Build scripts stay in their sandbox.
With build.sandbox = true, build scripts and proc-macros run with no network and nothing writable outside the build. A script that reaches for ~/.bashrc or phones home fails instead — at no measurable cost.
rune config set build.sandbox true --global # every project on this machineRUNE_BUILD_SANDBOX=1 rune build # or for one run
Code that runs at build time, confined.
Every build script and compiler — and with it every proc-macro — gets no network and a read-only file system, except the build's own output and a private temporary directory.
Linux and macOS
Unprivileged user, mount and network namespaces on Linux (on Ubuntu 23.10+ AppArmor may have to allow them); sandbox-exec on macOS.
Network, where it is needed
build.sandbox-network = "openssl-src, foo" lets the build scripts of those packages download what they must.
Nothing to pay
A full sandboxed rebuild of Rune's own 194 units — ring, zstd-sys, proc-macros — takes as long as an unconfined one.
Advisories, with the path and the fix.
Every locked crates.io package against RustSec as OSV publishes it — plus GitHub's and OSV's reports, malicious releases among them. Vulnerabilities fail the command; the database is cached, so an audit also works offline and takes about 0.1 s.
▸ checked 236 packages against 1875 advisories✗ smallvec 1.6.0 · RUSTSEC-2021-0003 · critical 9.8 Buffer overflow in SmallVec::insert_many fix >=1.6.1 — rune update smallvec --precise 1.6.1 path app 0.1.0 → middle 1.0.0 → smallvec 1.6.0! bincode 1.3.3 · RUSTSEC-2025-0141 · unmaintained✗ 1 vulnerability found · 1 warning
--deny warnings fails on unmaintained, unsound and yanked crates too; audit.ignore accepts a reviewed advisory; --format json follows cargo-audit's shape.
Everything that runs, accounted for.
What the workspace ships, what runs code while it builds, and how new a release must be before it gets in.
rune sbom
A CycloneDX 1.5 or SPDX 2.3 bill of materials with package URLs, checksums, licences and the locked dependency edges; SOURCE_DATE_EPOCH makes it reproducible.
rune tree --exec-surface
Every crate that runs code on your machine while building — build scripts, proc-macros, native links crates — with the chain that brings each in.
resolve.min-release-age
"14d" keeps resolution away from releases younger than that. Malicious releases are usually yanked within days; locked versions stay as they are.
Conflicts, explained
Resolution takes the newest release each requirement allows and solves the rare hard case with PubGrub — and when no choice exists, it says why, step by step.
Dependencies, kept tidy.
rune unused runs rustc's own unused-dependency lint over every target — no text search, so proc-macros, renamed crates and build-dependencies are judged correctly — and suggests moving what only tests use to [dev-dependencies].
rune outdated # newer releases, compatible and newest overallrune upgrade # raise requirements, keeping comments and stylerune unused --fix # remove what the compiler says is unusedrune why serde # who depends on it, and why
Try it on your project.
Nothing to migrate and nothing to undo: your project keeps working with plain cargo.
$ curl -fsSL https://www.runepm.com/install.sh | sh