🔒 Dependency Dashboard #6

Open
opened 2026-08-27 23:04:51 +00:00 by Headscracher · 0 comments
Owner

🔒 Dependency Dashboard (2)

2 unknown

Severity Package Installed Fixed in Advisory
Unknown bincode 1.3.3 none yet RUSTSEC-2025-0141
Unknown yaml-rust 0.4.5 none yet RUSTSEC-2024-0320
bincode 1.3.3 — Bincode is unmaintained

Due to a doxxing and harassment incident, the bincode team has taken the decision to cease development permanently.

The team considers version 1.3.3 a complete version of bincode that is not in need of any updates.

Alternatives to consider

affected >=0.0.0-0 · found in Cargo.lock

https://crates.io/crates/bincode · https://rustsec.org/advisories/RUSTSEC-2025-0141.html · https://git.sr.ht/~stygianentity/bincode/tree/v3.0/item/README.md

yaml-rust 0.4.5 — yaml-rust is unmaintained.

The maintainer seems unreachable.

Many issues and pull requests have been submitted over the years
without any response.

Alternatives

Consider switching to the actively maintained yaml-rust2 fork of the original project:

affected >=0.0.0-0 · found in Cargo.lock

https://crates.io/crates/yaml-rust · https://rustsec.org/advisories/RUSTSEC-2024-0320.html · https://github.com/rustsec/advisory-db/issues/1921


Scanned 1 lockfile(s) · 2026-08-27 23:04 UTC · dependabork

<!-- dependabork:v1 --> <!-- hash:3324e85dc7700e1c --> # 🔒 Dependency Dashboard (2) **2 unknown** | Severity | Package | Installed | Fixed in | Advisory | |---|---|---|---|---| | ⚫ Unknown | bincode | 1.3.3 | **none yet** | [RUSTSEC-2025-0141](https://osv.dev/vulnerability/RUSTSEC-2025-0141) | | ⚫ Unknown | yaml-rust | 0.4.5 | **none yet** | [RUSTSEC-2024-0320](https://osv.dev/vulnerability/RUSTSEC-2024-0320) | <details><summary>bincode 1.3.3 — Bincode is unmaintained</summary> Due to a doxxing and harassment incident, the bincode team has taken the decision to cease development permanently. The team considers version 1.3.3 a complete version of bincode that is not in need of any updates. ## Alternatives to consider * [wincode](https://crates.io/crates/wincode) * [postcard](https://crates.io/crates/postcard) * [bitcode](https://crates.io/crates/bitcode) * [rkyv](https://crates.io/crates/rkyv) affected `>=0.0.0-0` · found in `Cargo.lock` <https://crates.io/crates/bincode> · <https://rustsec.org/advisories/RUSTSEC-2025-0141.html> · <https://git.sr.ht/~stygianentity/bincode/tree/v3.0/item/README.md> </details> <details><summary>yaml-rust 0.4.5 — yaml-rust is unmaintained.</summary> The maintainer seems [unreachable](https://github.com/chyh1990/yaml-rust/issues/197). Many issues and pull requests have been submitted over the years without any [response](https://github.com/chyh1990/yaml-rust/issues/160). ## Alternatives Consider switching to the actively maintained `yaml-rust2` fork of the original project: - [yaml-rust2](https://github.com/Ethiraric/yaml-rust2) - [yaml-rust2 @ crates.io](https://crates.io/crates/yaml-rust2) affected `>=0.0.0-0` · found in `Cargo.lock` <https://crates.io/crates/yaml-rust> · <https://rustsec.org/advisories/RUSTSEC-2024-0320.html> · <https://github.com/rustsec/advisory-db/issues/1921> </details> --- _Scanned 1 lockfile(s) · 2026-08-27 23:04 UTC · dependabork_
Sign in to join this conversation.
No labels
dependabork
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
Headscracher/KnowledgeBase#6
No description provided.