This project contains known security vulnerabilities. Find detailed information at the bottom.

Crate rust-service-template

Dependencies

(22 total, 6 outdated, 1 insecure)

CrateRequiredLatestStatus
 color-eyre^0.60.6.5up to date
 console-subscriber^0.10.5.0out of date
 criterion^0.30.8.2out of date
 eyre^0.60.6.14up to date
 futures^0.30.3.34up to date
 hyper^0.14.171.12.0out of date
 itertools^0.100.15.0out of date
 mimalloc^0.10.1.52up to date
 once_cell^1.81.21.4up to date
 prometheus^0.130.14.0out of date
 proptest^1.01.12.0up to date
 serde^1.01.0.229up to date
 serde_json^1.01.0.152up to date
 smallvec^1.6.11.16.3up to date
 structopt^0.30.3.26up to date
 thiserror^1.02.0.21out of date
 tokio^1.171.53.2up to date
 tracing^0.10.1.44up to date
 tracing-futures^0.20.2.5up to date
 tracing-subscriber^0.30.3.23up to date
 url^2.22.5.8up to date
 users ⚠️^0.110.11.0insecure

Dev dependencies

(3 total, all up-to-date)

CrateRequiredLatestStatus
 pretty_assertions^1.01.4.1up to date
 proptest^1.01.12.0up to date
 tracing-test^0.20.2.6up to date

Build dependencies

(2 total, all up-to-date)

CrateRequiredLatestStatus
 eyre^0.60.6.14up to date
 time^0.3.50.3.55up to date

Security Vulnerabilities

users: `root` appended to group listings

RUSTSEC-2025-0040

Affected versions append root to group listings, unless the correct listing has exactly 1024 groups.

This affects both:

  • The supplementary groups of a user
  • The group access list of the current process

If the caller uses this information for access control, this may lead to privilege escalation.

This crate is not currently maintained, so a patched version is not available.

Versions older than 0.8.0 do not contain the affected functions, so downgrading to them is a workaround.

Recommended alternatives

  • uzers (an actively maintained fork of the users crate)
  • sysinfo