This project contains known security vulnerabilities. Find detailed information at the bottom.

Crate kitsune-activitypub

Dependencies

(12 total, all up-to-date)

CrateRequiredLatestStatus
 async-trait^0.1.830.1.83up to date
 base64-simd^0.8.00.8.0up to date
 futures-util^0.3.310.3.31up to date
 headers^0.4.00.4.0up to date
 http^1.1.01.1.0up to date
 mime^0.3.170.3.17up to date
 mime_guess^2.0.52.0.5up to date
 serde^1.0.2101.0.213up to date
 sha2^0.10.80.10.8up to date
 tracing^0.1.400.1.40up to date
 typed-builder^0.20.00.20.0up to date
 url^2.5.22.5.2up to date

Dev dependencies

(4 total, all up-to-date)

CrateRequiredLatestStatus
 http-body-util^0.1.20.1.2up to date
 hyper^1.5.01.5.0up to date
 pretty_assertions^1.4.11.4.1up to date
 tower^0.5.10.5.1up to date

Crate kitsune-cache

Dependencies

(4 total, all up-to-date)

CrateRequiredLatestStatus
 enum_dispatch^0.3.130.3.13up to date
 serde^1.0.2101.0.213up to date
 tracing^0.1.400.1.40up to date
 typed-builder^0.20.00.20.0up to date

Crate kitsune-captcha

Dependencies

(6 total, all up-to-date)

CrateRequiredLatestStatus
 enum_dispatch^0.3.130.3.13up to date
 http^1.1.01.1.0up to date
 serde^1.0.2101.0.213up to date
 serde_urlencoded^0.7.10.7.1up to date
 strum^0.26.30.26.3up to date
 typed-builder^0.20.00.20.0up to date

Crate kitsune-config

Dependencies

(6 total, all up-to-date)

CrateRequiredLatestStatus
 eyre^0.6.120.6.12up to date
 human-size^0.4.30.4.3up to date
 isolang^2.4.02.4.0up to date
 serde^1.0.2101.0.213up to date
 smol_str^0.3.10.3.1up to date
 toml^0.8.190.8.19up to date

Crate kitsune-core

Dependencies

(7 total, all up-to-date)

CrateRequiredLatestStatus
 async-trait^0.1.830.1.83up to date
 const_format^0.2.330.2.33up to date
 git-version^0.3.90.3.9up to date
 paste^1.0.151.0.15up to date
 serde^1.0.2101.0.213up to date
 typed-builder^0.20.00.20.0up to date
 unsize^1.1.01.1.0up to date

Crate kitsune-db

Dependencies

(12 total, 1 outdated)

CrateRequiredLatestStatus
 diesel_migrations^2.2.02.2.0up to date
 futures-util^0.3.310.3.31up to date
 num-derive^0.4.20.4.2up to date
 num-traits^0.2.190.2.19up to date
 rustls^0.23.150.23.15up to date
 rustls-native-certs^0.8.00.8.0up to date
 serde^1.0.2101.0.213up to date
 tokio-postgres^0.7.120.7.12up to date
 tokio-postgres-rustls^0.12.00.13.0out of date
 tracing^0.1.400.1.40up to date
 tracing-log^0.2.00.2.0up to date
 typed-builder^0.20.00.20.0up to date

Crate kitsune-derive

Dependencies

(1 total, all up-to-date)

CrateRequiredLatestStatus
 typed-builder^0.20.00.20.0up to date

Crate kitsune-derive-impl

Dependencies

(3 total, all up-to-date)

CrateRequiredLatestStatus
 proc-macro2^1.0.881.0.89up to date
 quote^1.0.371.0.37up to date
 syn^2.0.792.0.82up to date

Crate kitsune-email

Dependencies

(4 total, all up-to-date)

CrateRequiredLatestStatus
 askama_axum^0.4.00.4.0up to date
 lettre^0.11.90.11.9up to date
 mrml^4.0.14.0.1up to date
 typed-builder^0.20.00.20.0up to date

