This project might be open to known security vulnerabilities, which can be prevented by tightening the version range of affected dependencies. Find detailed information at the bottom.

Crate veloren-common

Dependencies

(12 total, 1 outdated)

CrateRequiredLatestStatus
 approx^0.5.10.5.1up to date
 num-derive^0.4.00.4.2up to date
 roots^0.0.80.0.8up to date
 spin_sleep^1.01.2.0up to date
 uuid^1.4.11.8.0up to date
 dot_vox^5.15.1.1up to date
 serde_repr^0.1.60.1.19up to date
 csv^1.1.31.3.0up to date
 petgraph^0.60.6.4up to date
 kiddo^0.24.2.0out of date
 slotmap^1.01.0.7up to date
 indexmap^2.2.22.2.6up to date

Dev dependencies

(3 total, all up-to-date)

CrateRequiredLatestStatus
 criterion^0.5.10.5.1up to date
 tracing-subscriber^0.3.70.3.18up to date
 petgraph^0.6.00.6.4up to date

Crate veloren-common-assets

Dependencies

(3 total, all up-to-date)

CrateRequiredLatestStatus
 assets_manager^0.11.10.11.5up to date
 dot_vox^5.15.1.1up to date
 wavefront^0.20.2.3up to date

Dev dependencies

(1 total, all up-to-date)

CrateRequiredLatestStatus
 walkdir^2.3.22.5.0up to date

Crate veloren-common-i18n

No external dependencies! 🙌

Crate veloren-common-base

Dependencies

(2 total, 1 outdated)

CrateRequiredLatestStatus
 directories-next^2.02.0.0up to date
 profiling=1.0.81.0.15out of date

Crate veloren-common-dynlib

Dependencies

(3 total, all up-to-date)

CrateRequiredLatestStatus
 find_folder^0.3.00.3.0up to date
 libloading^0.80.8.3up to date
 notify^6.1.06.1.1up to date

Crate veloren-common-ecs

Dev dependencies

(1 total, all up-to-date)

CrateRequiredLatestStatus
 float-cmp^0.9.00.9.0up to date

Crate veloren-common-net

Dependencies

(2 total, all up-to-date)

CrateRequiredLatestStatus
 flate2^1.0.201.0.28up to date
 sum_type^0.2.00.2.0up to date

Crate veloren-common-state

Dependencies

(9 total, 2 outdated)

CrateRequiredLatestStatus
 num_cpus^1.01.16.0up to date
 scopeguard^1.1.01.2.0up to date
 toml^0.80.8.12up to date
 tar^0.4.370.4.40up to date
 timer-queue^0.1.00.1.0up to date
 wasmtime^17.0.020.0.0out of date
 wasmtime-wasi^17.0.020.0.0out of date
 bytes^11.6.0up to date
 futures^0.3.300.3.30up to date

Crate veloren-common-systems

No external dependencies! 🙌

Crate veloren-common-frontend

Dependencies

(4 total, 1 outdated)

CrateRequiredLatestStatus
 termcolor^1.11.4.1up to date
 tracing-appender^0.2.00.2.3up to date
 tracing-subscriber^0.3.70.3.18up to date
 tracing-tracy=0.10.20.11.0out of date

Crate veloren-client

Dependencies

(6 total, 1 outdated, 1 possibly insecure)

CrateRequiredLatestStatus
 byteorder^1.3.21.5.0up to date
 quinn^0.100.10.2up to date
 rustls ⚠️^0.21.60.23.5out of date
 hickory-resolver^0.24.00.24.1up to date
 async-channel^2.12.2.1up to date
 rustyline^14.0.014.0.0up to date

Crate veloren-client-i18n

Dependencies

(2 total, all up-to-date)

CrateRequiredLatestStatus
 unic-langid^0.90.9.4up to date
 deunicode^1.01.4.4up to date

Crate veloren-rtsim

Dependencies

(4 total, all up-to-date)

CrateRequiredLatestStatus
 rmp-serde^1.1.01.2.0up to date
 anymap2^0.130.13.0up to date
 atomic_refcell^0.10.1.13up to date
 slotmap^1.0.61.0.7up to date

Crate veloren-server

Dependencies

(13 total, 4 outdated, 1 possibly insecure)

CrateRequiredLatestStatus
 num_cpus^1.01.16.0up to date
 quinn^0.100.10.2up to date
 rustls ⚠️^0.210.23.5out of date
 rustls-pemfile^12.1.2out of date
 atomicwrites^0.40.4.3up to date
 drop_guard^0.3.00.3.0up to date
 humantime^2.1.02.1.0up to date
 parking_lot^0.120.12.2up to date
 noise^0.70.9.0out of date
 censor^0.30.3.0up to date
 rusqlite^0.30.00.31.0out of date
 refinery^0.8.120.8.14up to date
 schnellru^0.2.10.2.1up to date

