# Suggestion: cargo yank is a misfeature and should be deprecated and eventually removed

**URL:** <https://internals.rust-lang.org/t/suggestion-cargo-yank-is-a-misfeature-and-should-be-deprecated-and-eventually-removed/18486>\
**Category:** cargo\
**Created:** [March 7, 2023, 4:55am UTC](https://internals.rust-lang.org/t/suggestion-cargo-yank-is-a-misfeature-and-should-be-deprecated-and-eventually-removed/18486 "2023-03-07T04:55:03Z")\
**Posts on this page:** 1\
**Showing post:** 15

<div class="post-metadata">

**Author:** ![epage](https://sea2.discourse-cdn.com/flex002/user_avatar/internals.rust-lang.org/epage/32/3171_2.png) [@epage](https://internals.rust-lang.org/u/epage)\
**Post date:** [March 8, 2023, 1:19am UTC](https://internals.rust-lang.org/t/suggestion-cargo-yank-is-a-misfeature-and-should-be-deprecated-and-eventually-removed/18486/15 "2023-03-08T01:19:03Z")

</div>

> [@kornel](#):
>
> releases with known vulnerabilities

imo they have to be pretty severe to justify being yanked. Vulnerabilities are not one-size-fits-all bad. For example, the regex vulnerability doesn't matter if I'm using it within my tests. Other vulnerabilities might be in a part of the crate I'm not using (I wish `cargo audit` could report only for whats in use). Let `cargo audit` and `cargo deny` deal with reporting vulnerabilities. Let's improve their integration into users workflows.

> [@kornel](#):
>
> The idea is that you have `Cargo.lock` versioned in your repository, so when you bisect, you get all the exact dependencies as they existed at the time of the commit. Otherwise you have no reproducibility guarantees even without yanking, because Cargo picks latest dependencies, and _not_ the versions in `Cargo.toml` (i.e. `dep = "1.2.3"` doesn't use v1.2.3, but v1.999.999 if there is such version).

As was mentioned, the official docs and `cargo new` discourage committing `Cargo.lock` for libraries. So long as a semver-compatible upgrade is available, it at least shouldn't break people without a `Cargo.lock`. I do wonder if we should change this recommendation though to make life easier for `git bisect` and other workflows.

---

_[View the full topic](https://internals.rust-lang.org/t/suggestion-cargo-yank-is-a-misfeature-and-should-be-deprecated-and-eventually-removed/18486)._
