Skip to content

merge commit for archive created by Sapling #614

merge commit for archive created by Sapling

merge commit for archive created by Sapling #614

This check has been archived and is scheduled for deletion. Learn more about checks retention
GitHub Actions / Security audit failed Nov 29, 2023 in 0s

Security advisories found

1 advisory(ies), 3 unmaintained, 2 other

Details

Vulnerabilities

RUSTSEC-2023-0065

Tungstenite allows remote attackers to cause a denial of service

Details
Package tungstenite
Version 0.19.0
URL snapview/tungstenite-rs#376
Date 2023-09-25
Patched versions >=0.20.1

The Tungstenite crate through 0.20.0 for Rust allows remote attackers to cause
a denial of service (minutes of CPU consumption) via an excessive length of an
HTTP header in a client handshake. The length affects both how many times a parse
is attempted (e.g., thousands of times) and the average amount of data for each
parse attempt (e.g., millions of bytes).

Warnings

RUSTSEC-2021-0139

ansi_term is Unmaintained

Details
Status unmaintained
Package ansi_term
Version 0.12.1
URL ogham/rust-ansi-term#72
Date 2021-08-18

The maintainer has advised that this crate is deprecated and will not receive any maintenance.

The crate does not seem to have much dependencies and may or may not be ok to use as-is.

Last release seems to have been three years ago.

Possible Alternative(s)

The below list has not been vetted in any way and may or may not contain alternatives;

Dependency Specific Migration(s)

RUSTSEC-2020-0095

difference is unmaintained

Details
Status unmaintained
Package difference
Version 2.0.0
URL johannhof/difference.rs#45
Date 2020-12-20

The author of the difference crate is unresponsive.

Maintained alternatives:

RUSTSEC-2022-0054

wee_alloc is Unmaintained

Details
Status unmaintained
Package wee_alloc
Version 0.4.5
URL rustwasm/wee_alloc#107
Date 2022-05-11

Two of the maintainers have indicated that the crate may not be maintained.

The crate has open issues including memory leaks and may not be suitable for production use.

It may be best to switch to the default Rust standard allocator on wasm32 targets.

Last release seems to have been three years ago.

Possible Alternative(s)

The below list has not been vetted in any way and may or may not contain alternatives;

Honorable Mention(s)

The below may serve to educate on potential future alternatives: