Skip to content

Boshen/cargo-shear

Repository files navigation

Cargo Shear ✂️ 🐑

Detect and fix issues in Rust projects:

  • Unused dependencies in Cargo.toml
  • Misplaced dependencies (dev/build dependencies in wrong sections)
  • Unlinked source files (Rust files not reachable from any module tree)

Installation

# Install from pre-built binaries.
cargo binstall cargo-shear

# Build from source.
cargo install cargo-shear

# Install from brew.
brew install cargo-shear

Usage

Check for issues without making changes:

cargo shear

Automatically fix unused dependencies:

cargo shear --fix

Generate machine-readable JSON output:

cargo shear --format=json

This is particularly useful for CI/CD pipelines and custom tooling that need to programmatically process the results.

Limitations

Important

cargo shear cannot detect "hidden" imports from macro expansions without the --expand flag (nightly only). This is because cargo shear uses rust-analyzer's parser to parse files and does not expand macros by default.

To expand macros:

cargo shear --expand --fix

The --expand flag uses cargo expand, which requires nightly and is significantly slower.

Important

Misplaced dependency detection only works for integration tests, benchmarks, and examples. Unit tests dependencies within #[cfg(test)] cannot be detected as misplaced.

Configuration

Ignore false positives

False positives can be ignored by adding them to the package's Cargo.toml:

[package.metadata.cargo-shear]
ignored = ["crate-name"]

Ignore unlinked files

Unlinked files can be ignored using glob patterns:

[package.metadata.cargo-shear]
ignored-paths = ["src/proto/*.rs", "examples/old/*"]

Both options work in workspace Cargo.toml as well:

[workspace.metadata.cargo-shear]
ignored = ["crate-name"]
ignored-paths = ["*/proto/*.rs"]

Otherwise please report the issue as a bug.

CI

- name: Install cargo-binstall
  uses: cargo-bins/cargo-binstall@main

- name: Install cargo-shear
  run: cargo binstall --no-confirm cargo-shear

- run: cargo shear

JSON Output for CI Integration

For CI systems that require structured output, use the --format=json flag:

- name: Check for unused dependencies
  run: cargo shear --format=json > shear-results.json

The JSON output includes:

  • summary: Counts of errors, warnings, and fixes
  • findings: Detailed information about each issue including:
    • code: The diagnostic code (e.g., shear/unused_dependency)
    • severity: Error or warning level
    • message: Human-readable description
    • file: Path to the file with the issue
    • location: Byte offset and length within the file
    • help: Suggested fix
    • fixable: Boolean indicating if issue can be auto-fixed with --fix

Exit Code (for CI)

Exit Code Without --fix With --fix
0 No issues found No issues found, no changes made
1 Issues found Issues found and fixed
2 Error during processing Error during processing

GitHub Actions Example:

- name: cargo-shear
  shell: bash
  run: |
    if ! cargo shear --fix; then
      cargo check
    fi

Technique

  1. Use the cargo_metadata crate to list all dependencies specified in [workspace.dependencies] and [dependencies]
  2. Iterate through all package targets (lib, bin, example, test and bench) to locate all Rust files
  3. Use rust-analyzer's parser (ra_ap_syntax) to parse these Rust files and extract imports
    • Alternatively, use the --expand option with cargo expand to first expand macros and then parse the expanded code (though this is significantly slower)
  4. Find the difference between the imports and the package dependencies

Prior Art

  • est31/cargo-udeps
    • it collects dependency usage by compiling your project and find them from the target/ directory
    • does not seem to work anymore with the latest versions of cargo
    • does not work with cargo workspaces
  • bnjbvr/cargo-machete
    • it collects dependency usage by running regex patterns on source code
    • does not detect all usages of a dependency
    • does not remove unused dependencies from the workspace root
  • cargo and clippy

Trophy Cases

My sponsors

About

Remove unused dependencies in a Rust project

Resources

License

Stars

Watchers

Forks

Sponsor this project

 

Contributors 19