This project might be open to known security vulnerabilities, which can be prevented by tightening the version range of affected dependencies. Find detailed information at the bottom.

Crate deno_resolver

Dependencies

(40 total, 8 outdated, 1 possibly insecure)

CrateRequiredLatestStatus
 anyhow^1.0.571.0.100up to date
 async-once-cell^0.5.40.5.4up to date
 async-trait^0.1.730.1.89up to date
 base32=0.5.10.5.1up to date
 boxed_error^0.2.30.2.3up to date
 capacity_builder^0.5.00.5.0up to date
 chrono ⚠️^0.40.4.42maybe insecure
 dashmap^5.5.36.1.0out of date
 deno_ast=0.52.00.52.0up to date
 deno_cache_dir=0.26.30.26.3up to date
 deno_config^0.72.00.72.0up to date
 deno_error=0.7.10.7.3out of date
 deno_graph=0.105.00.105.0up to date
 deno_lockfile=0.32.20.32.2up to date
 deno_maybe_sync^0.9.00.9.0up to date
 deno_media_type=0.3.00.3.3out of date
 deno_npm=0.42.20.42.2up to date
 deno_package_json^0.24.00.24.0up to date
 deno_path_util=0.6.40.6.4up to date
 deno_permissions^0.81.00.81.0up to date
 deno_semver=0.9.10.9.1up to date
 deno_terminal=0.2.30.2.3up to date
 deno_unsync^0.4.40.4.4up to date
 dissimilar=1.0.91.0.10out of date
 futures^0.3.310.3.31up to date
 http^1.01.4.0up to date
 import_map^0.24.00.24.0up to date
 indexmap^22.12.1up to date
 jsonc-parser^0.27.10.28.0out of date
 log^0.4.280.4.29up to date
 node_resolver^0.60.00.60.0up to date
 once_cell^1.17.11.21.3up to date
 parking_lot^0.12.00.12.5up to date
 phf^0.110.13.1out of date
 serde^1.0.1491.0.228up to date
 serde_json^1.0.851.0.145up to date
 sys_traits=0.1.170.1.21out of date
 thiserror^2.0.122.0.17up to date
 twox-hash=2.1.02.1.2out of date
 url^2.52.5.7up to date

Dev dependencies

(2 total, 1 outdated)

CrateRequiredLatestStatus
 node_resolver^0.60.00.60.0up to date
 sys_traits=0.1.170.1.21out of date

Security Vulnerabilities

chrono: Potential segfault in `localtime_r` invocations

RUSTSEC-2020-0159

Impact

Unix-like operating systems may segfault due to dereferencing a dangling pointer in specific circumstances. This requires an environment variable to be set in a different thread than the affected functions. This may occur without the user's knowledge, notably in a third-party library.

Workarounds

No workarounds are known.

References