Skip to content

Update Rust crate compression to 0.1.5 - #92

Open
ghost wants to merge 1 commit into
masterfrom
whitesource-remediate/compression-0.x
Open

Update Rust crate compression to 0.1.5#92
ghost wants to merge 1 commit into
masterfrom
whitesource-remediate/compression-0.x

Update Rust crate compression to 0.1.5

f710783
Select commit
Loading
Failed to load commit list.
Deleted GitHub App / Mend Security Check failed Sep 2, 2025 in 36m 1s

Security Report

The Security Check found 36 vulnerabilities.

Vulnerability Severity CVSS Score Exploit Maturity EPSS Vulnerable Library Suggested Fix Issue
CVE-2025-1744

Path to dependency file: /Cargo.toml

Path to vulnerable library: /Cargo.toml

Dependency Hierarchy:

-> git2-0.16.1.crate (Root Library)

   -> libgit2-sys-0.14.2+1.5.1.crate

     -> libssh2-sys-0.2.23.crate

       -> ❌ libz-sys-1.1.8.crate (Vulnerable Library)

Critical 9.8 Not Defined 0.1% libz-sys-1.1.8.crate None
CVE-2025-1744

Path to dependency file: /Cargo.toml

Path to vulnerable library: /Cargo.toml

Dependency Hierarchy:

-> git2-0.16.1.crate (Root Library)

   -> ❌ libgit2-sys-0.14.2+1.5.1.crate (Vulnerable Library)

Critical 9.8 Not Defined 0.1% libgit2-sys-0.14.2+1.5.1.crate None
CVE-2023-45853

Path to dependency file: /Cargo.toml

Path to vulnerable library: /Cargo.toml

Dependency Hierarchy:

-> git2-0.16.1.crate (Root Library)

   -> libgit2-sys-0.14.2+1.5.1.crate

     -> libssh2-sys-0.2.23.crate

       -> ❌ libz-sys-1.1.8.crate (Vulnerable Library)

Critical 9.8 Not Defined 0.5% libz-sys-1.1.8.crate Upgrade to version: zlib - 1.3.1 None
CVE-2022-37434

Path to dependency file: /Cargo.toml

Path to vulnerable library: /Cargo.toml

Dependency Hierarchy:

-> git2-0.16.1.crate (Root Library)

   -> ❌ libgit2-sys-0.14.2+1.5.1.crate (Vulnerable Library)

Critical 9.8 Not Defined 92.7% libgit2-sys-0.14.2+1.5.1.crate None
CVE-2022-37434

Path to dependency file: /Cargo.toml

Path to vulnerable library: /Cargo.toml

Dependency Hierarchy:

-> git2-0.16.1.crate (Root Library)

   -> libgit2-sys-0.14.2+1.5.1.crate

     -> libssh2-sys-0.2.23.crate

       -> ❌ libz-sys-1.1.8.crate (Vulnerable Library)

Critical 9.8 Not Defined 92.7% libz-sys-1.1.8.crate None
CVE-2020-25573

Path to dependency file: /Cargo.toml

Path to vulnerable library: /Cargo.toml

Dependency Hierarchy:

-> riker-patterns-0.4.2.crate (Root Library)

   -> riker-0.4.2.crate

     -> config-0.10.1.crate

       -> serde-hjson-0.9.1.crate

         -> ❌ linked-hash-map-0.3.0.crate (Vulnerable Library)

Critical 9.8 Not Defined 0.6% linked-hash-map-0.3.0.crate Upgrade to version: linked-hash-map - 0.5.3 None
CVE-2020-25573

Path to dependency file: /Cargo.toml

Path to vulnerable library: /Cargo.toml

Dependency Hierarchy:

-> riker-0.4.2.crate (Root Library)

   -> config-0.10.1.crate

     -> serde-hjson-0.9.1.crate

       -> ❌ linked-hash-map-0.3.0.crate (Vulnerable Library)

Critical 9.8 Not Defined 0.6% linked-hash-map-0.3.0.crate Upgrade to version: linked-hash-map - 0.5.3 None
WS-2023-0045

Path to dependency file: /Cargo.toml

Path to vulnerable library: /Cargo.toml

Dependency Hierarchy:

-> tempfile-3.3.0.crate (Root Library)

   -> ❌ remove_dir_all-0.5.3.crate (Vulnerable Library)

Critical 9.1 Not Defined remove_dir_all-0.5.3.crate Upgrade to version: remove_dir_all - 0.8.0 None
CVE-2024-24577

Path to dependency file: /Cargo.toml

Path to vulnerable library: /Cargo.toml

Dependency Hierarchy:

-> git2-0.16.1.crate (Root Library)

