Commit Graph

1520 Commits

Author SHA1 Message Date
Alex Gaynor
b426bdf91c Tiny change to try to force github to sign 2021-10-07 10:02:39 -04:00
github-actions[bot]
76105bde90 Assigned RUSTSEC-2020-0158 to slice-deque (#1069)
Co-authored-by: tarcieri <tarcieri@users.noreply.github.com>
2021-10-07 07:38:11 -06:00
Théo Degioanni
377fdd8e59 Report slice-deque as unmaintained (#938) 2021-10-07 07:29:49 -06:00
Alexander Kjäll
bb3e4acd80 add CVE information to RUSTSEC-2021-0080 (#1068) 2021-10-01 23:25:09 +02:00
Alexander Kjäll
b858bec3cc Add CVE information (#1067) 2021-10-01 23:24:38 +02:00
github-actions[bot]
6724be0e29 Assigned RUSTSEC-2021-0119 to nix (#1066)
Co-authored-by: Shnatsel <Shnatsel@users.noreply.github.com>
2021-09-30 19:05:28 +02:00
Geoffrey Thomas
a59b58df71 nix::unistd::getgrouplist buffer overflow (#1060)
* nix::unistd::getgrouplist buffer overflow

* add `unaffected`

* add patched versions

* add affected OSs

* drop severity down to a warning

* note that this requires root to exploit

Co-authored-by: Sergey "Shnatsel" Davidoff <shnatsel@gmail.com>
2021-09-30 19:03:59 +02:00
github-actions[bot]
54d10b4026 Assigned RUSTSEC-2021-0118 to arrow (#1064)
Co-authored-by: Shnatsel <Shnatsel@users.noreply.github.com>
2021-09-29 18:01:48 +02:00
Sergey "Shnatsel" Davidoff
f2e3a65042 Yet another arrow advisory (#1059)
* Create RUSTSEC-0000-0000.md

* remove references to writes
2021-09-29 18:00:36 +02:00
github-actions[bot]
a9bf472713 Assigned RUSTSEC-2021-0117 to arrow (#1063)
Co-authored-by: Shnatsel <Shnatsel@users.noreply.github.com>
2021-09-29 18:00:13 +02:00
Sergey "Shnatsel" Davidoff
edfbe64d47 arrow DecimalArray advisory (#1058)
* Create RUSTSEC-0000-0000.md

* `url` instead of `references`

* remove references to writes
2021-09-29 17:58:28 +02:00
github-actions[bot]
a7d4ec8dd9 Assigned RUSTSEC-2021-0116 to arrow (#1062)
Co-authored-by: Shnatsel <Shnatsel@users.noreply.github.com>
2021-09-29 17:58:13 +02:00
Sergey "Shnatsel" Davidoff
9cc82e1b90 arrow BinaryArray advisory (#1057)
* Create RUSTSEC-0000-0000.md

* reword to also include writes

* remove mentions of writes
2021-09-29 17:46:18 +02:00
teor
a44ad8fae3 Clarify meaning of RUSTSEC-2021-0077.md (#1061)
There appear to be some missing words that create an unintended meaning.
2021-09-28 18:27:47 -04:00
Sergey "Shnatsel" Davidoff
653bd1397c Fix RUSTSEC-2018-0020 GHSA alias (#1056) 2021-09-25 15:47:25 +02:00
github-actions[bot]
b5319a3dba Assigned RUSTSEC-2021-0115 to zeroize_derive (#1055)
Co-authored-by: tarcieri <tarcieri@users.noreply.github.com>
2021-09-24 12:49:25 -06:00
daxpedda
0e04678ad8 #[zeroize(drop)] not working for enums (#1054) 2021-09-24 12:46:12 -06:00
github-actions[bot]
f1fc2c3eb0 Assigned RUSTSEC-2021-0114 to nanorand (#1052)
Co-authored-by: Shnatsel <Shnatsel@users.noreply.github.com>
2021-09-23 22:26:20 +02:00
Cyborus04
a4b1d48e55 nanorand tls_rand aliased mutable references (#1051)
* nanorand `tls_rand` aliased mutable references