Crate kitsune-embed

Dependencies

(2 total, all up-to-date)

CrateRequiredLatestStatus
 http^1.1.01.1.0up to date
 smol_str^0.3.10.3.1up to date

Crate kitsune-error

Dependencies

(5 total, all up-to-date)

CrateRequiredLatestStatus
 axum-core^0.4.50.4.5up to date
 eyre^0.6.120.6.12up to date
 http^1.1.01.1.0up to date
 sync_wrapper^1.0.11.0.1up to date
 tracing^0.1.400.1.40up to date

Crate kitsune-federation

Dependencies

(1 total, all up-to-date)

CrateRequiredLatestStatus
 typed-builder^0.20.00.20.0up to date

Crate kitsune-federation-filter

Dependencies

(2 total, all up-to-date)

CrateRequiredLatestStatus
 globset^0.4.150.4.15up to date
 url^2.5.22.5.2up to date

Crate kitsune-http-client

Dependencies

(11 total, all up-to-date)

CrateRequiredLatestStatus
 bytes^1.7.21.8.0up to date
 futures-util^0.3.310.3.31up to date
 http-body^1.0.11.0.1up to date
 http-body-util^0.1.20.1.2up to date
 hyper^1.5.01.5.0up to date
 hyper-util^0.1.90.1.9up to date
 hyper-rustls^0.27.30.27.3up to date
 pin-project^1.1.61.1.6up to date
 serde^1.0.2101.0.213up to date
 tower^0.5.10.5.1up to date
 tower-http^0.6.10.6.1up to date

Crate kitsune-jobs

Dependencies

(5 total, all up-to-date)

CrateRequiredLatestStatus
 derive_more^1.0.01.0.0up to date
 futures-util^0.3.310.3.31up to date
 serde^1.0.2101.0.213up to date
 tracing^0.1.400.1.40up to date
 typed-builder^0.20.00.20.0up to date

Crate kitsune-language

Dependencies

(4 total, all up-to-date)

CrateRequiredLatestStatus
 isolang^2.4.02.4.0up to date
 rustc-hash^2.0.02.0.0up to date
 whatlang^0.16.40.16.4up to date
 whichlang^0.1.00.1.0up to date

Crate kitsune-mastodon

Dependencies

(6 total, all up-to-date)

CrateRequiredLatestStatus
 futures-util^0.3.310.3.31up to date
 mime^0.3.170.3.17up to date
 serde^1.0.2101.0.213up to date
 smol_str^0.3.10.3.1up to date
 tracing^0.1.400.1.40up to date
 typed-builder^0.20.00.20.0up to date

Crate kitsune-observability

Dependencies

(12 total, all up-to-date)

CrateRequiredLatestStatus
 async-trait^0.1.830.1.83up to date
 eyre^0.6.120.6.12up to date
 http-body-util^0.1.20.1.2up to date
 hyper^1.5.01.5.0up to date
 opentelemetry^0.26.00.26.0up to date
 opentelemetry-http^0.26.00.26.0up to date
 opentelemetry-otlp^0.26.00.26.0up to date
 opentelemetry_sdk^0.26.00.26.0up to date
 tracing^0.1.400.1.40up to date
 tracing-error^0.2.00.2.0up to date
 tracing-opentelemetry^0.27.00.27.0up to date
 tracing-subscriber^0.3.180.3.18up to date

Crate kitsune-oidc

Dependencies

(6 total, all up-to-date)

CrateRequiredLatestStatus
 enum_dispatch^0.3.130.3.13up to date
 http-body-util^0.1.20.1.2up to date
 oauth2^5.0.0-rc.14.4.2up to date
 openidconnect^4.0.0-rc.13.5.0up to date
 serde^1.0.2101.0.213up to date
 url^2.5.22.5.2up to date

Dev dependencies

(1 total, all up-to-date)

CrateRequiredLatestStatus
 tokio^1.40.01.41.0up to date

Crate kitsune-s3

Dependencies

(7 total, all up-to-date)

