This project might be open to known security vulnerabilities , which can be prevented by tightening the version range of affected dependencies. Find detailed information at the bottom .
Crate bevy
Dev dependencies (18 total, 1 outdated)
Crate bevy_internal
No external dependencies! 🙌
Crate bevy_render
Dependencies (16 total, all up-to-date)
Crate bevy_mobile_example
No external dependencies! 🙌
Crate ci
Dependencies (3 total, all up-to-date)
Crate Required Latest Status argh ^0.1
0.1.12
up to date xshell ^0.2
0.2.6
up to date bitflags ^2.3
2.6.0
up to date
Crate build-templated-pages
Dependencies (5 total, 1 outdated)
Crate build-wasm-example
Dependencies (2 total, all up-to-date)
Crate Required Latest Status xshell ^0.2
0.2.6
up to date clap ^4.0
4.5.21
up to date
Crate example-showcase
Dependencies (6 total, all up-to-date)
Crate Required Latest Status xshell ^0.2
0.2.6
up to date clap ^4.0
4.5.21
up to date ron ^0.8
0.8.1
up to date toml_edit ^0.22.7
0.22.22
up to date pbr ^1.1
1.1.1
up to date regex ^1.10.5
1.11.1
up to date
Crate errors
No external dependencies! 🙌
Crate bevy_a11y
Dependencies (1 total, all up-to-date)
Crate Required Latest Status accesskit ^0.17
0.17.0
up to date
Crate bevy_app
Dependencies (2 total, all up-to-date)
Crate bevy_core
Dependencies (1 total, all up-to-date)
Crate Required Latest Status serde ^1.0
1.0.215
up to date
Dev dependencies (2 total, all up-to-date)
Crate bevy_derive
Dependencies (2 total, all up-to-date)
Crate Required Latest Status quote ^1.0
1.0.37
up to date syn ^2.0
2.0.87
up to date
Crate bevy_diagnostic
Dependencies (1 total, all up-to-date)
Crate bevy_ecs
Dependencies (10 total, 1 possibly insecure)
Dev dependencies (2 total, all up-to-date)
Crate bevy_state
No external dependencies! 🙌
Crate bevy_hierarchy
Dependencies (2 total, all up-to-date)
Crate bevy_input
Dependencies (3 total, 1 outdated)
Crate bevy_log
Dependencies (6 total, all up-to-date)
Crate bevy_math
Dependencies (9 total, all up-to-date)
Dev dependencies (4 total, all up-to-date)
Crate Required Latest Status approx ^0.5
0.5.1
up to date rand ^0.8
0.8.5
up to date rand_chacha ^0.3
0.3.1
up to date glam ^0.29
0.29.2
up to date
Crate bevy_ptr
No external dependencies! 🙌
Crate bevy_reflect
Dependencies (12 total, 1 outdated)
Dev dependencies (6 total, all up-to-date)
Crate bevy_time
Dependencies (2 total, all up-to-date)
Crate bevy_transform
Dependencies (2 total, all up-to-date)
Dev dependencies (1 total, all up-to-date)
Crate Required Latest Status approx ^0.5.1
0.5.1
up to date
Crate bevy_utils
Dependencies (4 total, 1 outdated, 1 possibly insecure)
Dev dependencies (1 total, all up-to-date)
Crate bevy_window
Dependencies (3 total, 1 outdated)
Crate bevy_tasks
Dependencies (5 total, all up-to-date)
Dev dependencies (1 total, all up-to-date)
Crate Required Latest Status web-time ^1.1
1.1.0
up to date
Crate bevy_animation
Dependencies (9 total, 2 possibly insecure)
Crate bevy_asset
Dependencies (18 total, 1 outdated)
Crate bevy_audio
Dependencies (1 total, 1 outdated)
Crate Required Latest Status rodio ^0.19
0.20.1
out of date
Crate bevy_color
Dependencies (5 total, all up-to-date)
Crate bevy_core_pipeline
Dependencies (6 total, 1 possibly insecure)
Crate bevy_dev_tools
Dependencies (2 total, all up-to-date)
Crate Required Latest Status serde ^1.0
1.0.215
up to date ron ^0.8.0
0.8.1
up to date
Crate bevy_gilrs
Dependencies (2 total, all up-to-date)
Crate Required Latest Status gilrs ^0.11.0
0.11.0
up to date derive_more ^1
1.0.0
up to date
Crate bevy_gizmos
Dependencies (1 total, all up-to-date)
Crate Required Latest Status bytemuck ^1.0
1.19.0
up to date
Crate bevy_gltf
Dependencies (7 total, all up-to-date)
Crate bevy_image
Dependencies (12 total, all up-to-date)
Crate bevy_pbr
Dependencies (15 total, 1 possibly insecure)
Crate bevy_picking
