advisory-db
Security advisory database for Rust crates published through crates.io (by rustsec)
vulndb
[mirror] The Go Vulnerability Database (by golang)
Our great sponsors
advisory-db | vulndb | |
---|---|---|
37 | 3 | |
829 | 537 | |
2.2% | 2.0% | |
9.2 | 9.7 | |
8 days ago | 6 days ago | |
Go | ||
GNU General Public License v3.0 or later | GNU General Public License v3.0 or later |
The number of mentions indicates the total number of mentions that we've tracked plus the number of user suggested alternatives.
Stars - the number of stars that a project has on GitHub. Growth - month over month growth in stars.
Activity is a relative number indicating how actively a project is being developed. Recent commits have higher weight than older ones.
For example, an activity of 9.0 indicates that a project is amongst the top 10% of the most actively developed projects that we are tracking.
Stars - the number of stars that a project has on GitHub. Growth - month over month growth in stars.
Activity is a relative number indicating how actively a project is being developed. Recent commits have higher weight than older ones.
For example, an activity of 9.0 indicates that a project is amongst the top 10% of the most actively developed projects that we are tracking.
advisory-db
Posts with mentions or reviews of advisory-db.
We have used some of these posts to build our list of alternatives
and similar projects. The last one was on 2024-03-26.
- Serde-YAML for Rust has been archived
- When Zig is safer and faster than Rust
-
Advisory: Miscompilation in cortex-m-rt 0.7.1 and 0.7.2
You might also want to add this to https://github.com/rustsec/advisory-db so that cargo audit and Dependabot surface it.
-
greater supply chain attack risk due to large dependency trees?
cargo-audit only checks for known issues reported to a vulnerability database.
- capnproto-rust: out-of-bound memory access bug
-
`cargo audit` can now scan compiled binaries
However, I keep getting this error when running cargo audit bin ~/.cargo/bin/*, even if I replace * with a specific binary: Fetching advisory database from `https://github.com/RustSec/advisory-db.git` Loaded 467 security advisories (from C:\Users\jonah\.cargo\advisory-db) Updating crates.io index error: I/O operation failed: The system cannot find the path specified. (os error 3) I'm on Windows 10.
-
Github Dependency graph adds vulnerability alerting support for Rust
FWIW the RustSec database is still not synced into the Github databse on a regular basis, even though they did an initial import of it. So the cargo audit github action is still relevant.
-
Hey Rustaceans! Got a question? Ask here! (18/2022)!
Removing prior log directory: ./target/cargo-checkmate/logs running 7 cargo-checkmate phases cargo-checkmate check... ok. cargo-checkmate format... ok. cargo-checkmate clippy... ok. cargo-checkmate build... ok. cargo-checkmate test... ok. cargo-checkmate doc... ok. cargo-checkmate audit... FAILED. failures: ---- cargo-checkmate audit ---- + ./target/cargo-checkmate/logs/audit.stdout: | Fetching advisory database from `https://github.com/RustSec/advisory-db.git` + ./target/cargo-checkmate/logs/audit.stderr: | thread 'main' panicked at 'called `Option::unwrap()` on a `None` value', /home/finn/.cargo/registry/src/github.com-1ecc6299db9ec823/cargo-checkmate-0.1.11/src/subcommands.rs:63:42 | note: run with `RUST_BACKTRACE=1` environment variable to display a backtrace cargo-checkmate result: FAILED. 6 passed; 1 failed
-
Rust code quality and vulnerability scan tool
If that were true then https://github.com/RustSec/advisory-db/ would not exist.
-
Announcing s2n-quic 1.0
You are correct. Definitely not to pick on the other implementations but through casual testing we've seen all of them panic on messages received over the wire. I don't think any of them have disclosure policies in place and/or there was no advisory issued.
vulndb
Posts with mentions or reviews of vulndb.
We have used some of these posts to build our list of alternatives
and similar projects. The last one was on 2021-07-22.
-
What is the equivalent of "npm audit" in go?
An official vulnerability database for exactly that is in the making: https://go.googlesource.com/proposal/+/master/design/draft-vulndb.md https://github.com/golang/vulndb
-
Google's unified vulnerability schema for open source supports Rust on launch
Today, we’re excited to announce a new milestone in expanding OSV to several key open-source ecosystems: Go, Rust, Python, and DWF.
What are some alternatives?
When comparing advisory-db and vulndb you can also consider the following projects:
nancy - A tool to check for vulnerabilities in your Golang dependencies, powered by Sonatype OSS Index
rustsec - RustSec API & Tooling
cargo-deny - ❌ Cargo plugin for linting your dependencies 🦀
chrono - Date and time library for Rust
dwflist - The DWF IDs
Rudra - Rust Memory Safety & Undefined Behavior Detection
treediff-rs - Extract differences between arbitrary datastructures
similar - A high level diffing library for rust based on diffs
advisory-database - Advisory database for Python packages published on pypi.org
project-safe-transmute - Project group working on the "safe transmute" feature
advisory-db - Security advisory database for Rust crates published through crates.io