This project might be open to known security vulnerabilities, which can be prevented by tightening the version range of affected dependencies. Find detailed information at the bottom.

Crate sheets-diff

Dependencies

(2 total, 1 possibly insecure)

CrateRequiredLatestStatus
 calamine ⚠️^00.27.0maybe insecure
 serde^11.0.219up to date

Security Vulnerabilities

calamine: `Sectors::get` accesses unclaimed/uninitialized memory

RUSTSEC-2021-0015

Affected versions of this crate arbitrarily calls Vec::set_len to increase length of a vector without claiming more memory for the vector. Affected versions of this crate also calls user-provided Read on the uninitialized memory of the vector that was extended with Vec::set_len.

This can overwrite active entities in adjacent heap memory and seems to be a major security issue. Also, calling user-provided Read on uninitialized memory is defined as UB in Rust.