RustSec's profile picture. Security advisory database for Rust crates published through http://crates.io. A project of the @rustsecurecode working group.

RustSec

@RustSec

Security advisory database for Rust crates published through http://crates.io. A project of the @rustsecurecode working group.

置頂

Growth in the @RustSec security advisory database year-over-year throughout its 6-year history

RustSec's tweet image. Growth in the @RustSec security advisory database year-over-year throughout its 6-year history

RustSec 已轉發

Rust is the fastest growing language on GitHub, and GitHub’s supply chain security features now help keep your Rust projects secure 🔒 github.co/3tiGH9E


RustSec 已轉發

A malicious crate was uploaded to crates.io, targeting GitLab CI environments. Read more on the security advisory: blog.rust-lang.org/2022/05/10/mal…


RustSec 已轉發

The regex crate is vulnerable to denial of service attacks when parsing untrusted regexes (CVE-2022-24713). We released version 1.5.5, fixing the issue. Read the advisory: blog.rust-lang.org/2022/03/08/cve…


RustSec 已轉發

The std::fs::remove_dir_all function in the Rust standard library is vulnerable to a race condition (CVE-2022-21658). We will release Rust 1.58.1 with the fix later today. Read the advisory: blog.rust-lang.org/2022/01/20/cve…


RustSec 已轉發

We have a security advisory for rustc today: blog.rust-lang.org/2021/11/01/cve… We will have a 1.56.1 release out soon.


The rustsec.org web site now features severity information for each security advisory

RustSec's tweet image. The rustsec.org web site now features severity information for each security advisory
RustSec's tweet image. The rustsec.org web site now features severity information for each security advisory

RustSec 已轉發

My team's first release since I joined GitHub is out today, and my first GitHub blog is live! Thanks so much to the @RustSec community for collaborating to bring curated Rust security advisories to the GitHub Advisory Database! github.blog/2021-09-23-git…


Introducing `auditable`: audit compiled @rustlang binaries against security advisories in the @RUSTSEC database: reddit.com/r/rust/comment…


RUSTSEC-2020-0036: failure is officially deprecated/unmaintained rustsec.org/advisories/RUS…


RustSec 已轉發

The Rust team was notified of a vulnerability affecting crates.io API tokens generation and storage, and out of aboundance of precaution we revoked all existing tokens. Learn more on the advisory: blog.rust-lang.org/2020/07/14/cra…


We've posted a retrospective on RUSTSEC advisories filed in April 2020: - rusqlite - os_str_bytes - flatbuffers - fake-static - plutonium reddit.com/r/rust/comment…


cargo-audit v0.12.0 is out with some minor fixes, including git2 crate updates which should make it easier to install: github.com/RustSec/cargo-…


Loading...

Something went wrong.


Something went wrong.