This project might be open to known security vulnerabilities , which can be prevented by tightening the version range of affected dependencies. Find detailed information at the bottom .
Crate thag_rs Dependencies (54 total, 7 outdated, 2 possibly insecure)
Dev dependencies (11 total, 1 possibly insecure)
Build dependencies (3 total, 1 outdated)
Crate Required Latest Status phf ^0.120.13.1out of date tempfile ^3.203.24.0up to date toml ^0.90.9.11+spec-1.1.0up to date
Crate thag_common Dependencies (17 total, 2 outdated)
Crate thag_proc_macros Dependencies (8 total, all up-to-date)
Dev dependencies (1 total, all up-to-date)
Crate Required Latest Status strum ^0.270.27.2up to date
Crate thag_profiler Dependencies (16 total, 1 outdated, 1 possibly insecure)
Dev dependencies (5 total, all up-to-date)
Crate thag_styling Dependencies (21 total, 3 outdated)
Dev dependencies (4 total, 2 outdated)
Build dependencies (3 total, 1 outdated)
Crate Required Latest Status phf ^0.120.13.1out of date tempfile ^3.203.24.0up to date toml ^0.90.9.11+spec-1.1.0up to date
Crate thag_demo Dependencies (9 total, 1 possibly insecure)
Security Vulnerabilities chrono: Potential segfault in `localtime_r` invocationsRUSTSEC-2020-0159
Impact
Unix-like operating systems may segfault due to dereferencing a dangling pointer in specific circumstances. This requires an environment variable to be set in a different thread than the affected functions. This may occur without the user's knowledge, notably in a third-party library.
Workarounds
No workarounds are known.
References
tokio: reject_remote_clients Configuration corruptionRUSTSEC-2023-0001
On Windows, configuring a named pipe server with pipe_mode will force ServerOptions ::reject_remote_clients as false.
This drops any intended explicit configuration for the reject_remote_clients that may have been set as true previously.
The default setting of reject_remote_clients is normally true meaning the default is also overridden as false.
Workarounds
Ensure that pipe_mode is set first after initializing a ServerOptions . For example:
let mut opts = ServerOptions::new();
opts.pipe_mode(PipeMode::Message);
opts.reject_remote_clients(true);
Patched
>=1.18.4, <1.19.0
>=1.20.3, <1.21.0
>=1.23.1