CrateRequiredLatestStatus
 bytes^1.7.21.8.0up to date
 futures-util^0.3.310.3.31up to date
 http^1.1.01.1.0up to date
 quick-xml^0.36.20.36.2up to date
 rusty-s3^0.5.00.5.0up to date
 serde^1.0.2101.0.213up to date
 typed-builder^0.20.00.20.0up to date

Crate kitsune-scss-compiler

Dependencies

(4 total, all up-to-date)

CrateRequiredLatestStatus
 eyre^0.6.120.6.12up to date
 glob^0.3.10.3.1up to date
 grass_compiler^0.13.40.13.4up to date
 tracing^0.1.400.1.40up to date

Crate kitsune-search

Dependencies

(12 total, all up-to-date)

CrateRequiredLatestStatus
 async-trait^0.1.830.1.83up to date
 bytes^1.7.21.8.0up to date
 enum_dispatch^0.3.130.3.13up to date
 futures-io^0.3.310.3.31up to date
 futures-util^0.3.310.3.31up to date
 http^1.1.01.1.0up to date
 meilisearch-sdk^0.27.10.27.1up to date
 pin-project-lite^0.2.140.2.14up to date
 serde^1.0.2101.0.213up to date
 serde_urlencoded^0.7.10.7.1up to date
 strum^0.26.30.26.3up to date
 tracing^0.1.400.1.40up to date

Crate kitsune-service

Dependencies

(20 total, 1 insecure)

CrateRequiredLatestStatus
 ahash^0.8.110.8.11up to date
 argon2^0.5.30.5.3up to date
 bytes^1.7.21.8.0up to date
 derive_builder^0.20.20.20.2up to date
 eyre^0.6.120.6.12up to date
 futures-util^0.3.310.3.31up to date
 http^1.1.01.1.0up to date
 img-parts^0.3.00.3.0up to date
 mime^0.3.170.3.17up to date
 password-hash^0.5.00.5.0up to date
 pkcs8^0.10.20.10.2up to date
 rand^0.8.50.8.5up to date
 rsa ⚠️^0.9.60.9.6insecure
 rusty-s3^0.5.00.5.0up to date
 serde^1.0.2101.0.213up to date
 smol_str^0.3.10.3.1up to date
 tracing^0.1.400.1.40up to date
 typed-builder^0.20.00.20.0up to date
 url^2.5.22.5.2up to date
 zxcvbn^3.1.03.1.0up to date

Dev dependencies

(6 total, all up-to-date)

CrateRequiredLatestStatus
 hex-simd^0.8.00.8.0up to date
 http-body-util^0.1.20.1.2up to date
 hyper^1.5.01.5.0up to date
 pretty_assertions^1.4.11.4.1up to date
 tempfile^3.13.03.13.0up to date
 tower^0.5.10.5.1up to date

Crate kitsune-storage

Dependencies

(5 total, all up-to-date)

CrateRequiredLatestStatus
 bytes^1.7.21.8.0up to date
 derive_more^1.0.01.0.0up to date
 futures-util^0.3.310.3.31up to date
 rusty-s3^0.5.00.5.0up to date
 tokio-util^0.7.120.7.12up to date

Dev dependencies

(1 total, all up-to-date)

CrateRequiredLatestStatus
 tempfile^3.13.03.13.0up to date

Crate kitsune-test

Dependencies

(10 total, all up-to-date)

CrateRequiredLatestStatus
 bytes^1.7.21.8.0up to date
 futures-util^0.3.310.3.31up to date
 http^1.1.01.1.0up to date
 http-body-util^0.1.20.1.2up to date
 isolang^2.4.02.4.0up to date
 pin-project-lite^0.2.140.2.14up to date
 rand^0.8.50.8.5up to date
 rusty-s3^0.5.00.5.0up to date
 url^2.5.22.5.2up to date
 uuid^1.11.01.11.0up to date

Crate kitsune-type

Dependencies

(4 total, all up-to-date)

