Bug 1883706: part 3) Implement `createHTML`, `createScript` and `createScriptURL...
[gecko.git] / supply-chain / imports.lock
blob5913bc8915a334de7e1481f89fef224fef9aec0c
2 # cargo-vet imports lock
4 [[publisher.aho-corasick]]
5 version = "1.1.0"
6 when = "2023-09-18"
7 user-id = 189
8 user-login = "BurntSushi"
9 user-name = "Andrew Gallant"
11 [[publisher.anstyle]]
12 version = "1.0.3"
13 when = "2023-09-11"
14 user-id = 6743
15 user-login = "epage"
16 user-name = "Ed Page"
18 [[publisher.arbitrary]]
19 version = "1.3.0"
20 when = "2023-03-13"
21 user-id = 696
22 user-login = "fitzgen"
23 user-name = "Nick Fitzgerald"
25 [[publisher.async-trait]]
26 version = "0.1.68"
27 when = "2023-03-24"
28 user-id = 3618
29 user-login = "dtolnay"
30 user-name = "David Tolnay"
32 [[publisher.atomic]]
33 version = "0.4.6"
34 when = "2020-07-05"
35 user-id = 2915
36 user-login = "Amanieu"
37 user-name = "Amanieu d'Antras"
39 [[publisher.audio_thread_priority]]
40 version = "0.31.0"
41 when = "2024-01-17"
42 user-id = 1258
43 user-login = "padenot"
44 user-name = "Paul Adenot"
46 [[publisher.authenticator]]
47 version = "0.4.0-alpha.24"
48 when = "2023-11-29"
49 user-id = 175410
50 user-login = "jschanck"
51 user-name = "John Schanck"
53 [[publisher.bhttp]]
54 version = "0.3.1"
55 when = "2023-02-23"
56 user-id = 128763
57 user-login = "martinthomson"
58 user-name = "Martin Thomson"
60 [[publisher.byteorder]]
61 version = "1.4.3"
62 when = "2021-03-10"
63 user-id = 189
64 user-login = "BurntSushi"
65 user-name = "Andrew Gallant"
67 [[publisher.bytes]]
68 version = "1.4.0"
69 when = "2023-01-31"
70 user-id = 6741
71 user-login = "Darksonn"
72 user-name = "Alice Ryhl"
74 [[publisher.cc]]
75 version = "1.0.89"
76 when = "2024-03-04"
77 user-id = 2915
78 user-login = "Amanieu"
79 user-name = "Amanieu d'Antras"
81 [[publisher.cexpr]]
82 version = "0.6.0"
83 when = "2021-10-11"
84 user-id = 3788
85 user-login = "emilio"
86 user-name = "Emilio Cobos Álvarez"
88 [[publisher.clap]]
89 version = "4.4.5"
90 when = "2023-09-25"
91 user-id = 6743
92 user-login = "epage"
93 user-name = "Ed Page"
95 [[publisher.clap_builder]]
96 version = "4.4.5"
97 when = "2023-09-25"
98 user-id = 6743
99 user-login = "epage"
100 user-name = "Ed Page"
102 [[publisher.clap_derive]]
103 version = "4.4.2"
104 when = "2023-08-31"
105 user-id = 6743
106 user-login = "epage"
107 user-name = "Ed Page"
109 [[publisher.clap_lex]]
110 version = "0.5.1"
111 when = "2023-08-24"
112 user-id = 6743
113 user-login = "epage"
114 user-name = "Ed Page"
116 [[publisher.core-foundation]]
117 version = "0.9.3"
118 when = "2022-02-07"
119 user-id = 5946
120 user-login = "jrmuizel"
121 user-name = "Jeff Muizelaar"
123 [[publisher.core-foundation-sys]]
124 version = "0.8.3"
125 when = "2021-10-12"
126 user-id = 2396
127 user-login = "jdm"
128 user-name = "Josh Matthews"
130 [[publisher.core-graphics]]
131 version = "0.22.3"
132 when = "2021-11-02"
133 user-id = 5946
134 user-login = "jrmuizel"
135 user-name = "Jeff Muizelaar"
137 [[publisher.core-graphics-types]]
138 version = "0.1.1"
139 when = "2020-09-15"
140 user-id = 2396
141 user-login = "jdm"
142 user-name = "Josh Matthews"
144 [[publisher.core-text]]
145 version = "19.2.0"
146 when = "2021-02-14"
147 user-id = 5946
148 user-login = "jrmuizel"
149 user-name = "Jeff Muizelaar"
151 [[publisher.derive_arbitrary]]
152 version = "1.3.0"
153 when = "2023-03-13"
154 user-id = 696
155 user-login = "fitzgen"
156 user-name = "Nick Fitzgerald"
158 [[publisher.dogear]]
159 version = "0.4.0"
160 when = "2019-09-16"
161 user-id = 27901
162 user-login = "linabutler"
163 user-name = "Lina Butler"
165 [[publisher.dtoa]]
166 version = "0.4.8"
167 when = "2021-03-29"
168 user-id = 3618
169 user-login = "dtolnay"
170 user-name = "David Tolnay"
172 [[publisher.encoding_rs]]
173 version = "0.8.33"
174 when = "2023-08-23"
175 user-id = 4484
176 user-login = "hsivonen"
177 user-name = "Henri Sivonen"
179 [[publisher.errno]]
180 version = "0.3.8"
181 when = "2023-11-28"
182 user-id = 6825
183 user-login = "sunfishcode"
184 user-name = "Dan Gohman"
186 [[publisher.etagere]]
187 version = "0.2.7"
188 when = "2022-05-04"
189 user-id = 1281
190 user-login = "nical"
191 user-name = "Nicolas Silva"
193 [[publisher.euclid]]
194 version = "0.22.7"
195 when = "2022-04-04"
196 user-id = 1281
197 user-login = "nical"
198 user-name = "Nicolas Silva"
200 [[publisher.flate2]]
201 version = "1.0.26"
202 when = "2023-04-28"
203 user-id = 4333
204 user-login = "joshtriplett"
205 user-name = "Josh Triplett"
207 [[publisher.freetype]]
208 version = "0.7.0"
209 when = "2020-07-14"
210 user-id = 2396
211 user-login = "jdm"
212 user-name = "Josh Matthews"
214 [[publisher.gleam]]
215 version = "0.15.0"
216 when = "2023-04-21"
217 user-id = 5946
218 user-login = "jrmuizel"
219 user-name = "Jeff Muizelaar"
221 [[publisher.glean]]
222 version = "58.1.0"
223 when = "2024-03-12"
224 user-id = 48
225 user-login = "badboy"
226 user-name = "Jan-Erik Rediger"
228 [[publisher.glean-core]]
229 version = "58.1.0"
230 when = "2024-03-12"
231 user-id = 48
232 user-login = "badboy"
233 user-name = "Jan-Erik Rediger"
235 [[publisher.glslopt]]
236 version = "0.1.10"
237 when = "2024-02-13"
238 user-id = 84794
239 user-login = "jamienicol"
240 user-name = "Jamie Nicol"
242 [[publisher.h2]]
243 version = "0.3.22"
244 when = "2023-11-15"
245 user-id = 359
246 user-login = "seanmonstar"
247 user-name = "Sean McArthur"
