This project might be open to known security vulnerabilities, which can be prevented by tightening the version range of affected dependencies. Find detailed information at the bottom.

Crate deno

Dependencies

(114 total, 26 outdated, 1 possibly insecure)

CrateRequiredLatestStatus
 anstream^0.6.140.6.18up to date
 async-trait^0.1.730.1.88up to date
 base64^0.22.10.22.1up to date
 bincode=1.3.32.0.1out of date
 boxed_error^0.2.30.2.3up to date
 bytes^1.4.01.10.1up to date
 capacity_builder^0.5.00.5.0up to date
 chrono ⚠️^0.40.4.40maybe insecure
 clap=4.5.304.5.34out of date
 clap_complete=4.5.454.5.47out of date
 clap_complete_fig=4.5.24.5.2up to date
 color-print^0.3.50.3.7up to date
 console_static_text=0.8.30.8.3up to date
 crossterm^0.28.10.28.1up to date
 dashmap^5.5.36.1.0out of date
 deno_ast=0.46.20.46.2up to date
 deno_cache_dir=0.18.00.18.0up to date
 deno_config=0.51.00.51.0up to date
 deno_core^0.341.00.341.0up to date
 deno_doc=0.169.10.169.1up to date
 deno_error=0.5.60.5.6up to date
 deno_graph=0.89.30.89.4out of date
 deno_lib^0.13.00.13.0up to date
 deno_lint=0.74.00.74.0up to date
 deno_lockfile=0.25.00.25.0up to date
 deno_media_type=0.2.80.2.8up to date
 deno_npm=0.30.10.30.2out of date
 deno_npm_cache^0.16.00.16.0up to date
 deno_package_json=0.6.00.6.0up to date
 deno_path_util=0.3.20.3.2up to date
 deno_resolver^0.28.00.28.0up to date
 deno_runtime^0.205.00.205.0up to date
 deno_semver=0.7.10.7.1up to date
 deno_snapshots^0.12.00.12.0up to date
 deno_task_shell=0.20.20.21.0out of date
 deno_telemetry^0.19.00.19.0up to date
 deno_terminal=0.2.20.2.2up to date
 dhat^0.3.30.3.3up to date
 dissimilar=1.0.91.0.10out of date
 dotenvy^0.15.70.15.7up to date
 dprint-plugin-json=0.20.00.20.0up to date
 dprint-plugin-jupyter=0.2.00.2.0up to date
 dprint-plugin-markdown=0.18.00.18.0up to date
 dprint-plugin-typescript=0.94.00.94.0up to date
 eszip^0.83.00.83.0up to date
 fancy-regex=0.14.00.14.0up to date
 faster-hex^0.10.00.10.0up to date
 flate2^1.0.301.1.0up to date
 fs3^0.5.00.5.0up to date
 http^1.01.3.1up to date
 http-body^1.01.0.1up to date
 http-body-util^0.1.20.1.3up to date
 import_map=0.21.00.21.0up to date
 indexmap^22.8.0up to date
 jsonc-parser=0.26.20.26.2up to date
 junction=1.2.01.2.0up to date
 runtimelib=0.19.00.25.0out of date
 lazy-regex^33.4.1up to date
 libc^0.2.1680.2.171up to date
 libsui^0.5.00.5.0up to date
 libz-sys^1.1.201.1.22up to date
 log^0.4.200.4.27up to date
 lsp-types=0.97.00.97.0up to date
 malva=0.11.00.11.2out of date
 markup_fmt=0.18.00.19.0out of date
 memchr^2.7.42.7.4up to date
 nix=0.27.10.29.0out of date
 node_resolver^0.35.00.35.0up to date
 notify=6.1.18.0.0out of date
 once_cell^1.17.11.21.3up to date
 open^5.0.15.3.2up to date
 opentelemetry^0.27.00.29.0out of date
 opentelemetry-otlp^0.27.00.29.0out of date
 opentelemetry-semantic-conventions^0.27.00.29.0out of date
 opentelemetry_sdk^0.27.00.29.0out of date
 p256^0.13.20.13.2up to date
 pathdiff^0.2.10.2.3up to date
 percent-encoding^2.3.02.3.1up to date
 phf^0.110.11.3up to date
 pretty_yaml=0.5.00.5.0up to date
 quick-junit^0.3.50.5.1out of date
 rand=0.8.50.9.0out of date
 regex^1.7.01.11.1up to date
 ring^0.17.140.17.14up to date
 rustc-hash^2.1.12.1.1up to date
 rustyline=13.0.015.0.0out of date
 rustyline-derive=0.7.00.11.0out of date
 serde^1.0.1491.0.219up to date
 serde_repr=0.1.190.1.20out of date
 sha2^0.10.80.10.8up to date
 shell-escape=0.1.50.1.5up to date
 spki^0.7.20.7.3up to date
 sqlformat=0.3.50.3.5up to date
 strsim^0.11.10.11.1up to date
 sys_traits=0.1.80.1.8up to date
 tar=0.4.430.4.44out of date
 tempfile^3.4.03.19.1up to date
 text-size=1.1.11.1.1up to date
 text_lines=0.6.00.6.0up to date
 thiserror^2.0.122.0.12up to date
 tokio^1.36.01.44.1up to date
 tokio-util^0.7.40.7.14up to date
 tower^0.5.20.5.2up to date
 deno_tower_lsp=0.4.30.4.3up to date
 tracing^0.10.1.41up to date
 tracing-opentelemetry^0.28.00.30.0out of date
 tracing-subscriber^0.3.190.3.19up to date
 typed-arena=2.0.22.0.2up to date
 unicode-width^0.1.30.2.0out of date
 uuid^1.3.01.16.0up to date
 walkdir=2.5.02.5.0up to date
 winapi=0.3.90.3.9up to date
 zip^2.4.12.5.0up to date
 zstd=0.13.20.13.3out of date

Dev dependencies

(3 total, all up-to-date)

CrateRequiredLatestStatus
 deno_bench_util^0.191.00.191.0up to date
 pretty_assertions=1.4.11.4.1up to date
 sys_traits=0.1.80.1.8up to date

Security Vulnerabilities

chrono: Potential segfault in `localtime_r` invocations

RUSTSEC-2020-0159

Impact

Unix-like operating systems may segfault due to dereferencing a dangling pointer in specific circumstances. This requires an environment variable to be set in a different thread than the affected functions. This may occur without the user's knowledge, notably in a third-party library.

Workarounds

No workarounds are known.

References