CrateRequiredLatestStatus
 serde^1.0.2101.0.213up to date
 serde_with^3.11.03.11.0up to date
 smol_str^0.3.10.3.1up to date
 strum^0.26.30.26.3up to date

Dev dependencies

(3 total, all up-to-date)

CrateRequiredLatestStatus
 pretty_assertions^1.4.11.4.1up to date
 rstest^0.23.00.23.0up to date
 serde_test^11.0.177up to date

Crate kitsune-url

Dependencies

(1 total, all up-to-date)

CrateRequiredLatestStatus
 smol_str^0.3.10.3.1up to date

Crate kitsune-util

Dependencies

(3 total, all up-to-date)

CrateRequiredLatestStatus
 bubble-bath^0.2.00.2.0up to date
 pulldown-cmark^0.12.20.12.2up to date
 rand^0.8.50.8.5up to date

Crate kitsune-wasm-mrf

Dependencies

(13 total, 2 outdated)

CrateRequiredLatestStatus
 async-trait^0.1.830.1.83up to date
 blake3^1.5.41.5.4up to date
 color-eyre^0.6.30.6.3up to date
 derive_more^1.0.01.0.0up to date
 enum_dispatch^0.3.130.3.13up to date
 futures-util^0.3.310.3.31up to date
 redb^2.1.42.1.4up to date
 slab^0.4.90.4.9up to date
 smol_str^0.3.10.3.1up to date
 tracing^0.1.400.1.40up to date
 walkdir^2.5.02.5.0up to date
 wasmtime^25.0.226.0.0out of date
 wasmtime-wasi^25.0.226.0.0out of date

Dev dependencies

(3 total, all up-to-date)

CrateRequiredLatestStatus
 tempfile^3.13.03.13.0up to date
 tracing-subscriber^0.3.180.3.18up to date
 wat^1.219.11.219.1up to date

Crate example-mrf

Dependencies

(2 total, all up-to-date)

CrateRequiredLatestStatus
 rand^0.8.50.8.5up to date
 wit-bindgen^0.34.00.34.0up to date

Crate kitsune-webfinger

Dependencies

(5 total, all up-to-date)

CrateRequiredLatestStatus
 async-trait^0.1.830.1.83up to date
 futures-util^0.3.310.3.31up to date
 http^1.1.01.1.0up to date
 tracing^0.1.400.1.40up to date
 urlencoding^2.1.32.1.3up to date

Dev dependencies

(4 total, all up-to-date)

CrateRequiredLatestStatus
 http-body-util^0.1.20.1.2up to date
 hyper^1.5.01.5.0up to date
 pretty_assertions^1.4.11.4.1up to date
 tower^0.5.10.5.1up to date

Crate kitsune

Dependencies

(34 total, all up-to-date)

CrateRequiredLatestStatus
 argon2^0.5.30.5.3up to date
 askama_axum^0.4.00.4.0up to date
 async-trait^0.1.830.1.83up to date
 axum^0.7.70.7.7up to date
 axum-extra^0.9.40.9.4up to date
 axum-flash^0.8.00.8.0up to date
 bytes^1.7.21.8.0up to date
 chrono^0.4.380.4.38up to date
 color-eyre^0.6.30.6.3up to date
 futures-util^0.3.310.3.31up to date
 headers^0.4.00.4.0up to date
 http^1.1.01.1.0up to date
 http-body-util^0.1.20.1.2up to date
 mimalloc^0.1.430.1.43up to date
 mime^0.3.170.3.17up to date
 mime_guess^2.0.52.0.5up to date
 oxide-auth^0.6.10.6.1up to date
 oxide-auth-async^0.2.10.2.1up to date
 oxide-auth-axum^0.5.00.5.0up to date
 rust-embed^8.5.08.5.0up to date
 scoped-futures^0.1.30.1.3up to date
 serde^1.0.2101.0.213up to date
 serde_urlencoded^0.7.10.7.1up to date
 strum^0.26.30.26.3up to date
 tempfile^3.13.03.13.0up to date
 time^0.3.360.3.36up to date
 tokio-util^0.7.120.7.12up to date
 tower^0.5.10.5.1up to date
 tower-http^0.6.10.6.1up to date
 tracing^0.1.400.1.40up to date
 typed-builder^0.20.00.20.0up to date
 url^2.5.22.5.2up to date
 async-graphql^7.0.117.0.11up to date
 async-graphql-axum^7.0.117.0.11up to date

