This project might be open to known security vulnerabilities, which can be prevented by tightening the version range of affected dependencies. Find detailed information at the bottom.

Crate rain-sdk

Dependencies

(17 total, 1 outdated, 1 possibly insecure)

CrateRequiredLatestStatus
 reqwest^0.120.13.1out of date
 tokio^1.491.49.0up to date
 serde^1.01.0.228up to date
 serde_json^1.01.0.149up to date
 serde_urlencoded^0.70.7.1up to date
 chrono ⚠️^0.40.4.43maybe insecure
 uuid^1.191.20.0up to date
 anyhow^1.01.0.100up to date
 thiserror^2.02.0.18up to date
 base64^0.220.22.1up to date
 hmac^0.120.12.1up to date
 sha2^0.100.10.9up to date
 url^2.52.5.8up to date
 utoipa^5.4.05.4.0up to date
 utoipa-axum^0.2.00.2.0up to date
 utoipa-config^0.1.20.1.2up to date
 utoipa-gen^5.4.05.4.0up to date

Dev dependencies

(3 total, all up-to-date)

CrateRequiredLatestStatus
 tokio-test^0.40.4.5up to date
 mockito^1.71.7.2up to date
 serde_test^1.01.0.177up to date

Security Vulnerabilities

chrono: Potential segfault in `localtime_r` invocations

RUSTSEC-2020-0159

Impact

Unix-like operating systems may segfault due to dereferencing a dangling pointer in specific circumstances. This requires an environment variable to be set in a different thread than the affected functions. This may occur without the user's knowledge, notably in a third-party library.

Workarounds

No workarounds are known.

References