We do have an issue to make the output better, and it’s one of the item on the list. Other than that - colors, sorting order, summary, etc.
This one is one I’m uneasy about. crev is essentially a cryptographic WoT. So everything is set-up, so you can trust reviews of other people and verify everything locally. Setting up a whole system of managing trust of ownership is quite complex, and is less of a guarantee than data returned by crates.io and fact of ownership. eg. what if ownership is shared, or someone’s account is compromised, crates.io gets hacked. etc.
Hmm…
Taking data from crates.io is the easy part.
I guess I could add a command or two, to be able to maintain a list of trusted and distrusted crates.io authors, and then mark crates in the summary view (cargo crev verify deps) somehow. Eg. new column “author” with known, unkown, flagged.
Now, should I circulate such information as a signed proof? Hmm… It is somewhat appealing, because the data is already there etc. But on the other hand the potential negative consequence is that it distracts from actually reviewing crates and gives false sense of security. Reputable authors can have their accounts compromised, or go to the dark side too.
Summing up: ideally, I would like burntsushi to sign reviews of his own (and other) crates, and not have people trust everything just because it says that allegedly it was authored by burntsushi. 