249 [[publisher.headers]]
250 version = "0.3.9"
251 when = "2023-08-31"
252 user-id = 359
253 user-login = "seanmonstar"
254 user-name = "Sean McArthur"
256 [[publisher.httparse]]
257 version = "1.8.0"
258 when = "2022-08-30"
259 user-id = 359
260 user-login = "seanmonstar"
261 user-name = "Sean McArthur"
263 [[publisher.indexmap]]
264 version = "1.9.3"
265 when = "2023-03-24"
266 user-id = 539
267 user-login = "cuviper"
268 user-name = "Josh Stone"
270 [[publisher.inherent]]
271 version = "1.0.7"
272 when = "2023-03-25"
273 user-id = 3618
274 user-login = "dtolnay"
275 user-name = "David Tolnay"
277 [[publisher.iovec]]
278 version = "0.1.4"
279 when = "2019-10-09"
280 user-id = 10
281 user-login = "carllerche"
282 user-name = "Carl Lerche"
284 [[publisher.itoa]]
285 version = "1.0.5"
286 when = "2022-12-17"
287 user-id = 3618
288 user-login = "dtolnay"
289 user-name = "David Tolnay"
291 [[publisher.jobserver]]
292 version = "0.1.25"
293 when = "2022-09-23"
294 user-id = 1
295 user-login = "alexcrichton"
296 user-name = "Alex Crichton"
298 [[publisher.libc]]
299 version = "0.2.152"
300 when = "2024-01-07"
301 user-id = 51017
302 user-login = "JohnTitor"
303 user-name = "Yuki Okushi"
305 [[publisher.linux-raw-sys]]
306 version = "0.4.12"
307 when = "2023-11-30"
308 user-id = 6825
309 user-login = "sunfishcode"
310 user-name = "Dan Gohman"
312 [[publisher.lock_api]]
313 version = "0.4.9"
314 when = "2022-09-20"
315 user-id = 2915
316 user-login = "Amanieu"
317 user-name = "Amanieu d'Antras"
319 [[publisher.memchr]]
320 version = "2.5.0"
321 when = "2022-04-30"
322 user-id = 189
323 user-login = "BurntSushi"
324 user-name = "Andrew Gallant"
326 [[publisher.mime]]
327 version = "0.3.16"
328 when = "2020-01-07"
329 user-id = 359
330 user-login = "seanmonstar"
331 user-name = "Sean McArthur"
333 [[publisher.mio]]
334 version = "0.6.21"
335 when = "2019-11-27"
336 user-id = 10
337 user-login = "carllerche"
338 user-name = "Carl Lerche"
340 [[publisher.nss-gk-api]]
341 version = "0.3.0"
342 when = "2023-06-14"
343 user-id = 175410
344 user-login = "jschanck"
345 user-name = "John Schanck"
347 [[publisher.num_cpus]]
348 version = "1.15.0"
349 when = "2022-12-20"
350 user-id = 359
351 user-login = "seanmonstar"
352 user-name = "Sean McArthur"
354 [[publisher.ohttp]]
355 version = "0.3.1"
356 when = "2023-02-23"
357 user-id = 128763
358 user-login = "martinthomson"
359 user-name = "Martin Thomson"
361 [[publisher.ordered-float]]
362 version = "3.4.0"
363 when = "2022-11-06"
364 user-id = 2017
365 user-login = "mbrubeck"
366 user-name = "Matt Brubeck"
368 [[publisher.parking_lot]]
369 version = "0.12.1"
370 when = "2022-05-31"
371 user-id = 2915
372 user-login = "Amanieu"
373 user-name = "Amanieu d'Antras"
375 [[publisher.parking_lot_core]]
376 version = "0.9.9"
377 when = "2023-10-17"
378 user-id = 2915
379 user-login = "Amanieu"
380 user-name = "Amanieu d'Antras"
382 [[publisher.paste]]
383 version = "1.0.11"
384 when = "2022-12-17"
385 user-id = 3618
386 user-login = "dtolnay"
387 user-name = "David Tolnay"
389 [[publisher.presser]]
390 version = "0.3.1"
391 when = "2022-10-16"
392 user-id = 52553
393 user-login = "embark-studios"
395 [[publisher.prio]]
396 version = "0.15.3"
397 when = "2023-10-03"
398 user-id = 213776
399 user-login = "divviup-github-automation"
401 [[publisher.proc-macro2]]
402 version = "1.0.74"
403 when = "2024-01-02"
404 user-id = 3618
405 user-login = "dtolnay"
406 user-name = "David Tolnay"
408 [[publisher.qcms]]
409 version = "0.3.0"
410 when = "2024-01-09"
411 user-id = 5946
412 user-login = "jrmuizel"
413 user-name = "Jeff Muizelaar"
415 [[publisher.quote]]
416 version = "1.0.35"
417 when = "2024-01-02"
418 user-id = 3618
419 user-login = "dtolnay"
420 user-name = "David Tolnay"
422 [[publisher.regex]]
423 version = "1.9.4"
424 when = "2023-08-26"
425 user-id = 189
426 user-login = "BurntSushi"
427 user-name = "Andrew Gallant"
429 [[publisher.regex-automata]]
430 version = "0.3.7"
431 when = "2023-08-26"
432 user-id = 189
433 user-login = "BurntSushi"
434 user-name = "Andrew Gallant"
436 [[publisher.regex-syntax]]
437 version = "0.7.5"
438 when = "2023-08-26"
439 user-id = 189
440 user-login = "BurntSushi"
441 user-name = "Andrew Gallant"
443 [[publisher.rust_cascade]]
444 version = "1.5.0"
445 when = "2023-04-05"
446 user-id = 57462
447 user-login = "mozkeeler"
448 user-name = "Dana Keeler"
450 [[publisher.rustix]]
451 version = "0.38.28"
452 when = "2023-12-09"
453 user-id = 6825
454 user-login = "sunfishcode"
455 user-name = "Dan Gohman"
457 [[publisher.ryu]]
458 version = "1.0.12"
459 when = "2022-12-17"
460 user-id = 3618
461 user-login = "dtolnay"
462 user-name = "David Tolnay"
464 [[publisher.same-file]]
465 version = "1.0.6"
466 when = "2020-01-11"
467 user-id = 189
468 user-login = "BurntSushi"
469 user-name = "Andrew Gallant"
471 [[publisher.scopeguard]]
472 version = "1.1.0"
473 when = "2020-02-16"
474 user-id = 2915
475 user-login = "Amanieu"
476 user-name = "Amanieu d'Antras"
478 [[publisher.serde]]
479 version = "1.0.197"
480 when = "2024-02-20"
481 user-id = 3618
482 user-login = "dtolnay"
483 user-name = "David Tolnay"
485 [[publisher.serde_bytes]]
486 version = "0.11.9"
487 when = "2023-02-05"
488 user-id = 3618
489 user-login = "dtolnay"
490 user-name = "David Tolnay"
492 [[publisher.serde_derive]]
493 version = "1.0.197"
494 when = "2024-02-20"
495 user-id = 3618
496 user-login = "dtolnay"
497 user-name = "David Tolnay"
499 [[publisher.serde_json]]
500 version = "1.0.93"
501 when = "2023-02-08"
502 user-id = 3618
503 user-login = "dtolnay"
504 user-name = "David Tolnay"
506 [[publisher.serde_repr]]
507 version = "0.1.12"
508 when = "2023-03-18"
509 user-id = 3618
510 user-login = "dtolnay"
511 user-name = "David Tolnay"
513 [[publisher.serde_yaml]]
514 version = "0.8.26"
515 when = "2022-07-16"
516 user-id = 3618
517 user-login = "dtolnay"
518 user-name = "David Tolnay"
520 [[publisher.smallvec]]
521 version = "1.13.1"
522 when = "2024-01-19"
523 user-id = 2017
524 user-login = "mbrubeck"
525 user-name = "Matt Brubeck"
527 [[publisher.syn]]
528 version = "2.0.46"
529 when = "2024-01-02"
530 user-id = 3618
531 user-login = "dtolnay"
532 user-name = "David Tolnay"
534 [[publisher.termcolor]]
535 version = "1.4.1"
536 when = "2024-01-10"
537 user-id = 189
538 user-login = "BurntSushi"
539 user-name = "Andrew Gallant"
541 [[publisher.thiserror]]
542 version = "1.0.57"
543 when = "2024-02-11"
544 user-id = 3618
545 user-login = "dtolnay"
546 user-name = "David Tolnay"
548 [[publisher.thiserror-impl]]
549 version = "1.0.57"
550 when = "2024-02-11"
551 user-id = 3618
552 user-login = "dtolnay"
553 user-name = "David Tolnay"
555 [[publisher.threadbound]]
556 version = "0.1.5"
557 when = "2022-12-17"
558 user-id = 3618
559 user-login = "dtolnay"
560 user-name = "David Tolnay"
562 [[publisher.tokio-util]]
563 version = "0.7.2"
564 when = "2022-05-15"
565 user-id = 6741
566 user-login = "Darksonn"
567 user-name = "Alice Ryhl"
569 [[publisher.toml]]
570 version = "0.5.7"
571 when = "2020-10-11"
572 user-id = 1
573 user-login = "alexcrichton"
574 user-name = "Alex Crichton"
576 [[publisher.unicode-ident]]
577 version = "1.0.6"
578 when = "2022-12-17"
579 user-id = 3618
580 user-login = "dtolnay"
581 user-name = "David Tolnay"
583 [[publisher.unicode-width]]
584 version = "0.1.10"
585 when = "2022-09-13"
586 user-id = 1139
587 user-login = "Manishearth"
588 user-name = "Manish Goregaokar"
590 [[publisher.unicode-xid]]
591 version = "0.2.4"
592 when = "2022-09-15"
593 user-id = 1139
594 user-login = "Manishearth"
595 user-name = "Manish Goregaokar"
597 [[publisher.uniffi]]
598 version = "0.25.3"
599 when = "2023-12-07"
600 user-id = 127697
601 user-login = "bendk"
603 [[publisher.uniffi_bindgen]]
604 version = "0.25.3"
605 when = "2023-12-07"
606 user-id = 127697
607 user-login = "bendk"
609 [[publisher.uniffi_build]]
610 version = "0.25.3"
611 when = "2023-12-07"
612 user-id = 127697
613 user-login = "bendk"
615 [[publisher.uniffi_checksum_derive]]
616 version = "0.25.3"
617 when = "2023-12-07"
618 user-id = 127697
619 user-login = "bendk"
621 [[publisher.uniffi_core]]
622 version = "0.25.3"
623 when = "2023-12-07"
624 user-id = 127697
625 user-login = "bendk"
627 [[publisher.uniffi_macros]]
628 version = "0.25.3"
629 when = "2023-12-07"
630 user-id = 127697
631 user-login = "bendk"
633 [[publisher.uniffi_meta]]
634 version = "0.25.3"
635 when = "2023-12-07"
636 user-id = 127697
637 user-login = "bendk"
639 [[publisher.uniffi_testing]]
640 version = "0.25.3"
641 when = "2023-12-07"
642 user-id = 127697
643 user-login = "bendk"
645 [[publisher.uniffi_udl]]
646 version = "0.25.3"
647 when = "2023-12-07"
648 user-id = 127697
649 user-login = "bendk"
651 [[publisher.utf8_iter]]
652 version = "1.0.3"
653 when = "2022-09-09"
654 user-id = 4484
655 user-login = "hsivonen"
656 user-name = "Henri Sivonen"
658 [[publisher.walkdir]]
659 version = "2.3.2"
660 when = "2021-03-22"
661 user-id = 189
662 user-login = "BurntSushi"
663 user-name = "Andrew Gallant"
665 [[publisher.warp]]
666 version = "0.3.6"
667 when = "2023-09-27"
668 user-id = 359
669 user-login = "seanmonstar"
670 user-name = "Sean McArthur"
672 [[publisher.wasi]]
673 version = "0.11.0+wasi-snapshot-preview1"
674 when = "2022-01-19"
675 user-id = 1
676 user-login = "alexcrichton"
677 user-name = "Alex Crichton"
679 [[publisher.wasm-encoder]]
680 version = "0.40.0"
681 when = "2024-01-24"
682 user-id = 1
683 user-login = "alexcrichton"
684 user-name = "Alex Crichton"
686 [[publisher.wasm-smith]]
687 version = "0.15.0"
688 when = "2024-01-24"
689 user-id = 1
690 user-login = "alexcrichton"
691 user-name = "Alex Crichton"
693 [[publisher.wast]]
694 version = "70.0.1"
695 when = "2024-01-24"
696 user-id = 1
697 user-login = "alexcrichton"
698 user-name = "Alex Crichton"
700 [[publisher.winapi-util]]
701 version = "0.1.5"
702 when = "2020-04-20"
703 user-id = 189
704 user-login = "BurntSushi"
705 user-name = "Andrew Gallant"
707 [[publisher.windows]]
708 version = "0.52.0"
709 when = "2023-11-15"
710 user-id = 64539
711 user-login = "kennykerr"
712 user-name = "Kenny Kerr"
714 [[publisher.windows-core]]
715 version = "0.52.0"
716 when = "2023-11-15"
717 user-id = 64539
718 user-login = "kennykerr"
719 user-name = "Kenny Kerr"
721 [[publisher.windows-sys]]
722 version = "0.52.0"
723 when = "2023-11-15"
724 user-id = 64539
725 user-login = "kennykerr"
726 user-name = "Kenny Kerr"
728 [[publisher.zeitstempel]]
729 version = "0.1.1"
730 when = "2021-03-18"
731 user-id = 48
732 user-login = "badboy"
733 user-name = "Jan-Erik Rediger"
735 [[audits.bytecode-alliance.wildcard-audits.arbitrary]]
736 who = "Nick Fitzgerald <fitzgen@gmail.com>"
737 criteria = "safe-to-deploy"
738 user-id = 696 # Nick Fitzgerald (fitzgen)
739 start = "2020-01-14"
740 end = "2024-04-21"
741 notes = "I am an author of this crate."
743 [[audits.bytecode-alliance.wildcard-audits.derive_arbitrary]]
744 who = "Nick Fitzgerald <fitzgen@gmail.com>"
745 criteria = "safe-to-deploy"
746 user-id = 696 # Nick Fitzgerald (fitzgen)
747 start = "2020-01-14"
748 end = "2024-04-27"
749 notes = "I am an author of this crate"
751 [[audits.bytecode-alliance.wildcard-audits.wasm-encoder]]
752 who = "Alex Crichton <alex@alexcrichton.com>"
753 criteria = "safe-to-deploy"
754 user-id = 1 # Alex Crichton (alexcrichton)
755 start = "2020-12-11"
756 end = "2024-04-14"
757 notes = """
758 This is a Bytecode Alliance authored crate maintained in the `wasm-tools`
759 repository of which I'm one of the primary maintainers and publishers for.
760 I am employed by a member of the Bytecode Alliance and plan to continue doing
761 so and will actively maintain this crate over time.
764 [[audits.bytecode-alliance.wildcard-audits.wasm-smith]]
765 who = "Alex Crichton <alex@alexcrichton.com>"
766 criteria = "safe-to-deploy"
767 user-id = 1 # Alex Crichton (alexcrichton)
768 start = "2020-09-03"
769 end = "2024-04-14"
770 notes = """
771 This is a Bytecode Alliance authored crate maintained in the `wasm-tools`
772 repository of which I'm one of the primary maintainers and publishers for.
773 I am employed by a member of the Bytecode Alliance and plan to continue doing
774 so and will actively maintain this crate over time.
777 [[audits.bytecode-alliance.wildcard-audits.wast]]
778 who = "Alex Crichton <alex@alexcrichton.com>"
779 criteria = "safe-to-deploy"
780 user-id = 1 # Alex Crichton (alexcrichton)
781 start = "2019-10-16"
782 end = "2024-04-14"
783 notes = """
784 This is a Bytecode Alliance authored crate maintained in the `wasm-tools`
785 repository of which I'm one of the primary maintainers and publishers for.
786 I am employed by a member of the Bytecode Alliance and plan to continue doing
787 so and will actively maintain this crate over time.
790 [[audits.bytecode-alliance.audits.adler]]
791 who = "Alex Crichton <alex@alexcrichton.com>"
792 criteria = "safe-to-deploy"
793 version = "1.0.2"
794 notes = "This is a small crate which forbids unsafe code and is a straightforward implementation of the adler hashing algorithm."
796 [[audits.bytecode-alliance.audits.arrayref]]
797 who = "Nick Fitzgerald <fitzgen@gmail.com>"
798 criteria = "safe-to-deploy"
799 version = "0.3.6"
800 notes = """
801 Unsafe code, but its logic looks good to me. Necessary given what it is
802 doing. Well tested, has quickchecks.
805 [[audits.bytecode-alliance.audits.arrayvec]]
806 who = "Nick Fitzgerald <fitzgen@gmail.com>"
807 criteria = "safe-to-deploy"
808 version = "0.7.2"
809 notes = """
810 Well documented invariants, good assertions for those invariants in unsafe code,
811 and tested with MIRI to boot. LGTM.
814 [[audits.bytecode-alliance.audits.base64]]
815 who = "Pat Hickey <phickey@fastly.com>"
816 criteria = "safe-to-deploy"
817 version = "0.21.0"
818 notes = "This crate has no dependencies, no build.rs, and contains no unsafe code."
820 [[audits.bytecode-alliance.audits.bitflags]]
821 who = "Jamey Sharp <jsharp@fastly.com>"
822 criteria = "safe-to-deploy"
823 delta = "2.1.0 -> 2.2.1"
824 notes = """
825 This version adds unsafe impls of traits from the bytemuck crate when built
826 with that library enabled, but I believe the impls satisfy the documented
827 safety requirements for bytemuck. The other changes are minor.
830 [[audits.bytecode-alliance.audits.bitflags]]
831 who = "Alex Crichton <alex@alexcrichton.com>"
832 criteria = "safe-to-deploy"
833 delta = "2.3.2 -> 2.3.3"
834 notes = """
835 Nothing outside the realm of what one would expect from a bitflags generator,
836 all as expected.
839 [[audits.bytecode-alliance.audits.block-buffer]]
840 who = "Benjamin Bouvier <public@benj.me>"
841 criteria = "safe-to-deploy"
842 delta = "0.9.0 -> 0.10.2"
844 [[audits.bytecode-alliance.audits.bumpalo]]
845 who = "Nick Fitzgerald <fitzgen@gmail.com>"
846 criteria = "safe-to-deploy"
847 version = "3.11.1"
848 notes = "I am the author of this crate."
850 [[audits.bytecode-alliance.audits.cargo-platform]]
851 who = "Pat Hickey <phickey@fastly.com>"
852 criteria = "safe-to-deploy"
853 version = "0.1.2"
854 notes = "no build, no ambient capabilities, no unsafe"
856 [[audits.bytecode-alliance.audits.cfg-if]]
857 who = "Alex Crichton <alex@alexcrichton.com>"
858 criteria = "safe-to-deploy"
859 version = "1.0.0"
860 notes = "I am the author of this crate."
862 [[audits.bytecode-alliance.audits.codespan-reporting]]
863 who = "Jamey Sharp <jsharp@fastly.com>"
864 criteria = "safe-to-deploy"
865 version = "0.11.1"
866 notes = "This library uses `forbid(unsafe_code)` and has no filesystem or network I/O."
868 [[audits.bytecode-alliance.audits.cpufeatures]]
869 who = "Alex Crichton <alex@alexcrichton.com>"
870 criteria = "safe-to-deploy"
871 delta = "0.2.2 -> 0.2.7"
872 notes = """
873 This is a minor update that looks to add some more detected CPU features and
874 various other minor portability fixes such as MIRI support.
877 [[audits.bytecode-alliance.audits.crypto-common]]
878 who = "Benjamin Bouvier <public@benj.me>"
879 criteria = "safe-to-deploy"
880 version = "0.1.3"
882 [[audits.bytecode-alliance.audits.fallible-iterator]]
883 who = "Alex Crichton <alex@alexcrichton.com>"
884 criteria = "safe-to-deploy"
885 delta = "0.2.0 -> 0.3.0"
886 notes = """
887 This major version update has a few minor breaking changes but everything
888 this crate has to do with iterators and `Result` and such. No `unsafe` or
889 anything like that, all looks good.
892 [[audits.bytecode-alliance.audits.foreign-types]]
893 who = "Pat Hickey <phickey@fastly.com>"
894 criteria = "safe-to-deploy"
895 version = "0.3.2"
896 notes = "This crate defined a macro-rules which creates wrappers working with FFI types. The implementation of this crate appears to be safe, but each use of this macro would need to be vetted for correctness as well."
898 [[audits.bytecode-alliance.audits.foreign-types-shared]]
899 who = "Pat Hickey <phickey@fastly.com>"
900 criteria = "safe-to-deploy"
901 version = "0.1.1"
903 [[audits.bytecode-alliance.audits.futures-channel]]
904 who = "Pat Hickey <phickey@fastly.com>"
905 criteria = "safe-to-deploy"
906 version = "0.3.27"
907 notes = "build.rs is just detecting the target and setting cfg. unsafety is for implementing a concurrency primitives using atomics and unsafecell, and is not obviously incorrect (this is the sort of thing I wouldn't certify as correct without formal methods)"
909 [[audits.bytecode-alliance.audits.futures-core]]
910 who = "Pat Hickey <phickey@fastly.com>"
911 criteria = "safe-to-deploy"
912 version = "0.3.27"
913 notes = "Unsafe used to implement a concurrency primitive AtomicWaker. Well-commented and not obviously incorrect. Like my other audits of these concurrency primitives inside the futures family, I couldn't certify that it is correct without formal methods, but that is out of scope for this vetting."
