This project contains known security vulnerabilities. Find detailed information at the bottom.

Crate connectorx

Dependencies

(48 total, 21 outdated, 2 insecure)

CrateRequiredLatestStatus
 anyhow^11.0.104up to date
 arrow^4660.0.0out of date
 arrow2 ⚠️^0.170.18.0insecure
 bb8^0.70.9.1out of date
 bb8-tiberius^0.50.16.0out of date
 chrono^0.40.4.45up to date
 csv^11.4.0up to date
 datafusion^3155.1.0out of date
 fallible-streaming-iterator^0.10.1.9up to date
 fehler^11.0.0up to date
 futures^0.30.3.34up to date
 gcp-bigquery-client^0.13.00.28.0out of date
 hex^0.40.4.3up to date
 itertools^0.110.15.0out of date
 j4rs^0.150.25.2out of date
 log^0.40.4.34up to date
 mysql_common^0.290.38.2out of date
 native-tls^0.20.2.18up to date
 ndarray^0.150.17.2out of date
 num-traits^0.20.2.19up to date
 openssl^0.100.10.81up to date
 oracle^0.50.6.3out of date
 owning_ref ⚠️^0.40.4.1insecure
 polars^0.320.55.2out of date
 postgres^0.190.19.14up to date
 postgres-native-tls^0.50.5.3up to date
 postgres-openssl^0.50.5.3up to date
 prusto^0.5.10.5.2up to date
 r2d2^0.80.8.10up to date
 r2d2-oracle^0.60.7.0out of date
 r2d2_mysql^2328.0.0out of date
 r2d2_postgres^0.18.10.18.2up to date
 r2d2_sqlite^0.23.00.35.0out of date
 rayon^11.12.0up to date
 regex^11.13.1up to date
 rusqlite^0.30.00.40.2out of date
 rust_decimal^11.43.0up to date
 rust_decimal_macros^11.40.0up to date
 serde^11.0.229up to date
 serde_json^11.0.151up to date
 sqlparser^0.370.63.0out of date
 thiserror^12.0.21out of date
 tiberius^0.50.13.0out of date
 tokio^11.53.1up to date
 tokio-util^0.60.7.19out of date
 url^22.5.8up to date
 urlencoding^2.12.1.3up to date
 uuid^0.81.26.1out of date

Dev dependencies

(4 total, 3 outdated)

CrateRequiredLatestStatus
 criterion^0.30.8.2out of date
 env_logger^0.90.11.11out of date
 iai^0.10.1.1up to date
 pprof^0.50.15.0out of date

Security Vulnerabilities

owning_ref: Multiple soundness issues in `owning_ref`

RUSTSEC-2022-0040

  • OwningRef::map_with_owner is unsound and may result in a use-after-free.
  • OwningRef::map is unsound and may result in a use-after-free.
  • OwningRefMut::as_owner and OwningRefMut::as_owner_mut are unsound and may result in a use-after-free.
  • The crate violates Rust's aliasing rules, which may cause miscompilations on recent compilers that emit the LLVM noalias attribute.

safer_owning_ref is a replacement crate which fixes these issues. No patched versions of the original crate are available, and the maintainer is unresponsive.

arrow2: Out of bounds access in public safe API

RUSTSEC-2025-0038

Rows::row_unchecked() allows out of bounds access to the underlying buffer without sufficient checks.

The arrow2 crate is no longer maintained, so there are no plans to fix this issue. Users are advised to migrate to the arrow crate, instead.