Subject
axum-core 0.5.6 is the foundational layer of the axum web framework, extracted into its own crate so that library authors can implement FromRequest, FromRequestParts, and IntoResponse without depending on the full axum crate. It defines the core trait hierarchy (FromRequestParts, FromRequest, IntoResponse, IntoResponseParts), the Body type that wraps an unsync boxed body, the DefaultBodyLimit Tower layer and middleware, request extension helpers (RequestExt, RequestPartsExt), a small set of standard extractor impls for primitive types (Bytes, String, HeaderMap, etc.), and the macro infrastructure (__define_rejection!, __composite_rejection!) used by axum to declare rejection types. The crate declares unsafe_code = "forbid" and is entirely safe Rust.
Methodology
The published crate contents were compared against the upstream Git repository at the commit recorded in .cargo_vcs_info.json using diff -rq. All 18 source files (~3780 LOC total) were read in full. Surveys were run for unsafe, FFI, network, filesystem, process, environment, crypto, RNG, and concurrency patterns using grep. The manifest files Cargo.toml and Cargo.toml.orig were read in full. The CHANGELOG and README were read. The VCS checkout in vcs/ was confirmed present and the diff against published contents showed only the expected Cargo normalization differences.
Tools used: openvet 0.6.0, diff, grep.
Results
The diff between the published crate and the VCS checkout at the pinned commit shows only Cargo.toml normalization and the expected cargo-generated sidecar files (Cargo.toml.orig, Cargo.lock, .cargo_vcs_info.json). All source files are byte-for-byte identical between the published crate and the repository. No unexplained files are present.
The crate declares [lints.rust] unsafe_code = "forbid". A full-codebase grep confirms no unsafe keyword appears anywhere in the source, justifying uses-unsafe = false. There is no build.rs and the crate is not a proc macro, justifying has-build-exec = false and has-install-exec = false. No binary artifacts are present (has-binaries = false).
No network I/O, filesystem access, process execution, environment variable reads, or cryptographic operations appear anywhere in the source, justifying uses-network = false, uses-filesystem = false, uses-exec = false, uses-environment = false, uses-crypto = false. The crate imports no async runtime and spawns no threads; it exposes async trait methods that callers drive via their own executor. This justifies uses-concurrency = false. No JIT, interpreter, or scripting engine is used or implemented, justifying uses-jit = false, uses-interpreter = false, impl-jit = false, impl-interpreter = false.
The crate does not implement cryptographic operations (impl-crypto = false), does not implement a parser (impl-parser = false), does not define new data structures or algorithms beyond straightforward newtype wrappers (impl-datastructure = false, impl-algorithm = false), does not implement a protocol (impl-protocol = false), and does not implement concurrency primitives (impl-concurrency = false).
Unit tests are present inline in multiple source files (13 test functions, justifying has-unit-tests); no integration, fuzz, or property tests are part of this crate (has-integration-tests = false, has-fuzz-tests = false, has-property-tests = false). The test coverage spans the main extractor impls and the rejection macro machinery.
No issues were found warranting a finding. The crate has no malicious or suspicious code (is-benign = true).
Conclusion
All source files matched the upstream repository at the pinned commit. The crate contains no unsafe code, no I/O, and no build-time execution. The public API consists of trait definitions, newtype wrappers, and macro-generated boilerplate; the logic in each file is straightforward. No findings were raised.