This project contains known security vulnerabilities. Find detailed information at the bottom.

Crate gix-revision

Dependencies

(10 total, 7 outdated, 1 insecure)

CrateRequiredLatestStatus
 bstr^1.3.01.13.1up to date
 document-features^0.2.10.2.12up to date
 gix-date ⚠️^0.8.40.17.0insecure
 gix-hash^0.14.10.27.0out of date
 gix-hashtable^0.5.10.17.0out of date
 gix-object^0.41.10.65.0out of date
 gix-revwalk^0.12.00.36.0out of date
 gix-trace^0.1.70.2.0out of date
 serde^1.0.1141.0.229up to date
 thiserror^1.0.262.0.21out of date

Security Vulnerabilities

gix-date: Non-utf8 String can be created with `TimeBuf::as_str`

RUSTSEC-2025-0140

The function gix_date::parse::TimeBuf::as_str can create an illegal string containing non-utf8 characters. This violates the safety invariant of TimeBuf and can lead to undefined behavior when consuming the string.

The bug can be prevented by adding str::from_utf8 to the function TimeBuf::write.