This project might be open to known security vulnerabilities, which can be prevented by tightening the version range of affected dependencies. Find detailed information at the bottom.

Crate cocogitto

Dependencies

(25 total, 5 outdated, 1 possibly insecure)

CrateRequiredLatestStatus
 anyhow^11.0.89up to date
 chrono ⚠️^0.4.190.4.38maybe insecure
 clap^4.2.44.5.17up to date
 clap_complete^4.04.5.28up to date
 clap_complete_nushell^4.4.24.5.3up to date
 clap_mangen^0.20.2.23up to date
 colored^22.1.0up to date
 config^0.13.30.14.0out of date
 conventional_commit_parser^0.9.40.9.4up to date
 edit^00.1.5up to date
 git2^0.18.10.19.0out of date
 globset^0.4.80.4.15up to date
 itertools^00.13.0up to date
 log^0.4.160.4.22up to date
 once_cell^11.19.0up to date
 pest^2.72.7.12up to date
 pest_derive^2.72.7.12up to date
 semver^11.0.23up to date
 serde^11.0.210up to date
 shell-words^11.1.0up to date
 stderrlog^0.5.10.6.0out of date
 tempfile^33.12.0up to date
 tera^1.18.11.20.0up to date
 toml^0.5.110.8.19out of date
 which^5.0.06.0.3out of date

Dev dependencies

(8 total, all up-to-date)

CrateRequiredLatestStatus
 assert_cmd^2.0.122.0.16up to date
 cmd_lib^1.3.01.9.4up to date
 indoc^2.0.42.0.5up to date
 predicates^3.0.43.1.2up to date
 pretty_assertions^1.0.01.4.1up to date
 rand^0.8.50.8.5up to date
 sealed_test^1.0.01.1.0up to date
 speculoos^0.11.00.11.0up to date

Security Vulnerabilities

chrono: Potential segfault in `localtime_r` invocations

RUSTSEC-2020-0159

Impact

Unix-like operating systems may segfault due to dereferencing a dangling pointer in specific circumstances. This requires an environment variable to be set in a different thread than the affected functions. This may occur without the user's knowledge, notably in a third-party library.

Workarounds

No workarounds are known.

References