NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
crates.io · #2849 most downloaded on crates.io
The simd optimized HTML escaping code
Last release 5 months ago
25 Apr 2026
Ships unpredictably
gaps range from 9 days to 3.7 years
Rarely documented
notes for 7 of 39 stable releases
1 version withdrawn
withdrawn after publishing
8 years old
40 releases · first in 2018
Documentation-only release regenerated on top of v_escape_codegen 0.2.1.
Documentation-only release regenerated on top of v_escape_codegen 0.2.1.
lib.rs with the richer module-level rustdoc (escape table, public API summary, runtime SIMD dispatch notes). The //! autogenerated by v_escape_codegen@… header now reflects the codegen version that produced the file.No behavior change; public functions and feature gates are identical to 0.16.0.
Documentation-only release of the autogenerated escape crates, regenerated
on top of v_escape_codegen 0.2.1:
| Crate | New version | Previous published |
|---|---|---|
v_htmlescape |
0.17.0 | 0.16.0 |
v_jsonescape |
0.9.0 | 0.8.0 |
v_latexescape |
0.16.0 | 0.15.0 |
lib.rs with the richer module-level rustdoc emitted by
v_escape_codegen 0.2.1 (escape table, public API summary, runtime
SIMD dispatch notes). The //! autogenerated by v_escape_codegen@…
header now also reflects the codegen version that produced the file.No behavior change; all public functions and their feature gates are
unchanged. Source-level layout was reflowed by cargo fmt to match what
scripts/generate.sh produces in CI.
One column per quarter.
Documentation-only release regenerated on top of v_escape_codegen 0.2.1.
Documentation-only release regenerated on top of v_escape_codegen 0.2.1.
lib.rs with the richer module-level rustdoc (escape table, public API summary, runtime SIMD dispatch notes). The //! autogenerated by v_escape_codegen@… header now reflects the codegen version that produced the file.No behavior change; public functions and feature gates are identical to 0.15.0.
This is part of a coordinated release that ships the rewritten v_escape workspace and addresses the soundness bug reported in #166. The same set of commits is delivered by every tag pushed in this batch.
| Crate | New version | Previous published |
|---|---|---|
v_escape-base |
0.1.0 | (initial release) |
v_escape-codegen-base |
0.1.0 | (initial release) |
v_escape-proc-macro |
0.1.0 | (initial release) |
v_escape_codegen |
0.1.9 | 0.1.8 |
v_escape |
0.19.0 | 0.18.0 |
v_htmlescape |
0.16.0 | 0.15.8 |
v_jsonescape |
0.8.0 | 0.7.8 |
v_latexescape |
0.15.0 | 0.14.8 |
Fix soundness bug reported in #166: the previously published v_htmlescape <= 0.15.8, v_jsonescape <= 0.7.8 and v_latexescape <= 0.14.8 exposed scalar::_escape(&[u8], _) (and the matching SIMD entry points) as safe functions that called core::str::from_utf8_unchecked on caller-provided bytes, producing UB whenever the input was not valid UTF-8.
The crate has been rewritten so the public escape API only accepts &str. from_utf8_unchecked is now confined to a single internal unsafe fn write_slice in v_escape-base whose callers always start from a &str and only split on ASCII boundaries. The affected published versions will be yanked from crates.io.
The new API is breaking: callers that previously passed &[u8] through scalar::_escape (or any SIMD entry point) must switch to &str input. If you have raw bytes, validate them with std::str::from_utf8 before calling the escape API.
See CHANGELOG.md for the full list of changes, bug fixes, dependency updates and miscellaneous tasks included in this release.
cargo add v_htmlescape@0.16.0This entry covers the coordinated release that ships the rewritten
v_escape workspace. The same set of commits is delivered by every
new tag pushed in this batch:
| Crate | New version | Previous published |
|---|---|---|
v_escape-base |
0.1.0 | (initial release) |
v_escape-codegen-base |
0.1.0 | (initial release) |
v_escape-proc-macro |
0.1.0 | (initial release) |
v_escape_codegen |
0.1.9 | 0.1.8 |
v_escape |
0.19.0 | 0.18.0 |
v_htmlescape |
0.16.0 | 0.15.8 |
v_jsonescape |
0.8.0 | 0.7.8 |
v_latexescape |
0.15.0 | 0.14.8 |
v_htmlescape <= 0.15.8, v_jsonescape <= 0.7.8
and v_latexescape <= 0.14.8 exposed scalar::_escape(&[u8], _) (and the
matching SIMD entry points) as safe functions that called
core::str::from_utf8_unchecked on caller-provided bytes, producing UB
whenever the input was not valid UTF-8. The crate has been rewritten so
the public escape API only accepts &str; from_utf8_unchecked is now
confined to a single internal unsafe fn write_slice in v_escape-base
whose callers always start from a &str and only split on ASCII
boundaries. The affected published versions will be yanked from
crates.io.This reverts commit e321ca96e48b2b01784a911964291f138cd568cc.
This reverts commit 24348f30e0bb029f045b6930b347c68c42b1a048.
This reverts commit 0d6f0f8f8e7b200e0768dfd1617a4c6c6bfce505.
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
This is part of a coordinated release that ships the rewritten v_escape workspace and addresses the soundness bug reported in #166 . The same set of c
This is part of a coordinated release that ships the rewritten v_escape workspace and addresses the soundness bug reported in #166. The same set of commits is delivered by every tag pushed in this batch.
| Crate | New version | Previous published |
|---|---|---|
v_escape-base |
0.1.0 | (initial release) |
v_escape-codegen-base |
0.1.0 | (initial release) |
v_escape-proc-macro |
0.1.0 | (initial release) |
v_escape_codegen |
0.1.9 | 0.1.8 |
v_escape |
0.19.0 | 0.18.0 |
v_htmlescape |
0.16.0 | 0.15.8 |
v_jsonescape |
0.8.0 | 0.7.8 |
v_latexescape |
0.15.0 | 0.14.8 |
Fix soundness bug reported in #166: the previously published v_htmlescape <= 0.15.8, v_jsonescape <= 0.7.8 and v_latexescape <= 0.14.8 exposed scalar::_escape(&[u8], _) (and the matching SIMD entry points) as safe functions that called core::str::from_utf8_unchecked on caller-provided bytes, producing UB whenever the input was not valid UTF-8.
