Skip to content

Update Rust crate serde_json to v1.0.123 #230

Update Rust crate serde_json to v1.0.123

Update Rust crate serde_json to v1.0.123 #230

GitHub Actions / Security audit failed Aug 11, 2024 in 0s

Security advisories found

1 advisory(ies), 2 unmaintained

Details

Vulnerabilities

RUSTSEC-2024-0336

rustls::ConnectionCommon::complete_io could fall into an infinite loop based on network input

Details
Package rustls
Version 0.20.9
URL GHSA-6g7w-8wpp-frhj
Date 2024-04-19
Patched versions >=0.23.5,>=0.22.4, <0.23.0,>=0.21.11, <0.22.0

If a close_notify alert is received during a handshake, complete_io
does not terminate.

Callers which do not call complete_io are not affected.

rustls-tokio and rustls-ffi do not call complete_io
and are not affected.

rustls::Stream and rustls::StreamOwned types use
complete_io and are affected.

Warnings

RUSTSEC-2022-0077

claim is Unmaintained

Details
Status unmaintained
Package claim
Version 0.5.0
URL svartalf/rust-claim#12
Date 2022-12-04

The last release was in February 2021, almost two years ago.

The maintainer has been unresponsive regarding this crate for over a year.

A pending issue with claim's dependencies has made the crate difficult to use.

Possible Alternative(s)

The below list has not been vetted in any way and may or may not contain alternatives;

  • claims, a direct fork of the claim crate

RUSTSEC-2024-0320

yaml-rust is unmaintained.

Details
Status unmaintained
Package yaml-rust
Version 0.4.5
URL rustsec/advisory-db#1921
Date 2024-03-20

The maintainer seems unreachable.

Many issues and pull requests have been submitted over the years
without any response.

Alternatives

Consider switching to the actively maintained yaml-rust2 fork of the original project: