RustSec
@RustSec
Security advisory database for Rust crates published through http://crates.io. A project of the @rustsecurecode working group.
Growth in the @RustSec security advisory database year-over-year throughout its 6-year history
Rust is the fastest growing language on GitHub, and GitHub’s supply chain security features now help keep your Rust projects secure 🔒 github.co/3tiGH9E
blog.logrocket.com/comparing-rust… Comparing Rust supply chain safety tools
A malicious crate was uploaded to crates.io, targeting GitLab CI environments. Read more on the security advisory: blog.rust-lang.org/2022/05/10/mal…
The regex crate is vulnerable to denial of service attacks when parsing untrusted regexes (CVE-2022-24713). We released version 1.5.5, fixing the issue. Read the advisory: blog.rust-lang.org/2022/03/08/cve…
The std::fs::remove_dir_all function in the Rust standard library is vulnerable to a race condition (CVE-2022-21658). We will release Rust 1.58.1 with the fix later today. Read the advisory: blog.rust-lang.org/2022/01/20/cve…
We have a security advisory for rustc today: blog.rust-lang.org/2021/11/01/cve… We will have a 1.56.1 release out soon.
My team's first release since I joined GitHub is out today, and my first GitHub blog is live! Thanks so much to the @RustSec community for collaborating to bring curated Rust security advisories to the GitHub Advisory Database! github.blog/2021-09-23-git…
Introducing `auditable`: audit compiled @rustlang binaries against security advisories in the @RUSTSEC database: reddit.com/r/rust/comment…
RUSTSEC-2020-0036: failure is officially deprecated/unmaintained rustsec.org/advisories/RUS…
The Rust team was notified of a vulnerability affecting crates.io API tokens generation and storage, and out of aboundance of precaution we revoked all existing tokens. Learn more on the advisory: blog.rust-lang.org/2020/07/14/cra…
We've posted a retrospective on RUSTSEC advisories filed in April 2020: - rusqlite - os_str_bytes - flatbuffers - fake-static - plutonium reddit.com/r/rust/comment…
cargo-audit v0.12.0 is out with some minor fixes, including git2 crate updates which should make it easier to install: github.com/RustSec/cargo-…
United States 趨勢
- 1. Chris Paul 8,931 posts
- 2. Pat Spencer 2,710 posts
- 3. FELIX LV VISIONARY SEOUL 11.2K posts
- 4. #FELIXxLouisVuitton 13.6K posts
- 5. Kerr 5,642 posts
- 6. Podz 3,322 posts
- 7. The Clippers 11.3K posts
- 8. Shai 15.8K posts
- 9. Seth Curry 5,053 posts
- 10. Jimmy Butler 2,666 posts
- 11. Lawrence Frank N/A
- 12. Hield 1,588 posts
- 13. Carter Hart 4,152 posts
- 14. #DubNation 1,440 posts
- 15. Mark Pope 1,980 posts
- 16. #SeanCombsTheReckoning 5,377 posts
- 17. #AreYouSure2 133K posts
- 18. Brandy 8,279 posts
- 19. Elden Campbell N/A
- 20. Derek Dixon 1,340 posts
Something went wrong.
Something went wrong.