915 [[audits.bytecode-alliance.audits.futures-executor]]
916 who = "Pat Hickey <phickey@fastly.com>"
917 criteria = "safe-to-deploy"
918 version = "0.3.27"
919 notes = "Unsafe used to implement the unpark mutex, which is well commented and not obviously incorrect. Like with futures-channel I wouldn't be able to certify it as correct without formal methods."
921 [[audits.bytecode-alliance.audits.futures-io]]
922 who = "Pat Hickey <phickey@fastly.com>"
923 criteria = "safe-to-deploy"
924 version = "0.3.27"
926 [[audits.bytecode-alliance.audits.futures-sink]]
927 who = "Pat Hickey <phickey@fastly.com>"
928 criteria = "safe-to-deploy"
929 version = "0.3.27"
931 [[audits.bytecode-alliance.audits.heck]]
932 who = "Alex Crichton <alex@alexcrichton.com>"
933 criteria = "safe-to-deploy"
934 version = "0.4.0"
935 notes = "Contains `forbid_unsafe` and only uses `std::fmt` from the standard library. Otherwise only contains string manipulation."
937 [[audits.bytecode-alliance.audits.id-arena]]
938 who = "Nick Fitzgerald <fitzgen@gmail.com>"
939 criteria = "safe-to-deploy"
940 version = "2.2.1"
941 notes = "I am the author of this crate."
943 [[audits.bytecode-alliance.audits.idna]]
944 who = "Alex Crichton <alex@alexcrichton.com>"
945 criteria = "safe-to-deploy"
946 version = "0.3.0"
947 notes = """
948 This is a crate without unsafe code or usage of the standard library. The large
949 size of this crate comes from the large generated unicode tables file. This
950 crate is broadly used throughout the ecosystem and does not contain anything
951 suspicious.
954 [[audits.bytecode-alliance.audits.leb128]]
955 who = "Nick Fitzgerald <fitzgen@gmail.com>"
956 criteria = "safe-to-deploy"
957 version = "0.2.5"
958 notes = "I am the author of this crate."
960 [[audits.bytecode-alliance.audits.memoffset]]
961 who = "Alex Crichton <alex@alexcrichton.com>"
962 criteria = "safe-to-deploy"
963 delta = "0.7.1 -> 0.8.0"
964 notes = "This was a small update to the crate which has to do with Rust language features and compiler versions, no substantial changes."
966 [[audits.bytecode-alliance.audits.miniz_oxide]]
967 who = "Alex Crichton <alex@alexcrichton.com>"
968 criteria = "safe-to-deploy"
969 version = "0.7.1"
970 notes = """
971 This crate is a Rust implementation of zlib compression/decompression and has
972 been used by default by the Rust standard library for quite some time. It's also
973 a default dependency of the popular `backtrace` crate for decompressing debug
974 information. This crate forbids unsafe code and does not otherwise access system
975 resources. It's originally a port of the `miniz.c` library as well, and given
976 its own longevity should be relatively hardened against some of the more common
977 compression-related issues.
980 [[audits.bytecode-alliance.audits.mio]]
981 who = "Alex Crichton <alex@alexcrichton.com>"
982 criteria = "safe-to-deploy"
983 delta = "0.8.6 -> 0.8.8"
984 notes = "Mostly OS portability updates along with some minor bugfixes."
986 [[audits.bytecode-alliance.audits.object]]
987 who = "Alex Crichton <alex@alexcrichton.com>"
988 criteria = "safe-to-deploy"
989 delta = "0.30.3 -> 0.31.1"
990 notes = "A large-ish update to the crate but nothing out of the ordering. Support for new formats like xcoff, new constants, minor refactorings, etc. Nothing out of the ordinary."
992 [[audits.bytecode-alliance.audits.object]]
993 who = "Alex Crichton <alex@alexcrichton.com>"
994 criteria = "safe-to-deploy"
995 delta = "0.31.1 -> 0.32.0"
996 notes = "Various new features and refactorings as one would expect from an object parsing crate, all looks good."
998 [[audits.bytecode-alliance.audits.percent-encoding]]
999 who = "Alex Crichton <alex@alexcrichton.com>"
1000 criteria = "safe-to-deploy"
1001 version = "2.2.0"
1002 notes = """
1003 This crate is a single-file crate that does what it says on the tin. There are
1004 a few `unsafe` blocks related to utf-8 validation which are locally verifiable
1005 as correct and otherwise this crate is good to go.
1008 [[audits.bytecode-alliance.audits.pin-utils]]
1009 who = "Pat Hickey <phickey@fastly.com>"
1010 criteria = "safe-to-deploy"
1011 version = "0.1.0"
1013 [[audits.bytecode-alliance.audits.pkg-config]]
1014 who = "Pat Hickey <phickey@fastly.com>"
1015 criteria = "safe-to-deploy"
1016 version = "0.3.25"
1017 notes = "This crate shells out to the pkg-config executable, but it appears to sanitize inputs reasonably."
1019 [[audits.bytecode-alliance.audits.rustc-demangle]]
1020 who = "Alex Crichton <alex@alexcrichton.com>"
1021 criteria = "safe-to-deploy"
1022 version = "0.1.21"
1023 notes = "I am the author of this crate."
1025 [[audits.bytecode-alliance.audits.semver]]
1026 who = "Pat Hickey <phickey@fastly.com>"
1027 criteria = "safe-to-deploy"
1028 version = "1.0.17"
1029 notes = "plenty of unsafe pointer and vec tricks, but in well-structured and commented code that appears to be correct"
1031 [[audits.bytecode-alliance.audits.slab]]
1032 who = "Pat Hickey <phickey@fastly.com>"
1033 criteria = "safe-to-deploy"
1034 version = "0.4.6"
1035 notes = "provides a datastructure implemented using std's Vec. all uses of unsafe are just delegating to the underlying unsafe Vec methods."
1037 [[audits.bytecode-alliance.audits.socket2]]
1038 who = "Alex Crichton <alex@alexcrichton.com>"
1039 criteria = "safe-to-deploy"
1040 delta = "0.4.7 -> 0.4.9"
1041 notes = "Minor OS compat updates but otherwise nothing major here."
1043 [[audits.bytecode-alliance.audits.tempfile]]
1044 who = "Pat Hickey <phickey@fastly.com>"
1045 criteria = "safe-to-deploy"
1046 delta = "3.3.0 -> 3.5.0"
1048 [[audits.bytecode-alliance.audits.tempfile]]
1049 who = "Alex Crichton <alex@alexcrichton.com>"
1050 criteria = "safe-to-deploy"
1051 delta = "3.5.0 -> 3.6.0"
1052 notes = "Dependency updates and new optimized trait implementations, but otherwise everything looks normal."
1054 [[audits.bytecode-alliance.audits.unicase]]
1055 who = "Alex Crichton <alex@alexcrichton.com>"
1056 criteria = "safe-to-deploy"
1057 version = "2.6.0"
1058 notes = """
1059 This crate contains no `unsafe` code and no unnecessary use of the standard
1060 library.
