This project might be open to known security vulnerabilities, which can be prevented by tightening the version range of affected dependencies. Find detailed information at the bottom.

Crate kvarn

Dependencies

(30 total, 1 outdated, 1 possibly insecure)

CrateRequiredLatestStatus
 bytes^11.9.0up to date
 compact_str^0.8.00.8.0up to date
 log^0.40.4.22up to date
 time^0.30.3.37up to date
 socket2^0.5.30.5.8up to date
 h2^0.4.50.4.7up to date
 http^1.01.2.0up to date
 mime^0.30.3.17up to date
 mime_guess^22.0.5up to date
 tree_magic_mini^33.1.6up to date
 percent-encoding^22.3.1up to date
 tokio^1.241.42.0up to date
 kvarn-tokio-uring^0.4.0-alpha1N/Aup to date
 moka^0.120.12.8up to date
 dashmap^66.1.0up to date
 rustls ⚠️^0.23.80.23.20maybe insecure
 rustls-pemfile^2.12.2.0up to date
 rustls-webpki^0.1020.102.8up to date
 base64^0.220.22.1up to date
 memchr^22.7.4up to date
 rand^0.80.8.5up to date
 brotli^77.0.0up to date
 flate2^11.0.35up to date
 zstd^0.130.13.2up to date
 tokio-tungstenite^0.240.26.0out of date
 sha-1^0.100.10.1up to date
 futures-util^0.30.3.31up to date
 h3^0.0.60.0.6up to date
 h3-quinn^0.0.70.0.7up to date
 quinn^0.11.10.11.6up to date

Crate kvarn_async

Dependencies

(3 total, all up-to-date)

CrateRequiredLatestStatus
 bytes^11.9.0up to date
 http^1.01.2.0up to date
 tokio^1.241.42.0up to date

Crate kvarn_utils

Dependencies

(5 total, all up-to-date)

CrateRequiredLatestStatus
 log^0.40.4.22up to date
 bytes^11.9.0up to date
 http^1.01.2.0up to date
 percent-encoding^2.32.3.1up to date
 compact_str^0.80.8.0up to date

Crate kvarn_signal

Dependencies

(4 total, all up-to-date)

CrateRequiredLatestStatus
 log^0.40.4.22up to date
 tokio^1.241.42.0up to date
 kvarn-tokio-uring^0.4.0-alpha1N/Aup to date
 notify^77.0.0up to date

Crate kvarn_testing

Dependencies

(7 total, 1 possibly insecure)

CrateRequiredLatestStatus
 reqwest^0.120.12.9up to date
 rand^0.80.8.5up to date
 rcgen^0.130.13.1up to date
 tokio^1.241.42.0up to date
 rustls ⚠️^0.23.80.23.20maybe insecure
 env_logger^0.110.11.5up to date
 log^0.4.190.4.22up to date

Crate kvarn-extensions

Dependencies

(15 total, 1 possibly insecure)

CrateRequiredLatestStatus
 futures-util^0.30.3.31up to date
 kvarn-fastcgi-client^0.90.9.0up to date
 tokio^1.241.42.0up to date
 kvarn-tokio-uring^0.4.0-alpha1N/Aup to date
 async_chunked_transfer^1.41.4.0up to date
 percent-encoding^22.3.1up to date
 memchr^22.7.4up to date
 small-acme^0.2.20.2.2up to date
 x509-parser^0.160.16.0up to date
 rustls ⚠️^0.23.80.23.20maybe insecure
 ron^0.80.8.1up to date
 rcgen^0.130.13.1up to date
 rustls-pemfile^22.2.0up to date
 rand^0.80.8.5up to date
 dashmap^66.1.0up to date

Dev dependencies

(1 total, all up-to-date)

CrateRequiredLatestStatus
 tokio^1.241.42.0up to date

Crate kvarn-chute

Dependencies

(14 total, all up-to-date)

CrateRequiredLatestStatus
 colored^2.02.2.0up to date
 pulldown-cmark^0.120.12.2up to date
 notify^77.0.0up to date
 unicode_categories^0.10.1.1up to date
 time^0.30.3.37up to date
 time-tz^22.0.0up to date
 kvarn_utils^0.60.6.1up to date
 clap^44.5.23up to date
 clap_autocomplete>=0.4.10.4.2up to date
 env_logger^0.110.11.5up to date
 log^0.4.170.4.22up to date
 notify-debouncer-full^0.40.4.0up to date
 syntect^5.0.05.2.0up to date
 lazy_static^1.4.01.5.0up to date

Crate url-crawl

Dependencies

(2 total, all up-to-date)

CrateRequiredLatestStatus
 log^0.40.4.22up to date
 memchr^22.7.4up to date

Crate kvarnctl

Dependencies

(5 total, all up-to-date)

CrateRequiredLatestStatus
 clap^44.5.23up to date
 clap_autocomplete^0.4.10.4.2up to date
 env_logger^0.110.11.5up to date
 log^0.40.4.22up to date
 tokio^1.241.42.0up to date

Security Vulnerabilities

rustls: rustls network-reachable panic in `Acceptor::accept`

RUSTSEC-2024-0399

A bug introduced in rustls 0.23.13 leads to a panic if the received TLS ClientHello is fragmented. Only servers that use rustls::server::Acceptor::accept() are affected.

Servers that use tokio-rustls's LazyConfigAcceptor API are affected.

Servers that use tokio-rustls's TlsAcceptor API are not affected.

Servers that use rustls-ffi's rustls_acceptor_accept API are affected.