Cargo and crates.io: the daily workflow
Everything up to now used only the standard library, so every example could be compiled and checked. Real Rust projects lean on crates, the packages published on crates.io. The code in this module is static (it needs crates and running services), so treat each lab as a recipe to try in your own Cargo project. The standard library is deliberately small: async runtimes, HTTP, JSON, database drivers and random numbers all live in crates.
Start a project the way teams do
cargo new creates Cargo.toml, src/main.rs, a .gitignore that excludes target/, and initialises a Git repository. cargo add edits Cargo.toml for you and picks the latest compatible version. The first build writes Cargo.lock, the exact version of every dependency. Commit it: for applications it guarantees that CI, your teammates and production build the same code.cargo new todo-api # Cargo.toml, src/main.rs, .gitignore, git init
cd todo-api
cargo add tokio --features full
cargo add axum
cargo add serde --features derive
cargo add serde_json
cargo build # downloads crates, writes Cargo.lock
git add . && git commit -m "Scaffold todo-api"
cargo tree -d # dependencies pulled in at two versions
cargo update -p serde # bump one crate within its semver range
cargo check # fast type-check, no binary
cargo build --release # optimised binary in target/release/[package]
name = "todo-api"
version = "0.1.0"
edition = "2021"
[dependencies]
axum = "0.8"
serde = { version = "1", features = ["derive"] }
serde_json = "1"
tokio = { version = "1", features = ["full"] }
[dev-dependencies]
# only compiled for tests and examples
[profile.release]
lto = true # link-time optimisation: smaller, faster binary
codegen-units = 1
strip = true # drop debug symbols from the release binary"1" means "any 1.x at or above 1.0.0" (semver caret rule). Features switch on optional parts of a crate, so you only compile what you use.
description, license and repository to [package], run cargo publish --dry-run, then cargo publish with a token from crates.io. Published versions are permanent; cargo yank only stops new projects from picking a broken version. Workspaces ([workspace] members = [...]) keep several crates in one repository with a shared Cargo.lock.