895
false
}
None => true,
});
if possibilities.is_empty() && has_candidates {
too_new.sort_by(|(a, _), (b, _)| a.cmp(b));
let mut msg = format!(
"all versions of crate `{dependency}` are too new per `min-publish-age`"
);
for (version, violation) in &too_new {
let note = violation.note();
let _ = write!(&mut msg, "\n version {version} is too new ({note})",);
}
let _ = write!(
&mut msg,
"\nhelp: to add the latest version anyways, \
re-run with `CARGO_RESOLVER_INCOMPATIBLE_PUBLISH_AGE=allow`"
);
anyhow::bail!(msg);
}
}
possibilities.sort_by_key(|s| {
// Fallback to a pre-release if no official release is available by sorting them as
// less.
let stable = s.version().pre.is_empty();
(stable, s.version().clone())
});
let mut latest = possibilities.last().ok_or_else(|| {
anyhow::format_err!(
"the crate `{dependency}` could not be found in registry index."
)
})?;
if honor_rust_version.unwrap_or(true) {
let (req_msrv, is_msrv) = specView on GitHub (pinned to 98a09e7e7d)