Rust's Cargo

Cargo 6,602 (github.com/rust-lang/cargo (https://github.com/rust-lang/cargo 15,526 ), MIT or Apache-2.0) is Rust's build tool and package manager in one, installed with the toolchain by rustup (Cargo 1.98.1 here). Its registry is crates.io, its manifest Cargo.toml, and its lockfile, Cargo.lock, records a SHA-256 checksum for every crate, as npm 2,036 records an integrity hash.

src/main.rs: printing a BookNest title with serde_jsonShell
fn main() {
    let book = serde_json::json!({ "title": "Salt and Saffron", "price": 24.0 });
    println!("{}", book["title"]);
}
Adding a crate, building and inspecting the lockfileShell
cd ~/v5-ch1 && cargo new -q rs-demo && cd rs-demo
cargo add -q serde_json           # then replace src/main.rs with the listing above
cargo run -q
sed -n '/name = "serde_json"/,/^checksum/p' Cargo.lock
Output
"Salt and Saffron"
name = "serde_json"
version = "1.0.151"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "c841b55ecdae098c80dcae9cf767f6f8a0c2cdb3416bbef72181df4d0fe73f14"

Cargo reads "1.0.151" as ^1.0.151, like npm, and allows two versions of a crate only if they are semver-incompatible (1.x and 2.x). Every crate compiles from source, so serde_json and its four dependencies left 41 MB in target/, and a crate's build.rs runs arbitrary code at build time, Cargo's install script.