NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
crates.io · #2829 most downloaded on crates.io
Client library for the RustSec security advisory database
Last release 4 months ago
05 Jun 2026
Ships fairly regularly
a new release about every 2 months
Nearly every release is documented
notes for 55 of the last 60 stable releases
8 versions withdrawn
withdrawn after publishing
10 years old
91 releases · first in 2017
Sort paths in lint function by @smoelius in #1544
lint function by @smoelius in #1544malicious as an explicit category by @LawnGnome in #1559One column per quarter.
Nothing published for this version
Nothing published for this version
Nothing published for this version
Upgraded to tame-index v0.18.1 to fix an incompatibility with Rust 1.85 and later ([#1333])
tame-index v0.18.1 to fix an incompatibility with Rust 1.85 and later (#1333)Added public APIs for scanning binary files that were previously private to cargo audit ([#1291])
cargo audit (#1291)Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Upgraded to gix v0.62. This fixes RUSTSEC-2024-0335. It also transitively upgrades to reqwest v0.12 and hyper v1.0. ([#1174])
gix v0.62. This fixes RUSTSEC-2024-0335. It also transitively upgrades to reqwest v0.12 and hyper v1.0. (#1174)Upgraded to gix v0.60. This fixes build issues due to a semver-incompatible change in the interaction of gix and tame-index. ([#1143])
gix v0.60. This fixes build issues due to a semver-incompatible change in the interaction of gix and tame-index. (#1143)Completely rewritten the fix module. ([#1113])
fix module. (#1113)
Cargo.lock as opposed to Cargo.toml, and performs only semver-compatible upgrades.cargo update, migrating away from the unmaintained cargo-edit-9 crate.fix feature is removed and the module is always enabled now that it requires no additional dependencies.tame-index 0.9.3 or later, which fixes issues with some enterprise firewalls. (#1103)Additions to the OSV advisory struct ([#656])
schema_version field to OsvAdvisoryDeserialize implementation for OsvAdvisoryOsvAdvisory contentNothing published for this version
Upgraded dependencies gix to 0.58.x and tame-index to 0.9.x ([#1099])
gix to 0.58.x and tame-index to 0.9.x (#1099)Switched from Git-compatible lockfiles to locks provided by the operating system. This fixes issues around stale lockfiles being left behind on power
CachedIndex now acquires the global Cargo package lock. This was necessary to avoid racing with Cargo when updating crates.io index via Git or writing sparse index entries. Note that this also prevents most Cargo operations for the current user until CachedIndex is dropped. (#1032)gix crate is now used in the max-performance-safe configuration, enabling multi-threading. (#1045)Severity type now implements Hash (#1042)Upgraded to tame-index 0.6.0 and gix 0.53.1 to fix a vulnerability in gix, see RUSTSEC-2023-0064 ([#1015])
tame-index 0.6.0 and gix 0.53.1 to fix a vulnerability in gix, see RUSTSEC-2023-0064 (#1015)No longer require HTTP/2 for accessing sparse crates.io index. This degrades performance somewhat due to an additional roundtrip to crates.io, but all
Sparse crates.io index is now supported. This dramatically speeds up the checks for yanked crates. This crate honors the Cargo settings for the use of
affected field to Warning, to communicate e.g. warnings specific to a particular platform. (#964)license field to the advisory format in preparation for data import from GHSA. (#682)CommitHash type to represent git commit hashes independently from the git implementation used. (#961)fix feature is not yet converted; enabling it will pull in OpenSSL.libgit2 to gitoxide as the git implementation. (#925)crates-index to tame-index for crates.io access. (#923)rustsec::registry::Index because it is impractically slow when the sparse crates.io index is used. Use rustsec::registry::CachedIndex instead. (#923)rustsec::registry::CachedIndex.is_yanked(). Use .find_yanked() instead. Checking a large number of crates at once is orders of magnitude faster when using the sparse index. (#937)From implementations from rustsec::Error to avoid tying rustsec SemVer to that of dependency crates. This should result in less frequent SemVer bumps for rustsec in the future. (#961)rustsec can now be used in Alpine Linux containers (#466).rustsec running in parallel can now fetch Git repositories without races (#490).Nothing published for this version
Upgraded to cargo-lock v9.0.0, which enables support for sparse registries.
