advisory-db icon indicating copy to clipboard operation
advisory-db copied to clipboard

Security advisory database for Rust crates published through crates.io

Results 181 advisory-db issues
Sort by recently updated
recently updated
newest added

But, in the event a vulnerability is reported, we'll consider a crate unmaintainted after a shorter 60 days

hwloc will no longer be maintained as declared by the developer. For more information, see: [hwloc-rs/issues](https://github.com/daschl/hwloc-rs/issues).

strason will no longer be maintained as declared by the developer. For more information, see: [strason/issues/4](https://github.com/apoelstra/strason/issues/4).

For more information, see: [rust-bcc/issues/200](https://github.com/rust-bpf/rust-bcc/issues/200) In the meantime, bcc will no longer be maintained. Users are encouraged to migrate to libbpf-rs.

The author has stated in the project's README and [crates.io page](https://crates.io/crates/instant/0.1.13) that the crate is unmaintained, and links to `web-time` as an alternative. See also https://github.com/sebcrozet/instant/issues/52. CC @sebcrozet @daxpedda

https://github.com/aarch64-switch-rs/nx/issues/18#issuecomment-2311281601 Two very blatant violations of &mut, one with no response for 2 years

I'm one of the CosmWasm maintainers.

For more information: https://github.com/tikv/minitrace-rust/issues/229

https://github.com/rmcgibbo/async-priority-channel/issues/75 The objects provided don't meet most definitions of channels (fifo). This is likely to cause someone else to use the library without knowing, and possibly causing a vulnerability. Developer...

Both crates mentioned advertise a sandbox-by-default behavior from within the runtime, which can be violated by this op