This project contains known security vulnerabilities . Find detailed information at the bottom .
Crate greenglas Dependencies (3 total, 1 outdated)
Crate coaster Dependencies (7 total, 2 outdated)
Dev dependencies (1 total, all up-to-date)
Crate Required Latest Status trybuild ^1.01.0.122up to date
Crate coaster-nn Dependencies (5 total, 3 outdated)
Crate Required Latest Status libc ^0.20.2.190up to date log ^0.40.4.34up to date rand ^0.80.10.3out of date rand_chacha ^0.3.00.10.0out of date thiserror ^1.02.0.21out of date
Dev dependencies (2 total, 1 outdated)
Crate Required Latest Status env_logger ^0.90.11.11out of date num ^0.40.4.3up to date
Crate coaster-blas Dependencies (1 total, all up-to-date)
Crate Required Latest Status log ^0.40.4.34up to date
Crate juice Dependencies (5 total, 2 outdated, 1 insecure)
Crate Required Latest Status log ^0.40.4.34up to date rand ^0.80.10.3out of date num ^0.40.4.3up to date capnp ⚠️ ^0.140.27.2insecure timeit ^0.10.1.2up to date
Dev dependencies (1 total, 1 outdated)
Crate Required Latest Status env_logger ^0.90.11.11out of date
Build dependencies (1 total, 1 outdated)
Crate Required Latest Status capnpc ^0.140.27.0out of date
Crate rust-blas Dependencies (3 total, all up-to-date)
Crate Required Latest Status num ^0.40.4.3up to date num-complex ^0.40.4.6up to date libc ^0.20.2.190up to date
Build dependencies (1 total, all up-to-date)
Crate Required Latest Status pkg-config ^0.30.3.34up to date
Crate rcudnn Dependencies (3 total, 1 outdated)
Crate Required Latest Status libc ^0.20.2.190up to date num ^0.40.4.3up to date thiserror ^1.02.0.21out of date
Dev dependencies (2 total, 1 outdated)
Crate Required Latest Status env_logger ^0.90.11.11out of date log ^0.40.4.34up to date
Crate rcudnn-sys Dependencies (1 total, all up-to-date)
Crate Required Latest Status libc ^0.20.2.190up to date
Build dependencies (2 total, 1 outdated)
Crate Required Latest Status pkg-config ^0.30.3.34up to date bindgen ^0.60.10.73.2out of date
Crate rcublas Dependencies (4 total, 1 outdated)
Crate Required Latest Status libc ^0.20.2.190up to date lazy_static ^11.5.1up to date log ^0.40.4.34up to date thiserror ^1.02.0.21out of date
Dev dependencies (1 total, 1 outdated)
Crate Required Latest Status env_logger ^0.90.11.11out of date
Crate rcublas-sys Dependencies (1 total, all up-to-date)
Crate Required Latest Status libc ^0.20.2.190up to date
Build dependencies (2 total, 1 outdated)
Crate Required Latest Status pkg-config ^0.30.3.34up to date bindgen ^0.60.10.73.2out of date
Crate juice-utils Dependencies (4 total, 2 outdated)
Crate Required Latest Status reqwest ^0.110.13.5out of date flate2 ^11.1.10up to date fs-err ^23.3.2out of date log ^0.40.4.34up to date
Crate example-rnn-regression Dependencies (6 total, 2 outdated)
Crate Required Latest Status csv ^1.11.4.0up to date serde ^11.0.229up to date env_logger ^0.90.11.11out of date log ^0.40.4.34up to date docopt ^1.11.1.1up to date fs-err ^23.3.2out of date
Crate example-mnist-classification Dependencies (13 total, 4 outdated)
Security Vulnerabilities capnp: Unsound APIs of public `constant::Reader` and `StructSchema`RUSTSEC-2025-0143
The safe API functions constant::Reader::get and StructSchema::new rely on PointerReader::get_root_unchecked, which can cause undefined behavior (UB) by constructing arbitrary words or schemas.
Reader::get
pub fn get(&self) -> Result<<T as Owned>::Reader<'static>> {
// ...
// UNSAFE: access `words` without validation
}
StructSchema::new
pub fn new(builder: RawBrandedStructSchema) -> StructSchema {
// ...
// UNSAFE: access encoded nodes without validation
}
This vulnerability allows safe Rust code to trigger UB, which violates Rust's safety guarantees.
The issue is resolved in version 0.24.0 by making constructor functions unsafe and mark the fields of struct as visible only in the crate.