1063 [[audits.bytecode-alliance.audits.unicode-bidi]]
1064 who = "Alex Crichton <alex@alexcrichton.com>"
1065 criteria = "safe-to-deploy"
1066 version = "0.3.8"
1067 notes = """
1068 This crate has no unsafe code and does not use `std::*`. Skimming the crate it
1069 does not attempt to out of the bounds of what it's already supposed to be doing.
1072 [[audits.bytecode-alliance.audits.unicode-normalization]]
1073 who = "Alex Crichton <alex@alexcrichton.com>"
1074 criteria = "safe-to-deploy"
1075 version = "0.1.19"
1076 notes = """
1077 This crate contains one usage of `unsafe` which I have manually checked to see
1078 it as correct. This crate's size comes in large part due to the generated
1079 unicode tables that it contains. This crate is additionally widely used
1080 throughout the ecosystem and skimming the crate shows no usage of `std::*` APIs
1081 and nothing suspicious.
1084 [[audits.embark-studios.wildcard-audits.presser]]
1085 who = "Gray Olson <opensource@embark-studios.com>"
1086 criteria = "safe-to-deploy"
1087 user-id = 52553 # embark-studios
1088 start = "2021-01-01"
1089 end = "2024-05-23"
1090 notes = """
1091 Small crate with no dependencies and no ambient capabilities. The safe interface of the crate
1092 is gated behind unsafe implementation of a core trait, and care must be taken to ensure that
1093 the relevant invariants are guaranteed when doing so. Maintained by the Ark team at Embark
1094 and used in production.
1097 [[audits.embark-studios.audits.anyhow]]
1098 who = "Johan Andersson <opensource@embark-studios.com>"
1099 criteria = "safe-to-deploy"
1100 version = "1.0.58"
1102 [[audits.embark-studios.audits.cfg_aliases]]
1103 who = "Johan Andersson <opensource@embark-studios.com>"
1104 criteria = "safe-to-deploy"
1105 version = "0.1.1"
1106 notes = "No unsafe usage or ambient capabilities"
1108 [[audits.embark-studios.audits.derive_more]]
1109 who = "Johan Andersson <opensource@embark-studios.com>"
1110 criteria = "safe-to-deploy"
1111 version = "0.99.17"
1112 notes = "No unsafe usage or ambient capabilities"
1114 [[audits.embark-studios.audits.ident_case]]
1115 who = "Johan Andersson <opensource@embark-studios.com>"
1116 criteria = "safe-to-deploy"
1117 version = "1.0.1"
1118 notes = "No unsafe usage or ambient capabilities"
1120 [[audits.embark-studios.audits.idna]]
1121 who = "Johan Andersson <opensource@embark-studios.com>"
1122 criteria = "safe-to-deploy"
1123 delta = "0.3.0 -> 0.4.0"
1124 notes = "No unsafe usage or ambient capabilities"
1126 [[audits.embark-studios.audits.line-wrap]]
1127 who = "Johan Andersson <opensource@embark-studios.com>"
1128 criteria = "safe-to-deploy"
1129 version = "0.1.1"
1130 notes = "No unsafe usage or ambient capabilities"
1132 [[audits.embark-studios.audits.yaml-rust]]
1133 who = "Johan Andersson <opensource@embark-studios.com>"
1134 criteria = "safe-to-deploy"
1135 version = "0.4.5"
1136 notes = "No unsafe usage or ambient capabilities"
1138 [[audits.google.audits.ash]]
1139 who = "David Koloski <dkoloski@google.com>"
1140 criteria = "safe-to-deploy"
1141 version = "0.37.0+1.3.209"
1142 notes = "Reviewed on https://fxrev.dev/694269"
1143 aggregated-from = "https://fuchsia.googlesource.com/fuchsia/+/refs/heads/main/third_party/rust_crates/supply-chain/audits.toml?format=TEXT"
1145 [[audits.google.audits.fastrand]]
1146 who = "George Burgess IV <gbiv@google.com>"
1147 criteria = "safe-to-deploy"
1148 version = "1.9.0"
1149 notes = """
1150 `does-not-implement-crypto` is certified because this crate explicitly says
1151 that the RNG here is not cryptographically secure.
1153 aggregated-from = "https://chromium.googlesource.com/chromiumos/third_party/rust_crates/+/refs/heads/main/cargo-vet/audits.toml?format=TEXT"
1155 [[audits.google.audits.futures]]
1156 who = "George Burgess IV <gbiv@google.com>"
1157 criteria = "safe-to-deploy"
1158 version = "0.3.28"
1159 notes = """
1160 `futures` has no logic other than tests - it simply `pub use`s things from
1161 other crates.
1163 aggregated-from = "https://chromium.googlesource.com/chromiumos/third_party/rust_crates/+/refs/heads/main/cargo-vet/audits.toml?format=TEXT"
1165 [[audits.google.audits.glob]]
1166 who = "George Burgess IV <gbiv@google.com>"
1167 criteria = "safe-to-deploy"
1168 version = "0.3.1"
1169 aggregated-from = "https://chromium.googlesource.com/chromiumos/third_party/rust_crates/+/refs/heads/main/cargo-vet/audits.toml?format=TEXT"
1171 [[audits.google.audits.http]]
1172 who = "ChromeOS"
1173 criteria = "safe-to-run"
1174 version = "0.2.8"
1175 aggregated-from = "https://chromium.googlesource.com/chromiumos/third_party/rust_crates/+/refs/heads/main/cargo-vet/audits.toml?format=TEXT"
1177 [[audits.google.audits.http-body]]
1178 who = "ChromeOS"
1179 criteria = "safe-to-run"
1180 version = "0.4.5"
1181 aggregated-from = "https://chromium.googlesource.com/chromiumos/third_party/rust_crates/+/refs/heads/main/cargo-vet/audits.toml?format=TEXT"
1183 [[audits.google.audits.httpdate]]
1184 who = "ChromeOS"
1185 criteria = "safe-to-run"
1186 version = "1.0.2"
1187 aggregated-from = "https://chromium.googlesource.com/chromiumos/third_party/rust_crates/+/refs/heads/main/cargo-vet/audits.toml?format=TEXT"
1189 [[audits.google.audits.hyper]]
1190 who = "ChromeOS"
1191 criteria = "safe-to-run"
1192 version = "0.14.20"
1193 aggregated-from = "https://chromium.googlesource.com/chromiumos/third_party/rust_crates/+/refs/heads/main/cargo-vet/audits.toml?format=TEXT"
1195 [[audits.google.audits.nom]]
1196 who = "danakj@chromium.org"
1197 criteria = "safe-to-deploy"
1198 version = "7.1.3"
1199 notes = """
1200 Reviewed in https://chromium-review.googlesource.com/c/chromium/src/+/5046153
1202 aggregated-from = "https://chromium.googlesource.com/chromium/src/+/main/third_party/rust/chromium_crates_io/supply-chain/audits.toml?format=TEXT"
1204 [[audits.google.audits.pin-project]]
1205 who = "ChromeOS"
1206 criteria = "safe-to-run"
1207 version = "1.0.12"
1208 aggregated-from = "https://chromium.googlesource.com/chromiumos/third_party/rust_crates/+/refs/heads/main/cargo-vet/audits.toml?format=TEXT"
1210 [[audits.google.audits.pin-project-internal]]
1211 who = "ChromeOS"
1212 criteria = "safe-to-run"
1213 version = "1.0.12"
1214 aggregated-from = "https://chromium.googlesource.com/chromiumos/third_party/rust_crates/+/refs/heads/main/cargo-vet/audits.toml?format=TEXT"
1216 [[audits.google.audits.pin-project-lite]]
1217 who = "David Koloski <dkoloski@google.com>"
1218 criteria = "safe-to-deploy"
1219 version = "0.2.9"
1220 notes = "Reviewed on https://fxrev.dev/824504"
1221 aggregated-from = "https://fuchsia.googlesource.com/fuchsia/+/refs/heads/main/third_party/rust_crates/supply-chain/audits.toml?format=TEXT"
1223 [[audits.google.audits.scoped-tls]]
1224 who = "George Burgess IV <gbiv@google.com>"
1225 criteria = "safe-to-run"
1226 version = "1.0.0"
1227 aggregated-from = "https://chromium.googlesource.com/chromiumos/third_party/rust_crates/+/refs/heads/main/cargo-vet/audits.toml?format=TEXT"
1229 [[audits.google.audits.serde_urlencoded]]
1230 who = "ChromeOS"
1231 criteria = "safe-to-run"
1232 version = "0.7.1"
1233 aggregated-from = "https://chromium.googlesource.com/chromiumos/third_party/rust_crates/+/refs/heads/main/cargo-vet/audits.toml?format=TEXT"
1235 [[audits.google.audits.static_assertions]]
1236 who = "Lukasz Anforowicz <lukasza@chromium.org>"
1237 criteria = "safe-to-deploy"
1238 version = "1.1.0"
1239 notes = """
1240 Grepped for `-i cipher`, `-i crypto`, `'\bfs\b'`, `'\bnet\b'`, `'\bunsafe\b'`
1241 and there were no hits except for one `unsafe`.