The crate has been rewritten so the public escape API only accepts &str. from_utf8_unchecked is now confined to a single internal unsafe fn write_slice in v_escape-base whose callers always start from a &str and only split on ASCII boundaries. The affected published versions will be yanked from crates.io.
The new API is breaking: callers that previously passed &[u8] through scalar::_escape (or any SIMD entry point) must switch to &str input. If you have raw bytes, validate them with std::str::from_utf8 before calling the escape API.
See CHANGELOG.md for the full list of changes, bug fixes, dependency updates and miscellaneous tasks included in this release.
cargo add v_latexescape@0.15.0Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Documentation-only release regenerated on top of v_escape_codegen 0.2.1.
Documentation-only release regenerated on top of v_escape_codegen 0.2.1.
lib.rs with the richer module-level rustdoc (escape table, public API summary, runtime SIMD dispatch notes). The //! autogenerated by v_escape_codegen@… header now reflects the codegen version that produced the file.No behavior change; public functions and feature gates are identical to 0.8.0.
This is part of a coordinated release that ships the rewritten v_escape workspace and addresses the soundness bug reported in #166 . The same set of c
This is part of a coordinated release that ships the rewritten v_escape workspace and addresses the soundness bug reported in #166. The same set of commits is delivered by every tag pushed in this batch.
| Crate | New version | Previous published |
|---|---|---|
v_escape-base |
0.1.0 | (initial release) |
v_escape-codegen-base |
0.1.0 | (initial release) |
v_escape-proc-macro |
0.1.0 | (initial release) |
v_escape_codegen |
0.1.9 | 0.1.8 |
v_escape |
0.19.0 | 0.18.0 |
v_htmlescape |
0.16.0 | 0.15.8 |
v_jsonescape |
0.8.0 | 0.7.8 |
v_latexescape |
0.15.0 | 0.14.8 |
Fix soundness bug reported in #166: the previously published v_htmlescape <= 0.15.8, v_jsonescape <= 0.7.8 and v_latexescape <= 0.14.8 exposed scalar::_escape(&[u8], _) (and the matching SIMD entry points) as safe functions that called core::str::from_utf8_unchecked on caller-provided bytes, producing UB whenever the input was not valid UTF-8.
The crate has been rewritten so the public escape API only accepts &str. from_utf8_unchecked is now confined to a single internal unsafe fn write_slice in v_escape-base whose callers always start from a &str and only split on ASCII boundaries. The affected published versions will be yanked from crates.io.
The new API is breaking: callers that previously passed &[u8] through scalar::_escape (or any SIMD entry point) must switch to &str input. If you have raw bytes, validate them with std::str::from_utf8 before calling the escape API.
See CHANGELOG.md for the full list of changes, bug fixes, dependency updates and miscellaneous tasks included in this release.
cargo add v_jsonescape@0.8.0Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
### Miscellaneous Tasks - (cargo-release) version 0.1.2 - (cargo-release) version 0.15.2 - (cargo-release) version 0.7.2 - (cargo-release) version 0.1
Fix bad function rocket sizing at benches
as_mutBytesMut in favor of buf-min::Buffer traitnew_escape to newUpdates the requirements on cfg-if to permit the latest version.
Signed-off-by: dependabot-preview[bot] support@dependabot.com
Updates the requirements on bytes to permit the latest version.
Signed-off-by: dependabot-preview[bot] support@dependabot.com
buf-min dependencyRelease v_escape-proc-macro 0.1.0
This is part of a coordinated release that ships the rewritten v_escape workspace and addresses the soundness bug reported in #166. The same set of commits is delivered by every tag pushed in this batch.
| Crate | New version | Previous published |
|---|---|---|
v_escape-base |
0.1.0 | (initial release) |
v_escape-codegen-base |
0.1.0 | (initial release) |
v_escape-proc-macro |
0.1.0 | (initial release) |
v_escape_codegen |
0.1.9 | 0.1.8 |
v_escape |
0.19.0 | 0.18.0 |
v_htmlescape |
0.16.0 | 0.15.8 |
v_jsonescape |
0.8.0 | 0.7.8 |
v_latexescape |
0.15.0 | 0.14.8 |
Fix soundness bug reported in #166: the previously published v_htmlescape <= 0.15.8, v_jsonescape <= 0.7.8 and v_latexescape <= 0.14.8 exposed scalar::_escape(&[u8], _) (and the matching SIMD entry points) as safe functions that called core::str::from_utf8_unchecked on caller-provided bytes, producing UB whenever the input was not valid UTF-8.
The crate has been rewritten so the public escape API only accepts &str. from_utf8_unchecked is now confined to a single internal unsafe fn write_slice in v_escape-base whose callers always start from a &str and only split on ASCII boundaries. The affected published versions will be yanked from crates.io.
The new API is breaking: callers that previously passed &[u8] through scalar::_escape (or any SIMD entry point) must switch to &str input. If you have raw bytes, validate them with std::str::from_utf8 before calling the escape API.
See CHANGELOG.md for the full list of changes, bug fixes, dependency updates and miscellaneous tasks included in this release.
cargo add v_escape-proc-macro@0.1.0Your coding agent can read these notes before it upgrades. Set up the MCP server →