Crate veloren-server-agent

No external dependencies! 🙌

Crate veloren-server-cli

Dependencies

(8 total, 2 outdated)

CrateRequiredLatestStatus
 num_cpus^1.01.16.0up to date
 cansi^2.2.12.2.1up to date
 crossterm^0.270.27.0up to date
 signal-hook^0.3.60.3.17up to date
 shell-words^1.0.01.1.0up to date
 ratatui^0.26.00.26.2up to date
 axum^0.6.200.7.5out of date
 hyper^0.14.261.3.1out of date

Crate veloren-voxygen

Dependencies

(22 total, 8 outdated)

CrateRequiredLatestStatus
 winit^0.28.60.29.15out of date
 wgpu^0.18.00.19.4out of date
 wgpu-profiler^0.15.00.16.2out of date
 bytemuck^1.71.15.0up to date
 cmake=0.1.450.1.50out of date
 euc^0.5.00.5.3up to date
 glyph_brush^0.7.00.7.8up to date
 egui^0.230.27.2out of date
 egui_winit_platform^0.200.21.0out of date
 levenshtein^1.0.51.0.5up to date
 gilrs^0.10.00.10.6up to date
 assets_manager^0.110.11.5up to date
 backtrace^0.3.400.3.71up to date
 chumsky^0.90.9.3up to date
 directories-next^2.02.0.0up to date
 dot_vox^5.15.1.1up to date
 guillotiere^0.6.20.6.2up to date
 native-dialog^0.6.30.7.0out of date
 rodio^0.170.17.3up to date
 treeculler^0.20.3.0out of date
 num_cpus^1.01.16.0up to date
 discord-sdk^0.3.00.3.6up to date

Dev dependencies

(1 total, all up-to-date)

CrateRequiredLatestStatus
 criterion^0.5.10.5.1up to date

Crate veloren-voxygen-anim

Dependencies

(1 total, all up-to-date)

CrateRequiredLatestStatus
 bytemuck^1.41.15.0up to date

Crate veloren-voxygen-i18n-helpers

No external dependencies! 🙌

Crate veloren-voxygen-egui

Dependencies

(3 total, 3 outdated)

CrateRequiredLatestStatus
 egui^0.230.27.2out of date
 egui_plot^0.230.27.2out of date
 egui_winit_platform^0.200.21.0out of date

Crate veloren-world

Dependencies

(13 total, 3 outdated)

CrateRequiredLatestStatus
 bitvec^1.0.11.0.1up to date
 enumset^1.1.31.1.3up to date
 noise^0.70.9.0out of date
 arr_macro^0.2.10.2.1up to date
 packed_simd^0.3.90.3.9up to date
 kiddo^0.24.2.0out of date
 lz-fear^0.20.2.0up to date
 deflate^1.0.01.0.0up to date
 flate2^1.0.201.0.28up to date
 fallible-iterator^0.3.00.3.0up to date
 rstar^0.100.12.0out of date
 signal-hook^0.3.60.3.17up to date
 indicatif^0.17.80.17.8up to date

Dev dependencies

(6 total, 1 outdated)

CrateRequiredLatestStatus
 criterion^0.5.10.5.1up to date
 csv^1.1.31.3.0up to date
 tracing-subscriber^0.3.70.3.18up to date
 minifb^0.250.25.0up to date
 rusqlite^0.30.00.31.0out of date
 svg_fmt^0.40.4.2up to date

Crate veloren-network

Dependencies

(7 total, 1 outdated, 1 possibly insecure)

CrateRequiredLatestStatus
 socket2^0.5.20.5.6up to date
 tokio-stream^0.1.20.1.15up to date
 async-channel^2.12.2.1up to date
 quinn^0.100.10.2up to date
 rustls ⚠️^0.210.23.5out of date
 lz-fear^0.20.2.0up to date
 bytes^11.6.0up to date

Dev dependencies

(5 total, 1 outdated)

CrateRequiredLatestStatus
 tracing-subscriber^0.3.70.3.18up to date
 shellexpand^3.1.03.1.0up to date
 serde^1.01.0.198up to date
 criterion^0.5.10.5.1up to date
 rcgen^0.120.13.1out of date

Crate veloren-network-protocol

Dependencies

(1 total, all up-to-date)

CrateRequiredLatestStatus
 bytes^11.6.0up to date

Dev dependencies

(2 total, all up-to-date)

CrateRequiredLatestStatus
 async-channel^2.12.2.1up to date
 criterion^0.5.10.5.1up to date

Security Vulnerabilities

rustls: `rustls::ConnectionCommon::complete_io` could fall into an infinite loop based on network input

RUSTSEC-2024-0336

If a close_notify alert is received during a handshake, complete_io does not terminate.

Callers which do not call complete_io are not affected.

rustls-tokio and rustls-ffi do not call complete_io and are not affected.

rustls::Stream and rustls::StreamOwned types use complete_io and are affected.