This project contains known security vulnerabilities. Find detailed information at the bottom.

Crate bp7

Dependencies

(10 total, 4 outdated, 1 insecure)

CrateRequiredLatestStatus
 crc^1.0.03.4.0out of date
 derive_builder^0.90.20.2out of date
 humantime^2.02.4.0up to date
 nanorand ⚠️^0.4.30.8.0insecure
 serde^1.01.0.229up to date
 serde_bytes^0.110.11.19up to date
 serde_cbor^0.110.11.2up to date
 serde_json^1.01.0.151up to date
 stdweb^0.40.4.20up to date
 thiserror^1.0.202.0.21out of date

Dev dependencies

(3 total, 2 outdated)

CrateRequiredLatestStatus
 criterion^0.30.8.2out of date
 instant^0.10.1.13up to date
 test-case^1.0.03.4.0out of date

Security Vulnerabilities

nanorand: nanorand 0.5.0 - RNGs failed to generate properly for non-64-bit numbers

RUSTSEC-2020-0089

In versions of nanorand prior to 0.5.1, RandomGen implementations for standard unsigned integers could fail to properly generate numbers, due to using bit-shifting to truncate a 64-bit number, rather than just an as conversion.

This often manifested as RNGs returning nothing but 0, including the cryptographically secure ChaCha random number generator..