# \`cargo search\` returns prerelease versions

**URL:** <https://internals.rust-lang.org/t/cargo-search-returns-prerelease-versions/21649>\
**Category:** cargo\
**Created:** [October 4, 2024, 10:07am UTC](https://internals.rust-lang.org/t/cargo-search-returns-prerelease-versions/21649 "2024-10-04T10:07:06Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Trem](https://avatars.discourse-cdn.com/v4/letter/t/eb8c5e/32.png) [@Trem](https://internals.rust-lang.org/u/Trem)\
**Post date:** [October 4, 2024, 10:07am UTC](https://internals.rust-lang.org/t/cargo-search-returns-prerelease-versions/21649/1 "2024-10-04T10:07:06Z")

</div>

The output of `cargo search` currently returns prerelease versions, for example:

```rust
$ cargo search rand
rand = "0.9.0-alpha.2" # Random number generators and other randomness functionality. 
...

```

On the other hand, [crates.io](https://crates.io/crates/rand) shows `0.8.5` as the current version, since that's the latest stable release.

This does not seem like it should be the default behavior of `cargo search`.

* * *

I've looked into what would be required to change this:

- The registry API does return a field `max_stable_version`, which could be used. For some reason, it is [not documented](https://doc.rust-lang.org/nightly/cargo/reference/registry-web-api.html#search), but gets returned e.g. with:

- In their simplest form, the code changes required affect just two lines of production code, which need to be changed from `max_version` to `max_stable_version`, and a couple unit tests that need to be adjusted accordingly.

- Theoretically, someone might depend on prerelease versions being returned by `cargo search`, so maybe should be mentioned in the changelog.

Thoughts on this?  
I might be able to contribute a PR.

---

<div class="post-metadata">

**Author:** ![epage](https://sea2.discourse-cdn.com/flex002/user_avatar/internals.rust-lang.org/epage/32/3171_2.png) [@epage](https://internals.rust-lang.org/u/epage)\
**Post date:** [October 4, 2024, 2:40pm UTC](https://internals.rust-lang.org/t/cargo-search-returns-prerelease-versions/21649/2 "2024-10-04T14:40:51Z")

</div>

> [@Trem](#):
>
> The registry API does return a field `max_stable_version`, which could be used. For some reason, it is [not documented](https://doc.rust-lang.org/nightly/cargo/reference/registry-web-api.html#search), but gets returned e.g. with:

There is a difference between the official registry API specification and what extensions registries, like [crates.io](http://crates.io), make. So this isn't just a two line change but Cargo adding more requirements to what a registry is expected to do. There are things to do, like considering the field to be optional, but I hope its clear this is more than just a two line change.

---

<div class="post-metadata">

**Author:** ![Trem](https://avatars.discourse-cdn.com/v4/letter/t/eb8c5e/32.png) [@Trem](https://internals.rust-lang.org/u/Trem)\
**Post date:** [October 5, 2024, 3:57pm UTC](https://internals.rust-lang.org/t/cargo-search-returns-prerelease-versions/21649/3 "2024-10-05T15:57:07Z")

</div>

Makes sense. I've done a bit of brainstorming for alternative solutions:

1. Make `max_stable_version` an optional field in the registry API, falling back to `max_version` otherwise.

2. Introduce (or wait for) a v2 of the registry API.

3. Change API of [crates.io](http://crates.io) by populating `max_version` with the latest stable version instead.

4. Make use of the registry index, like `cargo add` does.

---

<div class="post-metadata">

**Author:** ![steffahn](https://sea2.discourse-cdn.com/flex002/user_avatar/internals.rust-lang.org/steffahn/32/13288_2.png) [@steffahn](https://internals.rust-lang.org/u/steffahn)\
**Post date:** [March 29, 2026, 3:57pm UTC](https://internals.rust-lang.org/t/cargo-search-returns-prerelease-versions/21649/4 "2026-03-29T15:57:49Z")

</div>

This topic was automatically closed 540 days after the last reply. New replies are no longer allowed.