Build dependencies

(2 total, all up-to-date)

CrateRequiredLatestStatus
 camino^1.1.91.1.9up to date
 fs_extra^1.3.01.3.0up to date

Crate kitsune-cli

Dependencies

(5 total, all up-to-date)

CrateRequiredLatestStatus
 color-eyre^0.6.30.6.3up to date
 dotenvy^0.15.70.15.7up to date
 envy^0.4.20.4.2up to date
 serde^1.0.2101.0.213up to date
 tracing-subscriber^0.3.180.3.18up to date

Crate kitsune-job-runner

Dependencies

(4 total, all up-to-date)

CrateRequiredLatestStatus
 color-eyre^0.6.30.6.3up to date
 mimalloc^0.1.430.1.43up to date
 tracing^0.1.400.1.40up to date
 typed-builder^0.20.00.20.0up to date

Crate athena

Dependencies

(13 total, all up-to-date)

CrateRequiredLatestStatus
 ahash^0.8.110.8.11up to date
 async-trait^0.1.830.1.83up to date
 either^1.13.01.13.0up to date
 futures-util^0.3.310.3.31up to date
 rand^0.8.50.8.5up to date
 serde^1.0.2101.0.213up to date
 smol_str^0.3.10.3.1up to date
 thiserror^1.0.641.0.65up to date
 tokio-util^0.7.120.7.12up to date
 tracing^0.1.400.1.40up to date
 typed-builder^0.20.00.20.0up to date
 typetag^0.2.180.2.18up to date
 unsize^1.1.01.1.0up to date

Dev dependencies

(2 total, all up-to-date)

CrateRequiredLatestStatus
 postcard^1.0.101.0.10up to date
 tracing-subscriber^0.3.180.3.18up to date

Crate blowocking

Dependencies

(3 total, all up-to-date)

CrateRequiredLatestStatus
 rayon^1.10.01.10.0up to date
 thiserror^1.0.641.0.65up to date
 tracing^0.1.400.1.40up to date

Crate cursiv

Dependencies

(11 total, all up-to-date)

CrateRequiredLatestStatus
 aliri_braid^0.4.00.4.0up to date
 blake3^1.5.41.5.4up to date
 cookie^0.18.10.18.1up to date
 hex-simd^0.8.00.8.0up to date
 http^1.1.01.1.0up to date
 pin-project-lite^0.2.140.2.14up to date
 rand^0.8.50.8.5up to date
 tower^0.5.10.5.1up to date
 zeroize^1.8.11.8.1up to date
 async-trait^0.1.830.1.83up to date
 axum-core^0.4.50.4.5up to date

Dev dependencies

(2 total, all up-to-date)

CrateRequiredLatestStatus
 futures-test^0.3.310.3.31up to date
 tower^0.5.10.5.1up to date

Crate fast-cjson

Dependencies

(3 total, all up-to-date)

CrateRequiredLatestStatus
 icu_normalizer^1.5.01.5.0up to date
 memchr^2.7.42.7.4up to date
 serde^1.0.2101.0.213up to date

Dev dependencies

(7 total, all up-to-date)

CrateRequiredLatestStatus
 divan^0.1.140.1.14up to date
 mimalloc^0.1.430.1.43up to date
 olpc-cjson^0.1.40.1.4up to date
 proptest^1.5.01.5.0up to date
 proptest-derive^0.5.00.5.0up to date
 serde^1.0.2101.0.213up to date
 serde_json^1.0.1291.0.132up to date

