Skip to content

Guardrails / Collectors

Rust build ​

The Cargo build in the project directory: the crate it declares, the Rust version and edition it asks for, every workspace member, the dependencies each manifest names with where each comes from and whether it is pinned, and the lock file beside them.

Facts keyrust
Versionv1
Scriptrust.py
Timeout30 seconds

Inputs ​

InputDescriptionDefaultEnvironment
projectDirDirectory holding the project, relative to the directory the CLI runs in..GUARDRAIL_INPUT_PROJECTDIR
maxMembersMaximum number of workspace members to describe. A larger workspace carries the ones its globs resolve first.200GUARDRAIL_INPUT_MAXMEMBERS

When a guardrail declares an input with the same name, it passes its value through. That means you set these values in the guardrail's configuration in buildnote.json.

A guardrail asks for these facts by name and reads them back by the same name:

json
{
  "collect": ["rust"]
}
python
rust = guardrail.facts("rust")

Facts ​

These are the fields of the document rust collects. In a path, [] means each entry of the list before it, and [path] means a key of the object before it.

FactMeaning
directoryThe project directory set by the guardrail's projectDir input, relative to the directory the CLI runs in. Every other path this collector reports is also relative to the directory the CLI runs in, so it resolves from where you invoked the CLI, not from wherever the collector happened to run.
existsWhether that directory exists. When it doesn't, nothing else is collected.
manifestPath of the primary manifest, from the directory the CLI runs in, always Cargo.toml.
sourcesEvery manifest that was read and understood, in the order they were read. A manifest the reader could not handle is in unparsed instead.
declaredThe Rust version the build asks for, or null when it asks for none. rust-toolchain.toml wins over rust-version, because it is what cargo installs, while rust-version is only the minimum the crate compiles with. A rust-version under [workspace.package] is read as the whole workspace's, which is what a member inheriting it with rust-version.workspace = true compiles at.
declared.versionChannel or version exactly as written, such as 1.76, stable or nightly-2026-03-01.
declared.sourceFile declaring it, from the directory the CLI runs in.
declared.pinnedWhether it names one exact version rather than a moving channel. stable, beta and nightly are not pinned; 1.76.0 is.
editionThe Rust edition the package declares, such as 2021, or null when it declares none and 2015 is implied. Taken from the root [package], then from [workspace.package] where the workspace declares one for its members to inherit, then from the first member declaring one of its own.
workspaceWhether the manifest declares a [workspace], so a guardrail can tell a single crate from the root of several.
projectsEvery crate in the build: the root package when it is one, followed by every workspace member.
projects[].pathDirectory of the crate, from the directory the CLI runs in; directory itself for the project directory.
projects[].manifestThat crate's Cargo.toml, from the directory the CLI runs in.
projects[].nameName the [package] table declares, or null when it declares none.
dependenciesWhat the manifests declare, split by whether the build asks for it itself.
dependencies.directEvery dependency any manifest declares, in manifest order.
dependencies.direct[].nameCrate name as the manifest keys it. A renamed dependency is keyed by the name the code uses rather than the one it is published under.
dependencies.direct[].versionRequirement exactly as written, such as 1.0.197 or =1.0.197, or null when the dependency comes from a path, a git URL or the workspace.
dependencies.direct[].scopesWhich of dependencies, dev-dependencies, build-dependencies and workspace declare it.
dependencies.direct[].sourceManifest declaring it, from the directory the CLI runs in.
dependencies.direct[].pinnedWhether the requirement names one exact version. A bare 1.0 is Cargo's caret requirement and matches any compatible release, so only an = requirement is pinned.
dependencies.direct[].originWhere it comes from: registry, path for a crate in this checkout, git for one fetched from a URL, or workspace when the member inherits the root's.
dependencies.transitiveAlways empty. What Cargo.lock resolves is not read: lockfiles says whether one is committed.
lockfilesEvery lock file committed, from the directory the CLI runs in. A library that commits one pins its own build without constraining anything that depends on it.
droppedWorkspace members left out because maxMembers was reached. Above zero, projects and dependencies describe only part of the build.
unparsedEvery manifest the reader could not handle, so a guardrail can tell a build that declares nothing apart from one that could not be read.
unparsed[].pathPath of that manifest, from the directory the CLI runs in.
unparsed[].reasonWhy the reader could not handle it.

If a collector can't finish, it prints what it gathered so far along with an incomplete key that says why. Facts after the point where it stopped are missing, so a check that depends on them should read incomplete first.

Example facts ​

Here are the facts the rust collector gathers from an example project:

json
{
  "directory": ".",
  "exists": true,
  "manifest": "Cargo.toml",
  "sources": [
    "Cargo.toml"
  ],
  "declared": {
    "version": "1.76",
    "source": "Cargo.toml",
    "pinned": true
  },
  "edition": "2021",
  "workspace": false,
  "projects": [
    {
      "path": ".",
      "manifest": "Cargo.toml",
      "name": "widget"
    }
  ],
  "dependencies": {
    "direct": [
      {
        "name": "serde",
        "version": "1.0.197",
        "scopes": [
          "dependencies"
        ],
        "source": "Cargo.toml",
        "pinned": false,
        "origin": "registry"
      },
      {
        "name": "anyhow",
        "version": "1.0.81",
        "scopes": [
          "dependencies"
        ],
        "source": "Cargo.toml",
        "pinned": false,
        "origin": "registry"
      },
      {
        "name": "clap",
        "version": "=4.5.4",
        "scopes": [
          "dependencies"
        ],
        "source": "Cargo.toml",
        "pinned": true,
        "origin": "registry"
      },
      {
        "name": "queue",
        "version": null,
        "scopes": [
          "dependencies"
        ],
        "source": "Cargo.toml",
        "pinned": false,
        "origin": "path"
      },
      {
        "name": "proptest",
        "version": "1.4.0",
        "scopes": [
          "dev-dependencies"
        ],
        "source": "Cargo.toml",
        "pinned": false,
        "origin": "registry"
      },
      {
        "name": "cc",
        "version": "1.0.94",
        "scopes": [
          "build-dependencies"
        ],
        "source": "Cargo.toml",
        "pinned": false,
        "origin": "registry"
      }
    ],
    "transitive": []
  },
  "lockfiles": [
    "Cargo.lock"
  ],
  "dropped": 0,
  "unparsed": []
}

Collected for ​

GuardrailCategoryInputs
rust/edition-floorrustprojectDir
rust/lockfile-committedrustprojectDir
rust/no-git-dependenciesrustprojectDir
rust/version-declaredrustprojectDir

All collectors

Buildnote Limited
Registered in England and Wales, Reg: 16140412