Rust

SlowShield serves crates.io at https://slowshield.example.com/cargo/ as a sparse registry that replaces crates-io in Cargo's configuration. Needs Cargo 1.68 or later.

Set it up

Cargo only takes source replacement from a configuration file, not from environment variables:

Cargo

Release age: Cargo's own setting (min-publish-age) isn't stable yet: SlowShield is the only layer.

~/.cargo/config.toml

[source.crates-io]
replace-with = "slowshield"

[registries.slowshield]
index = "sparse+https://slowshield.example.com/cargo/"

CI and Dockerfiles (appends to $CARGO_HOME/config.toml)

mkdir -p "${CARGO_HOME:-$HOME/.cargo}" && printf '%s\n' '[source.crates-io]' 'replace-with = "slowshield"' '[registries.slowshield]' 'index = "sparse+https://slowshield.example.com/cargo/"' >> "${CARGO_HOME:-$HOME/.cargo}/config.toml"

What changes

The second layer

Cargo's own setting, min-publish-age, isn't stable yet, so SlowShield is the only layer.

In Docker and CI

FROM rust:1 AS build
ARG CARGO_INDEX=sparse+https://slowshield.example.com/cargo/
RUN if [ -n "$CARGO_INDEX" ]; then printf '%s\n' '[source.crates-io]' 'replace-with = "slowshield"' \
      '[registries.slowshield]' "index = \"$CARGO_INDEX\"" >> "$CARGO_HOME/config.toml"; fi
WORKDIR /src
COPY . .
RUN cargo build --release

Or run the Setup page's one-line command in a RUN step. Building images covers the base image too, and how to check that nothing in a build goes around SlowShield.

Limits

For agents: this page as Markdown · llms.txt · the SlowShield skill