Crate geomjeungja

Dependencies

(8 total, all up-to-date)

CrateRequiredLatestStatus
 async-trait^0.1.830.1.83up to date
 hickory-resolver^0.25.0-alpha.20.24.1up to date
 rand^0.8.50.8.5up to date
 serde^1.0.2101.0.213up to date
 thiserror^1.0.641.0.65up to date
 tracing^0.1.400.1.40up to date
 typed-builder^0.20.00.20.0up to date
 unsize^1.1.01.1.0up to date

Dev dependencies

(2 total, all up-to-date)

CrateRequiredLatestStatus
 insta^1.40.01.40.0up to date
 rand_xorshift^0.3.00.3.0up to date

Crate http-signatures

Dependencies

(13 total, all up-to-date)

CrateRequiredLatestStatus
 atoi_radix10^0.0.10.0.1up to date
 base64-simd^0.8.00.8.0up to date
 const-oid^0.9.60.9.6up to date
 derive_builder^0.20.20.20.2up to date
 http^1.1.01.1.0up to date
 httpdate^1.0.31.0.3up to date
 logos^0.14.20.14.2up to date
 miette^7.2.07.2.0up to date
 pkcs8^0.10.20.10.2up to date
 ring^0.17.80.17.8up to date
 scoped-futures^0.1.30.1.3up to date
 thiserror^1.0.641.0.65up to date
 tracing^0.1.400.1.40up to date

Dev dependencies

(1 total, all up-to-date)

CrateRequiredLatestStatus
 divan^0.1.140.1.14up to date

Crate http-signatures-cli

Dependencies

(2 total, all up-to-date)

CrateRequiredLatestStatus
 miette^7.2.07.2.0up to date
 owo-colors^4.1.04.1.0up to date

Crate just-retry

Dependencies

(2 total, all up-to-date)

CrateRequiredLatestStatus
 retry-policies^0.4.00.4.0up to date
 tracing^0.1.400.1.40up to date

Crate masto-id-convert

Dependencies

(3 total, all up-to-date)

CrateRequiredLatestStatus
 atoi_radix10^0.0.10.0.1up to date
 nanorand^0.7.00.7.0up to date
 uuid^1.11.01.11.0up to date

Dev dependencies

(3 total, all up-to-date)

CrateRequiredLatestStatus
 divan^0.1.140.1.14up to date
 time^0.3.360.3.36up to date
 uuid^1.11.01.11.0up to date

Crate mrf-manifest

Dependencies

(7 total, all up-to-date)

CrateRequiredLatestStatus
 leb128^0.2.50.2.5up to date
 schemars^0.8.210.8.21up to date
 semver^1.0.231.0.23up to date
 serde^1.0.2101.0.213up to date
 thiserror^1.0.641.0.65up to date
 wasm-encoder^0.219.10.219.1up to date
 wasmparser^0.219.10.219.1up to date

Dev dependencies

(2 total, all up-to-date)

CrateRequiredLatestStatus
 insta^1.40.01.40.0up to date
 wat^1.219.11.219.1up to date

Crate mrf-tool

Dependencies

(3 total, all up-to-date)

CrateRequiredLatestStatus
 color-eyre^0.6.30.6.3up to date
 colored_json^5.0.05.0.0up to date
 wasmparser^0.219.10.219.1up to date

Dev dependencies

(1 total, all up-to-date)

CrateRequiredLatestStatus
 wat^1.219.11.219.1up to date

Crate post-process

Dependencies

(1 total, all up-to-date)

CrateRequiredLatestStatus
 logos^0.14.20.14.2up to date

Dev dependencies

(4 total, all up-to-date)

CrateRequiredLatestStatus
 divan^0.1.140.1.14up to date
 futures-executor^0.3.310.3.31up to date
 insta^1.40.01.40.0up to date
 pretty_assertions^1.4.11.4.1up to date

Crate schaber

Dependencies

(2 total, all up-to-date)