   -> ❌ libgit2-sys-0.14.2+1.5.1.crate (Vulnerable Library)

High 8.6 Not Defined 0.3% libgit2-sys-0.14.2+1.5.1.crate None
CVE-2023-4807

Path to dependency file: /Cargo.toml

Path to vulnerable library: /Cargo.toml

Dependency Hierarchy:

-> git2-0.16.1.crate (Root Library)

   -> libgit2-sys-0.14.2+1.5.1.crate

     -> libssh2-sys-0.2.23.crate

       -> openssl-sys-0.9.80.crate

         -> ❌ openssl-src-111.24.0+1.1.1s.crate (Vulnerable Library)

High 7.8 Not Defined 0.70000005% openssl-src-111.24.0+1.1.1s.crate None
WS-2023-0083

Path to dependency file: /Cargo.toml

Path to vulnerable library: /Cargo.toml

Dependency Hierarchy:

-> git2-0.16.1.crate (Root Library)

   -> libgit2-sys-0.14.2+1.5.1.crate

     -> libssh2-sys-0.2.23.crate

       -> ❌ openssl-sys-0.9.80.crate (Vulnerable Library)

High 7.5 Not Defined openssl-sys-0.9.80.crate Upgrade to version: openssl - 0.10.48 None
WS-2023-0082

Path to dependency file: /Cargo.toml

Path to vulnerable library: /Cargo.toml

Dependency Hierarchy:

-> git2-0.16.1.crate (Root Library)

   -> libgit2-sys-0.14.2+1.5.1.crate

     -> libssh2-sys-0.2.23.crate

       -> ❌ openssl-sys-0.9.80.crate (Vulnerable Library)

High 7.5 Not Defined openssl-sys-0.9.80.crate Upgrade to version: openssl - 0.10.48 None
WS-2023-0081

Path to dependency file: /Cargo.toml

Path to vulnerable library: /Cargo.toml

Dependency Hierarchy:

-> git2-0.16.1.crate (Root Library)

   -> libgit2-sys-0.14.2+1.5.1.crate

     -> libssh2-sys-0.2.23.crate

       -> ❌ openssl-sys-0.9.80.crate (Vulnerable Library)

High 7.5 Not Defined openssl-sys-0.9.80.crate Upgrade to version: openssl - 0.10.48 None
WS-2022-0013

Path to dependency file: /Cargo.toml

Path to vulnerable library: /Cargo.toml

Dependency Hierarchy:

-> riker-patterns-0.4.2.crate (Root Library)

   -> riker-0.4.2.crate

     -> ❌ dashmap-3.11.10.crate (Vulnerable Library)

High 7.5 Not Defined dashmap-3.11.10.crate Upgrade to version: dashmap - 5.1.0 None
WS-2022-0013

Path to dependency file: /Cargo.toml

Path to vulnerable library: /Cargo.toml

Dependency Hierarchy:

-> riker-0.4.2.crate (Root Library)

   -> ❌ dashmap-3.11.10.crate (Vulnerable Library)

High 7.5 Not Defined dashmap-3.11.10.crate Upgrade to version: dashmap - 5.1.0 None
CVE-2024-27308

Path to dependency file: /Cargo.toml

Path to vulnerable library: /Cargo.toml

Dependency Hierarchy:

-> actix-web-4.3.0.crate (Root Library)

   -> actix-codec-0.5.0.crate

     -> tokio-1.24.2.crate

       -> ❌ mio-0.8.5.crate (Vulnerable Library)

High 7.5 Not Defined 0.1% mio-0.8.5.crate None
CVE-2023-26964

Path to dependency file: /Cargo.toml

Path to vulnerable library: /Cargo.toml

Dependency Hierarchy:

-> actix-web-4.3.0.crate (Root Library)

   -> actix-http-3.3.0.crate

     -> ❌ h2-0.3.15.crate (Vulnerable Library)

High 7.5 Not Defined 0.2% h2-0.3.15.crate Upgrade to version: h2 - 0.3.17 None
CVE-2023-0464

Path to dependency file: /Cargo.toml

Path to vulnerable library: /Cargo.toml

Dependency Hierarchy:

-> git2-0.16.1.crate (Root Library)

   -> libgit2-sys-0.14.2+1.5.1.crate

     -> libssh2-sys-0.2.23.crate

       -> openssl-sys-0.9.80.crate

         -> ❌ openssl-src-111.24.0+1.1.1s.crate (Vulnerable Library)

High 7.5 Not Defined 1.2% openssl-src-111.24.0+1.1.1s.crate None
CVE-2023-0215

Path to dependency file: /Cargo.toml

Path to vulnerable library: /Cargo.toml

Dependency Hierarchy:

