RustSec's profile picture. Security advisory database for Rust crates published through http://crates.io. A project of the @rustsecurecode working group.

RustSec

@RustSec

Security advisory database for Rust crates published through http://crates.io. A project of the @rustsecurecode working group.

مثبتة

Growth in the @RustSec security advisory database year-over-year throughout its 6-year history

RustSec's tweet image. Growth in the @RustSec security advisory database year-over-year throughout its 6-year history

RustSec أعاد

Rust is the fastest growing language on GitHub, and GitHub’s supply chain security features now help keep your Rust projects secure 🔒 github.co/3tiGH9E


RustSec أعاد

A malicious crate was uploaded to crates.io, targeting GitLab CI environments. Read more on the security advisory: blog.rust-lang.org/2022/05/10/mal…


RustSec أعاد

The regex crate is vulnerable to denial of service attacks when parsing untrusted regexes (CVE-2022-24713). We released version 1.5.5, fixing the issue. Read the advisory: blog.rust-lang.org/2022/03/08/cve…


RustSec أعاد

The std::fs::remove_dir_all function in the Rust standard library is vulnerable to a race condition (CVE-2022-21658). We will release Rust 1.58.1 with the fix later today. Read the advisory: blog.rust-lang.org/2022/01/20/cve…


RustSec أعاد

We have a security advisory for rustc today: blog.rust-lang.org/2021/11/01/cve… We will have a 1.56.1 release out soon.


The rustsec.org web site now features severity information for each security advisory

RustSec's tweet image. The rustsec.org web site now features severity information for each security advisory
RustSec's tweet image. The rustsec.org web site now features severity information for each security advisory

RustSec أعاد

My team's first release since I joined GitHub is out today, and my first GitHub blog is live! Thanks so much to the @RustSec community for collaborating to bring curated Rust security advisories to the GitHub Advisory Database! github.blog/2021-09-23-git…


Introducing `auditable`: audit compiled @rustlang binaries against security advisories in the @RUSTSEC database: reddit.com/r/rust/comment…


RUSTSEC-2020-0036: failure is officially deprecated/unmaintained rustsec.org/advisories/RUS…


RustSec أعاد

The Rust team was notified of a vulnerability affecting crates.io API tokens generation and storage, and out of aboundance of precaution we revoked all existing tokens. Learn more on the advisory: blog.rust-lang.org/2020/07/14/cra…


We've posted a retrospective on RUSTSEC advisories filed in April 2020: - rusqlite - os_str_bytes - flatbuffers - fake-static - plutonium reddit.com/r/rust/comment…


Loading...

Something went wrong.


Something went wrong.