1243 The lambda where `unsafe` is used is never invoked (e.g. the `unsafe` code
1244 never runs) and is only introduced for some compile-time checks.  Additional
1245 unsafe review comments can be found in https://crrev.com/c/5353376.
1247 This crate has been added to Chromium in https://crrev.com/c/3736562.  The CL
1248 description contains a link to a document with an additional security review.
1250 aggregated-from = "https://chromium.googlesource.com/chromium/src/+/main/third_party/rust/chromium_crates_io/supply-chain/audits.toml?format=TEXT"
1252 [[audits.google.audits.strsim]]
1253 who = "danakj@chromium.org"
1254 criteria = "safe-to-deploy"
1255 version = "0.10.0"
1256 notes = """
1257 Reviewed in https://crrev.com/c/5171063
1259 Previously reviewed during security review and the audit is grandparented in.
1261 aggregated-from = "https://chromium.googlesource.com/chromium/src/+/main/third_party/rust/chromium_crates_io/supply-chain/audits.toml?format=TEXT"
1263 [[audits.google.audits.tokio]]
1264 who = "Vovo Yang <vovoy@google.com>"
1265 criteria = "safe-to-run"
1266 version = "1.29.1"
1267 aggregated-from = "https://chromium.googlesource.com/chromiumos/third_party/rust_crates/+/refs/heads/main/cargo-vet/audits.toml?format=TEXT"
1269 [[audits.google.audits.tokio-stream]]
1270 who = "David Koloski <dkoloski@google.com>"
1271 criteria = "safe-to-deploy"
1272 version = "0.1.11"
1273 notes = "Reviewed on https://fxrev.dev/804724"
1274 aggregated-from = "https://fuchsia.googlesource.com/fuchsia/+/refs/heads/main/third_party/rust_crates/supply-chain/audits.toml?format=TEXT"
1276 [[audits.google.audits.tower-service]]
1277 who = "ChromeOS"
1278 criteria = "safe-to-run"
1279 version = "0.3.2"
1280 aggregated-from = "https://chromium.googlesource.com/chromiumos/third_party/rust_crates/+/refs/heads/main/cargo-vet/audits.toml?format=TEXT"
1282 [[audits.google.audits.tracing]]
1283 who = "ChromeOS"
1284 criteria = "safe-to-run"
1285 version = "0.1.35"
1286 aggregated-from = "https://chromium.googlesource.com/chromiumos/third_party/rust_crates/+/refs/heads/main/cargo-vet/audits.toml?format=TEXT"
1288 [[audits.google.audits.tracing-attributes]]
1289 who = "ChromeOS"
1290 criteria = "safe-to-run"
1291 version = "0.1.22"
1292 aggregated-from = "https://chromium.googlesource.com/chromiumos/third_party/rust_crates/+/refs/heads/main/cargo-vet/audits.toml?format=TEXT"
1294 [[audits.google.audits.tracing-core]]
1295 who = "ChromeOS"
1296 criteria = "safe-to-run"
1297 version = "0.1.29"
1298 aggregated-from = "https://chromium.googlesource.com/chromiumos/third_party/rust_crates/+/refs/heads/main/cargo-vet/audits.toml?format=TEXT"
1300 [[audits.google.audits.try-lock]]
1301 who = "ChromeOS"
1302 criteria = "safe-to-run"
1303 version = "0.2.3"
1304 aggregated-from = "https://chromium.googlesource.com/chromiumos/third_party/rust_crates/+/refs/heads/main/cargo-vet/audits.toml?format=TEXT"
1306 [[audits.google.audits.version_check]]
1307 who = "George Burgess IV <gbiv@google.com>"
1308 criteria = "safe-to-deploy"
1309 version = "0.9.4"
1310 aggregated-from = "https://chromium.googlesource.com/chromiumos/third_party/rust_crates/+/refs/heads/main/cargo-vet/audits.toml?format=TEXT"
1312 [[audits.google.audits.want]]
1313 who = "ChromeOS"
1314 criteria = "safe-to-run"
1315 version = "0.3.0"
1316 aggregated-from = "https://chromium.googlesource.com/chromiumos/third_party/rust_crates/+/refs/heads/main/cargo-vet/audits.toml?format=TEXT"
1318 [[audits.isrg.wildcard-audits.prio]]
1319 who = "David Cook <dcook@divviup.org>"
1320 criteria = "safe-to-deploy"
1321 user-id = 213776 # divviup-github-automation
1322 start = "2020-09-28"
1323 end = "2025-02-12"
1325 [[audits.isrg.audits.base64]]
1326 who = "Tim Geoghegan <timg@letsencrypt.org>"
1327 criteria = "safe-to-deploy"
1328 delta = "0.21.0 -> 0.21.1"
1330 [[audits.isrg.audits.base64]]
1331 who = "Brandon Pitman <bran@bran.land>"
1332 criteria = "safe-to-deploy"
1333 delta = "0.21.1 -> 0.21.2"
1335 [[audits.isrg.audits.base64]]
1336 who = "David Cook <dcook@divviup.org>"
1337 criteria = "safe-to-deploy"
1338 delta = "0.21.2 -> 0.21.3"
1340 [[audits.isrg.audits.block-buffer]]
1341 who = "David Cook <dcook@divviup.org>"
1342 criteria = "safe-to-deploy"
1343 version = "0.9.0"
1345 [[audits.isrg.audits.getrandom]]
1346 who = "Tim Geoghegan <timg@letsencrypt.org>"
1347 criteria = "safe-to-deploy"
1348 delta = "0.2.9 -> 0.2.10"
1349 notes = "These changes include some new `unsafe` code for the `emscripten` and `psvita` targets, but all it does is call `libc::getentropy`."
