This project might be open to known security vulnerabilities, which can be prevented by tightening the version range of affected dependencies. Find detailed information at the bottom.

Crate spirit-log

Dependencies

(16 total, 7 outdated, 1 possibly insecure)

CrateRequiredLatestStatus
 chrono ⚠️~0.40.4.38maybe insecure
 crossbeam-channel~0.30.5.12out of date
 either~11.11.0up to date
 failure~0.10.1.8up to date
 fern~0.5.70.6.2out of date
 itertools~0.80.12.1out of date
 log~0.40.4.21up to date
 log-panics~22.1.0up to date
 log-reroute~0.1.20.1.8up to date
 parking_lot~0.70.12.2out of date
 serde~11.0.200up to date
 serde_json~11.0.116up to date
 spirit~0.3.10.4.21out of date
 structdoc~0.10.1.4up to date
 structopt~0.20.3.26out of date
 syslog~46.1.1out of date

Dev dependencies

(1 total, 1 outdated)

CrateRequiredLatestStatus
 version-sync~0.70.9.5out of date

Security Vulnerabilities

chrono: Potential segfault in `localtime_r` invocations

RUSTSEC-2020-0159

Impact

Unix-like operating systems may segfault due to dereferencing a dangling pointer in specific circumstances. This requires an environment variable to be set in a different thread than the affected functions. This may occur without the user's knowledge, notably in a third-party library.

Workarounds

No workarounds are known.

References