Dependency health Workspace

arrayrefcrates.io

Documented supply-chain history

This package has dated incident reports relevant to its trust history. Check the affected releases and the response before drawing conclusions about its current version.

Read the incident coverage →

Supply-chain news and reputation

Dated reporting about this package. These events are separate from its current maintenance score.

All supply-chain news →
What the project says about itself
  • OpenSSF Scorecard3.2 / 10 on 2026-08-17. Source: OpenSSF, via deps.dev. A third party's view of security practice, not part of the health score.

Third-party facts checked today; registry facts on every crawl.

State history 1
WhenChange
2026-09-05 first verdict: drifting
Supply-chain history 1
  1. account hijacked 2026-08 0.3.10

    A compromised maintainer account republished all three with a dependency on a look-alike proc-macro crate whose build script ran a payload at compile time, and yanked the older arrayref releases so Cargo would prefer the malicious one.

    Deleted from crates.io within two hours, the yanked versions restored, the account locked.

    Source: Rust blog post-mortem by the Security Response Team, 20 August 2026. History, not a warning about today — the verdict above is about maintenance now.

Badge

maintenance: drifting

Drop this in your README. It re-renders itself as the verdict changes.

[![maintenance](https://isitdeadyet.dev/badge/crates/arrayref.svg)](https://isitdeadyet.dev/crates/arrayref)

Watch it

Get told when arrayref changes state, changes licence, or is deprecated — instead of finding out during an incident.

Free for up to 25 packages. Signing in is a link sent to your email — there is no password to choose.