This project contains known security vulnerabilities. Find detailed information at the bottom.

Crate sentry

Dependencies

(23 total, 15 outdated, 1 insecure)

CrateRequiredLatestStatus
 curl^0.4.250.4.50up to date
 http-client^6.5.36.5.3up to date
 httpdate^1.0.01.0.3up to date
 isahc^0.9.142.0.1out of date
 log^0.4.80.4.34up to date
 native-tls^0.2.80.2.18up to date
 reqwest^0.110.13.5out of date
 rustls ⚠️^0.20.60.23.45insecure
 sentry-anyhow^0.29.30.49.3out of date
 sentry-backtrace^0.29.30.49.3out of date
 sentry-contexts^0.29.30.49.3out of date
 sentry-core^0.29.30.49.3out of date
 sentry-debug-images^0.29.30.49.3out of date
 sentry-log^0.29.30.49.3out of date
 sentry-panic^0.29.30.49.3out of date
 sentry-slog^0.29.30.49.3out of date
 sentry-tower^0.29.30.49.3out of date
 sentry-tracing^0.29.30.49.3out of date
 serde_json^1.0.481.0.151up to date
 surf^2.0.02.3.2up to date
 tokio^1.01.53.1up to date
 ureq^2.3.03.4.2out of date
 webpki-roots^0.22.51.0.9out of date

Dev dependencies

(9 total, 2 outdated)

CrateRequiredLatestStatus
 actix-web^44.15.0up to date
 anyhow^1.0.301.0.104up to date
 log^0.4.80.4.34up to date
 pretty_env_logger^0.4.00.5.0out of date
 slog^2.5.22.8.2up to date
 tokio^1.01.53.1up to date
 tower^0.40.5.3out of date
 tracing^0.10.1.44up to date
 tracing-subscriber^0.30.3.23up to date

Security Vulnerabilities

rustls: `rustls::ConnectionCommon::complete_io` could fall into an infinite loop based on network input

RUSTSEC-2024-0336

If a close_notify alert is received during a handshake, complete_io does not terminate.

Callers which do not call complete_io are not affected.

rustls-tokio and rustls-ffi do not call complete_io and are not affected.

rustls::Stream and rustls::StreamOwned types use complete_io and are affected.