I've used Rust a bit, but not enough to know the details of how cargo and crates.io approach managing collected information.
There seems to be an open issue and WIP PR with more details:
Issue: https://github.com/rust-lang/crates.io/issues/955
PR: https://github.com/rust-lang/www.rust-lang.org/pull/919/file...
The cargo manifest also supports things like:
The publish field (optional)
The publish field can be used to prevent a package from
being published to a package registry (like crates.io) by mistake,
for instance to keep a package private in a company.
[package]
# ...
publish = false
But I would be curious if someone more knowledgeable than myself would be interested in giving a quick summary of the approach?