This project contains known security vulnerabilities. Find detailed information at the bottom.

Crate bicycle

Dependencies

(4 total, 1 outdated)

CrateRequiredLatestStatus
 heck^0.5.00.5.0up to date
 toml^0.8.101.1.6+spec-1.1.0out of date
 serde_json^1.0.1141.0.151up to date
 clap^4.5.14.6.7up to date

Crate bicycle_core

Dependencies

(2 total, 2 outdated, 1 insecure)

CrateRequiredLatestStatus
 wasi-common^18.0.246.0.3out of date
 wasmtime ⚠️^18.0.249.0.2insecure

Crate bicycle_rocksdb

Dependencies

(1 total, 1 outdated)

CrateRequiredLatestStatus
 rocksdb^0.22.00.25.0out of date

Crate bicycle_sqlite

Dependencies

(2 total, 1 outdated)

CrateRequiredLatestStatus
 r2d2^0.8.100.8.10up to date
 r2d2_sqlite^0.24.00.35.0out of date

Crate bicycle_proto

No external dependencies! 🙌

Crate bicycle_shims

Dependencies

(1 total, 1 outdated)

CrateRequiredLatestStatus
 tonic^0.11.00.14.6out of date

Crate bicycle_server

Dependencies

(1 total, all up-to-date)

CrateRequiredLatestStatus
 jemallocator^0.5.00.5.4up to date

Security Vulnerabilities

wasmtime: Wasmtime doesn't fully sandbox all the Windows device filenames

RUSTSEC-2024-0438

This is an entry in the RustSec database for the Wasmtime security advisory located at https://github.com/bytecodealliance/wasmtime/security/advisories/GHSA-c2f5-jxjv-2hh8. For more information see the GitHub-hosted security advisory.

wasmtime: Host panic with `fd_renumber` WASIp1 function

RUSTSEC-2025-0046

This is an entry in the RustSec database for the Wasmtime security advisory located at https://github.com/bytecodealliance/wasmtime/security/advisories/GHSA-fm79-3f68-h2fc. For more information see the GitHub-hosted security advisory.

wasmtime: Unsound API access to a WebAssembly shared linear memory

RUSTSEC-2025-0118

This is an entry in the RustSec database for the Wasmtime security advisory located at https://github.com/bytecodealliance/wasmtime/security/advisories/GHSA-hc7m-r6v8-hg9q For more information see the GitHub-hosted security advisory.

wasmtime: Guest-controlled resource exhaustion in WASI implementations

RUSTSEC-2026-0020

This is an entry in the RustSec database for the Wasmtime security advisory located at https://github.com/bytecodealliance/wasmtime/security/advisories/GHSA-852m-cvvp-9p4w For more information see the GitHub-hosted security advisory.

wasmtime: Panic adding excessive fields to a `wasi:http/types.fields` instance

RUSTSEC-2026-0021

This is an entry in the RustSec database for the Wasmtime security advisory located at https://github.com/bytecodealliance/wasmtime/security/advisories/GHSA-243v-98vx-264h For more information see the GitHub-hosted security advisory.

wasmtime: Panic when lifting `flags` component value

RUSTSEC-2026-0085

This is an entry in the RustSec database for the Wasmtime security advisory located at https://github.com/bytecodealliance/wasmtime/security/advisories/GHSA-m758-wjhj-p3jq For more information see the GitHub-hosted security advisory.

wasmtime: Host data leakage with 64-bit tables and Winch

RUSTSEC-2026-0086

This is an entry in the RustSec database for the Wasmtime security advisory located at https://github.com/bytecodealliance/wasmtime/security/advisories/GHSA-m9w2-8782-2946 For more information see the GitHub-hosted security advisory.

wasmtime: Wasmtime segfault or unused out-of-sandbox load with `f64x2.splat` operator on Cranelift x86-64

RUSTSEC-2026-0087

This is an entry in the RustSec database for the Wasmtime security advisory located at https://github.com/bytecodealliance/wasmtime/security/advisories/GHSA-qqfj-4vcm-26hv For more information see the GitHub-hosted security advisory.

wasmtime: Data leakage between pooling allocator instances

RUSTSEC-2026-0088

This is an entry in the RustSec database for the Wasmtime security advisory located at https://github.com/bytecodealliance/wasmtime/security/advisories/GHSA-6wgr-89rj-399p For more information see the GitHub-hosted security advisory.

wasmtime: Host panic when Winch compiler executes `table.fill`

RUSTSEC-2026-0089

This is an entry in the RustSec database for the Wasmtime security advisory located at https://github.com/bytecodealliance/wasmtime/security/advisories/GHSA-q49f-xg75-m9xw For more information see the GitHub-hosted security advisory.

wasmtime: Out-of-bounds write or crash when transcoding component model strings

RUSTSEC-2026-0091

This is an entry in the RustSec database for the Wasmtime security advisory located at https://github.com/bytecodealliance/wasmtime/security/advisories/GHSA-394w-hwhg-8vgm For more information see the GitHub-hosted security advisory.

wasmtime: Panic when transcoding misaligned component model UTF-16 strings

RUSTSEC-2026-0092

This is an entry in the RustSec database for the Wasmtime security advisory located at https://github.com/bytecodealliance/wasmtime/security/advisories/GHSA-jxhv-7h78-9775 For more information see the GitHub-hosted security advisory.

wasmtime: Heap OOB read in component model UTF-16 to latin1+utf16 string transcoding

RUSTSEC-2026-0093

This is an entry in the RustSec database for the Wasmtime security advisory located at https://github.com/bytecodealliance/wasmtime/security/advisories/GHSA-hx6p-xpx3-jvvv For more information see the GitHub-hosted security advisory.

wasmtime: Improperly masked return value from `table.grow` with Winch compiler backend

RUSTSEC-2026-0094

This is an entry in the RustSec database for the Wasmtime security advisory located at https://github.com/bytecodealliance/wasmtime/security/advisories/GHSA-f984-pcp8-v2p7 For more information see the GitHub-hosted security advisory.

wasmtime: Wasmtime with Winch compiler backend may allow a sandbox-escaping memory access

RUSTSEC-2026-0095

This is an entry in the RustSec database for the Wasmtime security advisory located at https://github.com/bytecodealliance/wasmtime/security/advisories/GHSA-xx5w-cvp6-jv83 For more information see the GitHub-hosted security advisory.

wasmtime: Miscompiled guest heap access enables sandbox escape on aarch64 Cranelift

RUSTSEC-2026-0096

This is an entry in the RustSec database for the Wasmtime security advisory located at https://github.com/bytecodealliance/wasmtime/security/advisories/GHSA-jhxm-h53p-jm7w For more information see the GitHub-hosted security advisory.

wasmtime: Stores can mix up type indices between engines

RUSTSEC-2026-0222

This is an entry in the RustSec database for the Wasmtime security advisory located at https://github.com/bytecodealliance/wasmtime/security/advisories/GHSA-hgjw-h833-99q9 For more information see the GitHub-hosted security advisory.

wasmtime: Filesystem sandbox escape when paths or symlinks contain trailing slashes

RUSTSEC-2026-0269

This is an entry in the RustSec database for the Wasmtime security advisory located at https://github.com/bytecodealliance/wasmtime/security/advisories/GHSA-vqjp-4c8c-hfgg For more information see the GitHub-hosted security advisory.