CrateRequiredLatestStatus
 lol_html^2.0.02.0.0up to date
 thiserror^1.0.641.0.65up to date

Crate speedy-uuid

Dependencies

(7 total, all up-to-date)

CrateRequiredLatestStatus
 async-graphql^7.0.117.0.11up to date
 diesel^2.2.42.2.4up to date
 fred^9.2.19.3.0up to date
 serde^1.0.2101.0.213up to date
 thiserror^1.0.641.0.65up to date
 uuid^1.11.01.11.0up to date
 uuid-simd^0.8.00.8.0up to date

Dev dependencies

(1 total, all up-to-date)

CrateRequiredLatestStatus
 serde_test^1.0.1771.0.177up to date

Crate tick-tock-mock

Dev dependencies

(1 total, all up-to-date)

CrateRequiredLatestStatus
 divan^0.1.140.1.14up to date

Crate tower-http-digest

Dependencies

(12 total, all up-to-date)

CrateRequiredLatestStatus
 base64-simd^0.8.00.8.0up to date
 bytes^1.7.21.8.0up to date
 either^1.13.01.13.0up to date
 http^1.1.01.1.0up to date
 http-body^1.0.11.0.1up to date
 memchr^2.7.42.7.4up to date
 pin-project-lite^0.2.140.2.14up to date
 sha2^0.10.80.10.8up to date
 subtle^2.6.12.6.1up to date
 tower-layer^0.3.30.3.3up to date
 tower-service^0.3.30.3.3up to date
 tracing^0.1.400.1.40up to date

Dev dependencies

(4 total, all up-to-date)

CrateRequiredLatestStatus
 bytes^1.7.21.8.0up to date
 futures-test^0.3.310.3.31up to date
 http-body-util^0.1.20.1.2up to date
 tower^0.5.10.5.1up to date

Crate tower-stop-using-brave

Dependencies

(5 total, all up-to-date)

CrateRequiredLatestStatus
 either^1.13.01.13.0up to date
 http^1.1.01.1.0up to date
 regex^1.11.01.11.0up to date
 tower-layer^0.3.30.3.3up to date
 tower-service^0.3.30.3.3up to date

Dev dependencies

(2 total, all up-to-date)

CrateRequiredLatestStatus
 futures-test^0.3.310.3.31up to date
 tower^0.5.10.5.1up to date

Crate tower-x-clacks-overhead

Dependencies

(4 total, all up-to-date)

CrateRequiredLatestStatus
 http^1.1.01.1.0up to date
 pin-project-lite^0.2.140.2.14up to date
 tower-layer^0.3.30.3.3up to date
 tower-service^0.3.30.3.3up to date

Dev dependencies

(2 total, all up-to-date)

CrateRequiredLatestStatus
 futures-test^0.3.310.3.31up to date
 tower^0.5.10.5.1up to date

Crate trials

Dev dependencies

(1 total, all up-to-date)

CrateRequiredLatestStatus
 futures-test^0.3.310.3.31up to date

Crate xtask

Dependencies

(5 total, all up-to-date)

CrateRequiredLatestStatus
 argh^0.1.120.1.12up to date
 eyre^0.6.120.6.12up to date
 tracing^0.1.400.1.40up to date
 tracing-subscriber^0.3.180.3.18up to date
 ureq^2.10.12.10.1up to date

Security Vulnerabilities

rsa: Marvin Attack: potential key recovery through timing sidechannels

RUSTSEC-2023-0071

Impact

Due to a non-constant-time implementation, information about the private key is leaked through timing information which is observable over the network. An attacker may be able to use that information to recover the key.

Patches

No patch is yet available, however work is underway to migrate to a fully constant-time implementation.

Workarounds

The only currently available workaround is to avoid using the rsa crate in settings where attackers are able to observe timing information, e.g. local use on a non-compromised computer is fine.

References

This vulnerability was discovered as part of the "Marvin Attack", which revealed several implementations of RSA including OpenSSL had not properly mitigated timing sidechannel attacks.