1351 [[audits.isrg.audits.keccak]]
1352 who = "David Cook <dcook@divviup.org>"
1353 criteria = "safe-to-deploy"
1354 version = "0.1.2"
1356 [[audits.isrg.audits.keccak]]
1357 who = "Brandon Pitman <bran@bran.land>"
1358 criteria = "safe-to-deploy"
1359 delta = "0.1.3 -> 0.1.4"
1361 [[audits.isrg.audits.once_cell]]
1362 who = "Brandon Pitman <bran@bran.land>"
1363 criteria = "safe-to-deploy"
1364 delta = "1.17.1 -> 1.17.2"
1366 [[audits.isrg.audits.once_cell]]
1367 who = "David Cook <dcook@divviup.org>"
1368 criteria = "safe-to-deploy"
1369 delta = "1.17.2 -> 1.18.0"
1371 [[audits.isrg.audits.once_cell]]
1372 who = "Brandon Pitman <bran@bran.land>"
1373 criteria = "safe-to-deploy"
1374 delta = "1.18.0 -> 1.19.0"
1376 [[audits.isrg.audits.rand_chacha]]
1377 who = "David Cook <dcook@divviup.org>"
1378 criteria = "safe-to-deploy"
1379 version = "0.3.1"
1381 [[audits.isrg.audits.rand_core]]
1382 who = "David Cook <dcook@divviup.org>"
1383 criteria = "safe-to-deploy"
1384 version = "0.6.3"
1386 [[audits.isrg.audits.rayon-core]]
1387 who = "Brandon Pitman <bran@bran.land>"
1388 criteria = "safe-to-deploy"
1389 delta = "1.10.2 -> 1.11.0"
1391 [[audits.isrg.audits.rayon-core]]
1392 who = "David Cook <dcook@divviup.org>"
1393 criteria = "safe-to-deploy"
1394 delta = "1.11.0 -> 1.12.0"
1396 [[audits.isrg.audits.sha2]]
1397 who = "David Cook <dcook@divviup.org>"
1398 criteria = "safe-to-deploy"
1399 version = "0.10.2"
1401 [[audits.isrg.audits.sha3]]
1402 who = "David Cook <dcook@divviup.org>"
1403 criteria = "safe-to-deploy"
1404 version = "0.10.6"
1406 [[audits.isrg.audits.sha3]]
1407 who = "Brandon Pitman <bran@bran.land>"
1408 criteria = "safe-to-deploy"
1409 delta = "0.10.7 -> 0.10.8"
1411 [[audits.mozilla.wildcard-audits.zeitstempel]]
1412 who = "Jan-Erik Rediger <jrediger@mozilla.com>"
1413 criteria = "safe-to-deploy"
1414 user-id = 48 # Jan-Erik Rediger (badboy)
1415 start = "2021-03-03"
1416 end = "2024-05-10"
1417 notes = "Maintained by me"
1418 aggregated-from = "https://raw.githubusercontent.com/mozilla/glean/main/supply-chain/audits.toml"
1420 [[audits.mozilla.audits.askama]]
1421 who = "Jan-Erik Rediger <jrediger@mozilla.com>"
1422 criteria = "safe-to-deploy"
1423 delta = "0.11.1 -> 0.12.0"
1424 notes = "No new unsafe usage, mostly dependency updates and smaller API changes"
1425 aggregated-from = "https://raw.githubusercontent.com/mozilla/glean/main/supply-chain/audits.toml"
1427 [[audits.mozilla.audits.askama_derive]]
1428 who = "Jan-Erik Rediger <jrediger@mozilla.com>"
1429 criteria = "safe-to-deploy"
1430 delta = "0.11.2 -> 0.12.1"
1431 notes = "Dependency updates, a new toml dependency and some API changes. No unsafe use."
1432 aggregated-from = "https://raw.githubusercontent.com/mozilla/glean/main/supply-chain/audits.toml"
1434 [[audits.mozilla.audits.basic-toml]]
1435 who = "Jan-Erik Rediger <jrediger@mozilla.com>"
1436 criteria = "safe-to-deploy"
1437 version = "0.1.2"
1438 notes = "TOML parser, forked from toml 0.5"
1439 aggregated-from = "https://raw.githubusercontent.com/mozilla/glean/main/supply-chain/audits.toml"
1441 [[audits.mozilla.audits.bitflags]]
1442 who = "Jan-Erik Rediger <jrediger@mozilla.com>"
1443 criteria = "safe-to-deploy"
1444 delta = "2.4.0 -> 2.4.1"
1445 notes = "Only allowing new clippy lints"
1446 aggregated-from = "https://raw.githubusercontent.com/mozilla/glean/main/supply-chain/audits.toml"
1448 [[audits.mozilla.audits.either]]
1449 who = "Nika Layzell <nika@thelayzells.com>"
1450 criteria = "safe-to-deploy"
1451 version = "1.6.1"
1452 notes = """
1453 Straightforward crate providing the Either enum and trait implementations with
1454 no unsafe code.
1456 aggregated-from = "https://raw.githubusercontent.com/mozilla/cargo-vet/main/supply-chain/audits.toml"
1458 [[audits.mozilla.audits.lazy_static]]
1459 who = "Nika Layzell <nika@thelayzells.com>"
1460 criteria = "safe-to-deploy"
1461 version = "1.4.0"
1462 notes = "I have read over the macros, and audited the unsafe code."
1463 aggregated-from = "https://raw.githubusercontent.com/mozilla/cargo-vet/main/supply-chain/audits.toml"
1465 [[audits.mozilla.audits.log]]
1466 who = "Jan-Erik Rediger <jrediger@mozilla.com>"
1467 criteria = "safe-to-deploy"
1468 delta = "0.4.17 -> 0.4.18"
1469 notes = "One dependency removed, others updated (which we don't rely on), some APIs (which we don't use) changed."
1470 aggregated-from = "https://raw.githubusercontent.com/mozilla/glean/main/supply-chain/audits.toml"
1472 [[audits.mozilla.audits.log]]
1473 who = "Kagami Sascha Rosylight <krosylight@mozilla.com>"
1474 criteria = "safe-to-deploy"
1475 delta = "0.4.18 -> 0.4.20"
1476 notes = "Only cfg attribute and internal macro changes and module refactorings"
1477 aggregated-from = "https://raw.githubusercontent.com/mozilla/glean/main/supply-chain/audits.toml"
1479 [[audits.mozilla.audits.rkv]]
1480 who = "Kagami Sascha Rosylight <krosylight@mozilla.com>"
1481 criteria = "safe-to-deploy"
1482 delta = "0.18.4 -> 0.19.0"
1483 notes = "Maintained by Mozilla, no addition of unsafe blocks"
1484 aggregated-from = "https://raw.githubusercontent.com/mozilla/glean/main/supply-chain/audits.toml"