This project might be open to known security vulnerabilities, which can be prevented by tightening the version range of affected dependencies. Find detailed information at the bottom.

Crate chama-optics

Dependencies

(55 total, 5 outdated, 1 possibly insecure)

CrateRequiredLatestStatus
 wgpu^27.0.129.0.1out of date
 swift-bridge^0.10.1.59up to date
 futures^0.30.3.32up to date
 log^0.4.290.4.29up to date
 serde^11.0.228up to date
 serde_json^11.0.149up to date
 image^0.25.90.25.10up to date
 rfd^0.17.20.17.2up to date
 egui-file-dialog^0.12.00.13.0out of date
 imageproc>=0.260.26.1up to date
 anyhow^1.01.0.102up to date
 thiserror^22.0.18up to date
 ab_glyph^0.2.320.2.32up to date
 fast_image_resize^6.06.0.0up to date
 lazy_static^1.5.01.5.0up to date
 gcd^2.3.02.3.0up to date
 env_logger^0.11.90.11.10up to date
 web-time^11.1.0up to date
 rust-i18n^3.1.53.1.5up to date
 uuid^1.221.23.0up to date
 strum^0.280.28.0up to date
 strum_macros^0.280.28.0up to date
 sys-locale^0.3.20.3.2up to date
 dirs^6.06.0.0up to date
 num-traits^0.2.190.2.19up to date
 unicode-normalization^0.10.1.25up to date
 clap^4.5.594.6.0up to date
 chrono ⚠️^0.40.4.44maybe insecure
 resvg^0.470.47.0up to date
 tiny-skia^0.120.12.0up to date
 rand^0.100.10.0up to date
 rayon^1.111.11.0up to date
 num_cpus^1.171.17.0up to date
 ndarray^0.170.17.2up to date
 reqwest^0.130.13.2up to date
 mozjpeg^0.10.130.10.13up to date
 webp^0.3.10.3.1up to date
 img-parts^0.40.4.0up to date
 oxipng^1010.1.0up to date
 ort>=2.0.0-rc.10, <=2.0.0-rc.11N/Aup to date
 wagahai_lut^0.1.00.1.0up to date
 getrandom^0.40.4.2up to date
 wasm-bindgen^0.20.2.117up to date
 wasm-bindgen-futures^0.40.4.67up to date
 web-sys^0.30.3.94up to date
 js-sys^0.30.3.94up to date
 zip>=8.28.5.0up to date
 android_logger^0.150.15.1up to date
 libheif-rs^2.72.7.0up to date
 libheif-sys^55.2.0+1.21.2up to date
 candle-core^0.90.10.2out of date
 candle-nn^0.90.10.2out of date
 candle-onnx^0.90.10.2out of date
 half^2.42.7.1up to date
 prost^0.140.14.3up to date

Build dependencies

(9 total, 1 outdated, 1 possibly insecure)

CrateRequiredLatestStatus
 serde^11.0.228up to date
 reqwest^0.130.13.2up to date
 zip>=8.18.5.0up to date
 md-5^0.10.60.11.0out of date
 cargo_metadata^0.230.23.1up to date
 csv^1.41.4.0up to date
 chrono ⚠️^0.40.4.44maybe insecure
 swift-bridge-build^0.10.1.59up to date
 winres^0.10.1.12up to date

Crate chama-optics-macros

Dependencies

(3 total, all up-to-date)

CrateRequiredLatestStatus
 syn^2.02.0.117up to date
 quote^1.01.0.45up to date
 proc-macro2^1.01.0.106up to date

Security Vulnerabilities

chrono: Potential segfault in `localtime_r` invocations

RUSTSEC-2020-0159

Impact

Unix-like operating systems may segfault due to dereferencing a dangling pointer in specific circumstances. This requires an environment variable to be set in a different thread than the affected functions. This may occur without the user's knowledge, notably in a third-party library.

Workarounds

No workarounds are known.

References