* `TlsWyRand`, not `TlsRand`

* Add report title

whoops

* Remove invalid category

* add URL

* "UB" -> "undefined behavior"

Co-authored-by: Sergey "Shnatsel" Davidoff <shnatsel@gmail.com>
2021-09-23 22:25:05 +02:00
github-actions[bot]
d5c7ae1c71 Assigned RUSTSEC-2021-0112 to tectonic_xdv, RUSTSEC-2021-0113 to metrics-util (#1050)
Co-authored-by: Shnatsel <Shnatsel@users.noreply.github.com>
2021-09-18 23:35:48 +02:00
Yechan Bae
bb15a55b43 Add disappeared advisories (#1049) 2021-09-18 23:33:39 +02:00
github-actions[bot]
9fead37879 Assigned RUSTSEC-2021-0111 to tremor-script (#1048)
Co-authored-by: Shnatsel <Shnatsel@users.noreply.github.com>
2021-09-18 20:10:57 +02:00
Matthias Wahl
057094d60e Add advisory for memory corruption in tremor-script < 0.11.6 (#1045)
Signed-off-by: Matthias Wahl <mwahl@wayfair.com>
2021-09-18 20:05:02 +02:00
github-actions[bot]
26d56f7614 Assigned RUSTSEC-2021-0110 to wasmtime (#1047)
Co-authored-by: Shnatsel <Shnatsel@users.noreply.github.com>
2021-09-17 22:55:59 +02:00
Nick Fitzgerald
3d742d4426 Add recent Wasmtime CVEs (#1046)
* Add recent Wasmtime CVEs

* replace URL with references

Co-authored-by: Sergey "Shnatsel" Davidoff <shnatsel@gmail.com>
2021-09-17 22:47:54 +02:00
Sergey "Shnatsel" Davidoff
ab0a84327e Mention OSV in readme (#1043) 2021-09-12 18:03:16 +02:00
Sergey "Shnatsel" Davidoff
6c092fecd4 Switch to rustsec-admin 0.5.2 (OSV 1.0) and branch osv (#1042) 2021-09-12 16:30:20 +02:00
Sergey "Shnatsel" Davidoff
d202965dcb Add GHSA alias to RUSTSEC-2021-0106 (#1039) 2021-09-10 16:11:09 +00:00
Sergey "Shnatsel" Davidoff
b5756eddf9 Add GHSA alias to RUSTSEC-2021-0103 (#1040) 2021-09-10 16:10:58 +00:00
Sergey "Shnatsel" Davidoff
2b1a5c551d Add GHSA alias to RUSTSEC-2021-0105 (#1041) 2021-09-10 16:04:49 +00:00
Sergey "Shnatsel" Davidoff
464cc079a5 Add GHSA alias to RUSTSEC-2020-0156 2021-09-10 16:03:52 +00:00
Sergey "Shnatsel" Davidoff
b99d8a1347 Add GHSA alias to RUSTSEC-2021-0104 (#1038) 2021-09-10 16:01:55 +00:00
github-actions[bot]
8b677b0f9a Assigned RUSTSEC-2021-0109 to ckb (#1035)
Co-authored-by: Shnatsel <Shnatsel@users.noreply.github.com>
2021-09-10 15:58:38 +00:00
Sergey "Shnatsel" Davidoff
204c1ae2c6 add GHSA alias to RUSTSEC-2021-0101 (#1036) 2021-09-10 15:58:27 +00:00
Sergey "Shnatsel" Davidoff
a665da67eb Add GHSA alias to RUSTSEC-2021-0102 2021-09-10 15:58:05 +00:00
Jon Moroney
b838a4c68c Add rustsec advisory for GHSA-45p7-c959-rgcm (#1025)
* Add rustsec advisory for GHSA-45p7-c959-rgcm

