This project contains known security vulnerabilities. Find detailed information at the bottom.

Crate block-format

Dependencies

(4 total, 4 outdated)

CrateRequiredLatestStatus
 bytes^0.51.12.1out of date
 cid^0.50.11.3out of date
 multihash^0.110.19.5out of date
 thiserror^1.02.0.21out of date

Crate datastore

Dependencies

(7 total, 4 outdated)

CrateRequiredLatestStatus
 async-std^1.51.13.2up to date
 async-trait^0.10.1.92up to date
 parking_lot^0.10.00.12.5out of date
 path-clean^0.11.0.1out of date
 serde^1.01.0.229up to date
 thiserror^1.02.0.21out of date
 uuid^0.81.27.0out of date

Dev dependencies

(3 total, 1 outdated)

CrateRequiredLatestStatus
 matches^0.10.1.10up to date
 rand^0.7.20.10.3out of date
 serde_json^1.01.0.151up to date

Crate ds-rocksdb

Dependencies

(1 total, 1 outdated)

CrateRequiredLatestStatus
 thiserror^1.02.0.21out of date

Dev dependencies

(3 total, 1 outdated)

CrateRequiredLatestStatus
 matches^0.10.1.10up to date
 rand^0.70.10.3out of date
 tempfile^3.13.27.0up to date

Crate fs-lock

Dependencies

(3 total, all up-to-date)

CrateRequiredLatestStatus
 fs2^0.40.4.3up to date
 lazy_static^1.41.5.1up to date
 log^0.40.4.34up to date

Dev dependencies

(1 total, all up-to-date)

CrateRequiredLatestStatus
 tempfile^3.13.27.0up to date

Crate ipfs-blockstore

Dependencies

(2 total, 2 outdated)

CrateRequiredLatestStatus
 cid^0.50.11.3out of date
 thiserror^1.02.0.21out of date

Crate ipld-core

Dependencies

(8 total, 5 outdated)

CrateRequiredLatestStatus
 bytes^0.51.12.1out of date
 cid^0.50.11.3out of date
 either^1.51.18.0up to date
 minicbor^0.42.3.0out of date
 multihash^0.110.19.5out of date
 serde^1.01.0.229up to date
 serde_json^1.01.0.151up to date
 thiserror^1.02.0.21out of date

Dev dependencies

(3 total, 1 outdated)

CrateRequiredLatestStatus
 criterion^0.30.8.2out of date
 hex^0.40.4.3up to date
 maplit^1.01.0.2up to date

Crate ipld-format

Dependencies

(4 total, 3 outdated)

CrateRequiredLatestStatus
 cid^0.50.11.3out of date
 lazy_static^1.41.5.1up to date
 multihash^0.110.19.5out of date
 thiserror^1.02.0.21out of date

Dev dependencies

(1 total, 1 outdated)

CrateRequiredLatestStatus
 bytes^0.51.12.1out of date

Crate kvdb

Dependencies

(2 total, all up-to-date)

CrateRequiredLatestStatus
 smallvec^1.0.01.16.2up to date
 lazy_static^1.41.5.1up to date

Crate kvdb-rocksdb

Dependencies

(9 total, 2 outdated, 2 insecure)

CrateRequiredLatestStatus
 smallvec^1.0.01.16.2up to date
 fs-swap^0.2.40.2.6up to date
 interleaved-ordered^0.1.10.1.1up to date
 log^0.4.80.4.34up to date
 num_cpus^1.10.11.17.0up to date
 parking_lot^0.10.00.12.5out of date
 regex^1.3.11.13.1up to date
 rocksdb ⚠️^0.130.25.0insecure
 owning_ref ⚠️^0.4.00.4.1insecure

Dev dependencies

(4 total, 2 outdated)

CrateRequiredLatestStatus
 alloc_counter^0.0.40.0.4up to date
 criterion^0.30.8.2out of date
 rand^0.7.20.10.3out of date
 tempfile^3.13.27.0up to date

Crate kvdb-shared-tests

No external dependencies! 🙌

Security Vulnerabilities

owning_ref: Multiple soundness issues in `owning_ref`

RUSTSEC-2022-0040

  • OwningRef::map_with_owner is unsound and may result in a use-after-free.
  • OwningRef::map is unsound and may result in a use-after-free.
  • OwningRefMut::as_owner and OwningRefMut::as_owner_mut are unsound and may result in a use-after-free.
  • The crate violates Rust's aliasing rules, which may cause miscompilations on recent compilers that emit the LLVM noalias attribute.

safer_owning_ref is a replacement crate which fixes these issues. No patched versions of the original crate are available, and the maintainer is unresponsive.

rocksdb: Out-of-bounds read when opening multiple column families with TTL

RUSTSEC-2022-0046

Affected versions of this crate called the RocksDB C API rocksdb_open_column_families_with_ttl() with a pointer to a single integer TTL value, but one TTL value for each column family is expected.

This is only relevant when using rocksdb::DBWithThreadMode::open_cf_descriptors_with_ttl() with multiple column families.

This bug has been fixed in v0.19.0.