h2
advisory-database
h2 | advisory-database | |
---|---|---|
8 | 10 | |
1,306 | 1,617 | |
1.0% | 1.4% | |
7.7 | 10.0 | |
9 days ago | about 22 hours ago | |
Rust | ||
MIT License | Creative Commons Attribution 4.0 |
Stars - the number of stars that a project has on GitHub. Growth - month over month growth in stars.
Activity is a relative number indicating how actively a project is being developed. Recent commits have higher weight than older ones.
For example, an activity of 9.0 indicates that a project is amongst the top 10% of the most actively developed projects that we are tracking.
h2
-
Announcing `h2x` A library for building high performance HTTP/2 servers
h2x provides a wrapper around the h2 crate, offering additional functionality and utility functions for working with the HTTP/2 server.
- A CVE has been issued for hyper. Denial of Service possible
-
2022-10-02 gRPC benchmark results
multi-threaded tokio runtime can be harder to scale/higher in minimal overhead if cross thread sync is not handled correctly. In this case the usual suspect is h2 crate. Possible elated issue: https://github.com/hyperium/h2/issues/531
-
Linkerd: Service Mesh Overview
H2 - https://github.com/hyperium/h2
advisory-database
- Request GitHub to build an advisory database for C / C++ packages · Issue #2963 · github/advisory-database
- Extend GitHub's CNA scope to manage CVEs for projects on GitHub
-
A CVE has been issued for hyper. Denial of Service possible
That has since been updated to Moderate: https://github.com/github/advisory-database/commit/aa9e5d5386c5610944edf2b0ee0e4301aabaf1c5
-
CVE-2022-23529 – node-jsonwebtoken
I am trying this on GitHub https://github.com/github/advisory-database/pull/1595
- CVE-2022-23529 - jsonwebtoken has insecure input validation in jwt.verify function - used by over 22,000 projects and downloaded over 36 million times per month on NPM - Exploiting the flaw could enable attackers to bypass authentication mechanisms, access confidential information etc.
-
GitHub’s database of security advisories is now open source
We already have fixed versions (where they exist) - example link below.
On backfilling the data to include advisories from before 2017 - absolutely. So far we've done this in a relatively ad-hoc way - you should already find that the most important (severe and wide-reaching) CVEs from before 2017 are in the database (and if there are any that aren't you think should be we'd love you to open an issue on the DB). We want to do a more complete backfill in the near future.
https://github.com/github/advisory-database/blob/main/adviso...
- GitHub's database of known vulnerabilities is now open source
- Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software
What are some alternatives?
hyper - An HTTP library for Rust
vulndb - [mirror] The Go Vulnerability Database
another-rust-load-balancer - A load balancer with support for different middlewares and load balancing strategies, based on hyper and tokio
elixir-security-advisories - Public database of Elixir security advisories
redis-async-rs - A Rust client for Redis, using Tokio
GHSA-896r-f27r-55mw
sea-orm - 🐚 An async & dynamic ORM for Rust
rustsec - RustSec API & Tooling
tower - async fn(Request) -> Result<Response, Error>
napkin-math - Techniques and numbers for estimating system's performance from first-principles
zero2prod - An implementation of Zero To Production In Rust using Axum instead of Actix