* Update RUSTSEC-0000-0000.md

Co-authored-by: Sergey "Shnatsel" Davidoff <shnatsel@gmail.com>
2021-09-10 15:53:59 +00:00
github-actions[bot]
5046464393 Assigned RUSTSEC-2021-0108 to ckb (#1034)
Co-authored-by: Shnatsel <Shnatsel@users.noreply.github.com>
2021-09-10 15:52:06 +00:00
Jon Moroney
ef8532be92 Add rustsec advisory for GHSA-48vq-8jqv-gm6f (#1024)
* Add rustsec advisory for GHSA-48vq-8jqv-gm6f

* Update RUSTSEC-0000-0000.md

Co-authored-by: Sergey "Shnatsel" Davidoff <shnatsel@gmail.com>
2021-09-10 15:50:49 +00:00
github-actions[bot]
315a5c0609 Assigned RUSTSEC-2020-0157 to vm-memory, RUSTSEC-2021-0107 to ckb (#1033)
Co-authored-by: Shnatsel <Shnatsel@users.noreply.github.com>
2021-09-10 15:50:27 +00:00
Jon Moroney
f969fe8995 Add rustsec advisory for GHSA-mm4m-qg48-f7wc (#1018)
* Add rustsec advisory for GHSA-mm4m-qg48-f7wc

* Add GHSA to aliases

Co-authored-by: Sergey "Shnatsel" Davidoff <shnatsel@gmail.com>
2021-09-10 15:48:48 +00:00
Jon Moroney
181cf280e9 Add rustsec advisory for GHSA-v666-6w97-pcwm (#1015)
* Add rustsec advisory for GHSA-v666-6w97-pcwm

* Update RUSTSEC-0000-0000.md

Co-authored-by: Sergey "Shnatsel" Davidoff <shnatsel@gmail.com>
2021-09-10 15:47:22 +00:00
github-actions[bot]
ec858f80ef Assigned RUSTSEC-2021-0106 to bat (#1032)
Co-authored-by: alex <alex@users.noreply.github.com>
2021-09-09 18:41:38 -04:00
Jon Moroney
10fa105f05 Add rustsec advisory for GHSA-p24j-h477-76q3 (#1017)
* Add rustsec advisory for GHSA-p24j-h477-76q3

* Update crates/bat/RUSTSEC-0000-0000.md

Co-authored-by: Alex Gaynor <alex.gaynor@gmail.com>

* Update RUSTSEC-0000-0000.md

Capitalize `windows` to conform with https://docs.rs/platforms/1.1.0/platforms/target/enum.OS.html

* Update RUSTSEC-0000-0000.md

Add [affected] section

Co-authored-by: Alex Gaynor <alex.gaynor@gmail.com>
2021-09-09 18:40:15 -04:00
github-actions[bot]
fe4e45e52f Assigned RUSTSEC-2021-0105 to git-delta (#1031)
Co-authored-by: alex <alex@users.noreply.github.com>
2021-09-09 18:40:10 -04:00
Jon Moroney
fa5597ee92 Add rustsec advisory for GHSA-5xg3-j2j6-rcx4 (#1023)
* Add rustsec advisory for GHSA-5xg3-j2j6-rcx4

* Update RUSTSEC-0000-0000.md

Add [affected] section
2021-09-09 18:38:41 -04:00
github-actions[bot]
71f18afd3b Assigned RUSTSEC-2020-0156 to libsecp256k1-rs (#1030)
Co-authored-by: alex <alex@users.noreply.github.com>
2021-09-09 17:53:06 -04:00
Jon Moroney
e5b66bfe9e Add rustsec advisory for GHSA-7cqg-8449-rmfv (#1022) 2021-09-09 17:51:48 -04:00
github-actions[bot]
4b4a4d8d88 Assigned RUSTSEC-2021-0104 to pleaser (#1029)
Co-authored-by: alex <alex@users.noreply.github.com>
2021-09-09 17:51:08 -04:00
Jon Moroney
951070000d Add rustsec advisory for GHSA-f3fg-5j9p-vchc (#1020) 2021-09-09 17:49:39 -04:00
github-actions[bot]
8e5d566ef0 Assigned RUSTSEC-2021-0103 to molecule (#1028)
Co-authored-by: alex <alex@users.noreply.github.com>
2021-09-09 17:49:20 -04:00