Dependencies (2 total, all up-to-date)
Crate bevy_remote
Dependencies (6 total, all up-to-date)
Crate bevy_scene
Dependencies (3 total, all up-to-date)
Crate Required Latest Status serde ^1.0
1.0.215
up to date uuid ^1.1
1.11.0
up to date derive_more ^1
1.0.0
up to date
Dev dependencies (3 total, all up-to-date)
Crate bevy_sprite
Dependencies (9 total, all up-to-date)
Crate bevy_text
Dependencies (6 total, all up-to-date)
Dev dependencies (1 total, all up-to-date)
Crate Required Latest Status approx ^0.5.1
0.5.1
up to date
Crate bevy_ui
Dependencies (7 total, 1 outdated)
Crate bevy_winit
Dependencies (9 total, all up-to-date)
Crate bevy_encase_derive
Dependencies (1 total, all up-to-date)
Crate bevy_render_macros
Dependencies (3 total, all up-to-date)
Crate Required Latest Status syn ^2.0
2.0.87
up to date proc-macro2 ^1.0
1.0.89
up to date quote ^1.0
1.0.37
up to date
Crate bevy_mesh
Dependencies (6 total, all up-to-date)
Crate bevy_macro_utils
Dependencies (4 total, all up-to-date)
Crate Required Latest Status toml_edit ^0.22.7
0.22.22
up to date syn ^2.0
2.0.87
up to date quote ^1.0
1.0.37
up to date proc-macro2 ^1.0
1.0.89
up to date
Crate bevy_ecs_macros
Dependencies (3 total, all up-to-date)
Crate Required Latest Status syn ^2.0
2.0.87
up to date quote ^1.0
1.0.37
up to date proc-macro2 ^1.0
1.0.89
up to date
Crate bevy_state_macros
Dependencies (3 total, all up-to-date)
Crate Required Latest Status syn ^2.0
2.0.87
up to date quote ^1.0
1.0.37
up to date proc-macro2 ^1.0
1.0.89
up to date
Crate bevy_reflect_derive
Dependencies (4 total, all up-to-date)
Crate Required Latest Status proc-macro2 ^1.0
1.0.89
up to date quote ^1.0
1.0.37
up to date syn ^2.0
2.0.87
up to date uuid ^1.1
1.11.0
up to date
Crate bevy_utils_proc_macros
Dependencies (3 total, all up-to-date)
Crate Required Latest Status syn ^2.0
2.0.87
up to date quote ^1.0
1.0.37
up to date proc-macro2 ^1.0
1.0.89
up to date
Crate bevy_animation_derive
Dependencies (3 total, all up-to-date)
Crate Required Latest Status proc-macro2 ^1.0
1.0.89
up to date quote ^1.0
1.0.37
up to date syn ^2.0
2.0.87
up to date
Crate bevy_asset_macros
Dependencies (3 total, all up-to-date)
Crate Required Latest Status syn ^2.0
2.0.87
up to date proc-macro2 ^1.0
1.0.89
up to date quote ^1.0
1.0.37
up to date
Crate bevy_gizmos_macros
Dependencies (3 total, all up-to-date)
Crate Required Latest Status syn ^2.0
2.0.87
up to date proc-macro2 ^1.0
1.0.89
up to date quote ^1.0
1.0.37
up to date
Crate bevy_mikktspace
Dependencies (2 total, all up-to-date)
Crate Required Latest Status glam ^0.29.0
0.29.2
up to date libm ^0.2
0.2.11
up to date
Security Vulnerabilities smallvec
: Buffer overflow in SmallVec::insert_manyRUSTSEC-2021-0003
A bug in the SmallVec::insert_many
method caused it to allocate a buffer that was smaller than needed. It then wrote past the end of the buffer, causing a buffer overflow and memory corruption on the heap.
This bug was only triggered if the iterator passed to insert_many
yielded more items than the lower bound returned from its size_hint
method.
The flaw was corrected in smallvec 0.6.14 and 1.6.1, by ensuring that additional space is always reserved for each item inserted. The fix also simplified the implementation of insert_many
to use less unsafe code, so it is easier to verify its correctness.
Thank you to Yechan Bae (@Qwaz) and the Rust group at Georgia Tech’s SSLab for finding and reporting this bug.
Patched
>=0.6.14, <1.0.0
>=1.6.1
thread_local
: Data race in `Iter` and `IterMut`RUSTSEC-2022-0006
In the affected version of this crate, {Iter, IterMut}::next
used a weaker memory ordering when loading values than what was required, exposing a potential data race
when iterating over a ThreadLocal
's values.
Crates using Iter::next
, or IterMut::next
are affected by this issue.