cargo-lock v9.0.0, which enables support for sparse registries.Migrated to a maintained fork of cargo-edit v0.9.x to fix [CVE-2023-22742] in the transitive dependency libgit2-sys ([#831])
cargo-edit v0.9.x to fix CVE-2023-22742 in the transitive dependency libgit2-sys (#831)registry::CachedIndex now correctly handles invalid semver versions in crates.io registry, which crates.io allows for some reason ([#762])
registry::CachedIndex now correctly handles invalid semver versions in crates.io registry, which crates.io allows for some reason (#762)registry::CachedIndex which is orders of magnitude faster than registry::Index when scanning multiple Cargo.lock files or binaries ([#730])
registry::CachedIndex which is orders of magnitude faster than registry::Index when scanning multiple Cargo.lock files or binaries (#730)[#642]: https://github.com/RustSec/rustsec/pull/642
withdrawn (#642)[#631]: https://github.com/RustSec/rustsec/pull/631
yanked (#631)doc_cfg annotations when building on docs.rs ([#571])
git2 dependency to v0.14; MSRV 1.57 (#524)platforms dependency to v3.0 (#532)Query::crate_scope() as the Default (#544)cvss dependency to v2.0 (#550)cargo-lock dependency to v8.0 (#561)warnings module; rename WarningKind (#572)advisory::id module; rename IdKind (#573)Bump platforms dependency to v2.0.0 ([#485])
platforms dependency to v2.0.0 (#485)Bump cargo-edit dependency from 0.7.0 to 0.8.0 ([#439])
vendored-libgit2 feature ([#432])
Support ~ and = operators in version specification ([#402])
Do not lint year in CVE IDs ([#393])
Bump cargo-lock to v7.0 ([#379])
### Fixed - Workaround for stale git refs
Rename advisory-db master branch to main
master branch to main### Fixed - Parsing error on Windows
Advisory references as a URL list
references as a URL list[advisory] tablethread-safety categoryreferences field to relatedurl crate to parse metadata URLsmol_str to v0.1.17; MSRV 1.46+chrono with humantimeSystemTime instead of a git::Timestamp typefetch Cargo feature to gitrepository::GitRepository to repository::git::Repositorymarkdown featureNothing published for this version
Disable embedded file timestamps in rust-embed by @kpcyrd in #1554
Refactor Advisory and VulnerabilityInfo
Advisory and VulnerabilityInfolinter: fully deprecate obsolete in favor of yanked
fetch featurecargo-lock to v6; semver to v0.11advisory.title and advisory.description struct fieldsadvisory::parser module as pubcargo-edit to 0.7.0crates-index from 0.15.4 to 0.16.0advisory: laxer function path handlinglinter: fully deprecate obsolete in favor of yankedadvisory: markdown feature and Advisory::description_htmllinter: add support for V3 advisory formatplatforms crate to v1linter: correctly handle crates with dashes in namesadvisory.metadata.title and advisory.metadata.descriptionNothing published for this version
Nothing published for this version
Nothing published for this version
year, month, and day methods to advisory::Date
year, month, and day methods to advisory::Dateunsound informational advisory kindcrates-index from 0.14 to 0.15obsolete advisories to yankedwarning::Kind::Informational to ::Noticewarning::Kind a #[non_exhausive] enumInformational a #[non_exhausive] enumpatched_versions and unaffected_versions### Added - advisory::Id::numerical_part()
advisory::Id::numerical_part()Make WarningInfo into a simple type alias
WarningInfo into a simple type aliasBump dependencies to link libgit2 dynamically
libgit2 dynamicallyWarningInfo and modify Warning structMove yanked crate auditing to cargo-audit
cargo-auditUpdate cargo-lock requirement from 3.0 to 4.0
cargo-lock requirement from 3.0 to 4.0Support crate sources as a vulnerability query attribute
cargo audit fix logic into Fixervendored-openssl feature- Remove support.toml parsing
support.toml parsingversion: Fix matching bug for > version requirements
> version requirementslinter: Add informational as an allowable [advisory] key
informational as an allowable [advisory] keyauthentication moduleUpgrade to cargo-lock crate v3.0
cargo-lock crate v3.0Upgrade to cargo-lock crate v2.0
cargo-lock crate v2.0warning: Extract into module; make more like Vulnerability
Vulnerabilitycvss crate v1.0cargo-lock crate v1.0vulnerability: Add affected_functions()
cargo-lock craterustsec::db module to rustsec::databaseaffected_functions()rustsec::advisory::Linterreport module and built-in report-generatingrust advisory directory from RustSec/advisory-dbsupport.toml for indicating supported versionsrustsec::advisory::Category[affected] and [versions] sectionscvss field with CVSS v3.1 scorehome, remove directories and failureVersion and VersionReq newtypesYour coding agent can read these notes before it upgrades. Set up the MCP server →