-> git2-0.16.1.crate (Root Library)

   -> libgit2-sys-0.14.2+1.5.1.crate

     -> libssh2-sys-0.2.23.crate

       -> openssl-sys-0.9.80.crate

         -> ❌ openssl-src-111.24.0+1.1.1s.crate (Vulnerable Library)

High 7.5 Not Defined 0.1% openssl-src-111.24.0+1.1.1s.crate None
CVE-2022-4450

Path to dependency file: /Cargo.toml

Path to vulnerable library: /Cargo.toml

Dependency Hierarchy:

-> git2-0.16.1.crate (Root Library)

   -> libgit2-sys-0.14.2+1.5.1.crate

     -> libssh2-sys-0.2.23.crate

       -> openssl-sys-0.9.80.crate

         -> ❌ openssl-src-111.24.0+1.1.1s.crate (Vulnerable Library)

High 7.5 Not Defined 0.1% openssl-src-111.24.0+1.1.1s.crate None
CVE-2018-25032

Path to dependency file: /Cargo.toml

Path to vulnerable library: /Cargo.toml

Dependency Hierarchy:

-> git2-0.16.1.crate (Root Library)

   -> libgit2-sys-0.14.2+1.5.1.crate

     -> libssh2-sys-0.2.23.crate

       -> ❌ libz-sys-1.1.8.crate (Vulnerable Library)

High 7.5 Not Defined 0.1% libz-sys-1.1.8.crate Upgrade to version: v1.2.12 None
CVE-2023-0286

Path to dependency file: /Cargo.toml

Path to vulnerable library: /Cargo.toml

Dependency Hierarchy:

-> git2-0.16.1.crate (Root Library)

   -> libgit2-sys-0.14.2+1.5.1.crate

     -> libssh2-sys-0.2.23.crate

       -> openssl-sys-0.9.80.crate

         -> ❌ openssl-src-111.24.0+1.1.1s.crate (Vulnerable Library)

High 7.4 Not Defined 78.3% openssl-src-111.24.0+1.1.1s.crate Upgrade to version: openssl-3.0.8;cryptography - 39.0.1;openssl-src - 111.25.0+1.1.1t,300.0.12+3.0.8 None
WS-2020-0368

Path to dependency file: /Cargo.toml

Path to vulnerable library: /Cargo.toml

Dependency Hierarchy:

-> git2-0.16.1.crate (Root Library)

   -> libgit2-sys-0.14.2+1.5.1.crate

     -> libssh2-sys-0.2.23.crate

       -> ❌ libz-sys-1.1.8.crate (Vulnerable Library)

Medium 6.5 Not Defined libz-sys-1.1.8.crate None
CVE-2023-2650

Path to dependency file: /Cargo.toml

Path to vulnerable library: /Cargo.toml

Dependency Hierarchy:

-> git2-0.16.1.crate (Root Library)

   -> libgit2-sys-0.14.2+1.5.1.crate

     -> libssh2-sys-0.2.23.crate

       -> openssl-sys-0.9.80.crate

         -> ❌ openssl-src-111.24.0+1.1.1s.crate (Vulnerable Library)

Medium 6.5 Not Defined 88.200005% openssl-src-111.24.0+1.1.1s.crate Upgrade to version: OpenSSL_1_1_1u,openssl-3.0.9,openssl-3.1.1, cryptography - 41.0.0 None
CVE-2023-48795

Path to dependency file: /Cargo.toml

Path to vulnerable library: /Cargo.toml

Dependency Hierarchy:

-> git2-0.16.1.crate (Root Library)

   -> libgit2-sys-0.14.2+1.5.1.crate

     -> ❌ libssh2-sys-0.2.23.crate (Vulnerable Library)

Medium 5.9 Not Defined 57.200005% libssh2-sys-0.2.23.crate None
CVE-2022-4304

Path to dependency file: /Cargo.toml

Path to vulnerable library: /Cargo.toml

Dependency Hierarchy:

-> git2-0.16.1.crate (Root Library)

   -> libgit2-sys-0.14.2+1.5.1.crate

     -> libssh2-sys-0.2.23.crate

       -> openssl-sys-0.9.80.crate

         -> ❌ openssl-src-111.24.0+1.1.1s.crate (Vulnerable Library)

Medium 5.9 Not Defined 0.1% openssl-src-111.24.0+1.1.1s.crate Upgrade to version: OpenSSL_1_1_1t,openssl-3.0.8 None
CVE-2024-0727

Path to dependency file: /Cargo.toml

Path to vulnerable library: /Cargo.toml

Dependency Hierarchy:

-> git2-0.16.1.crate (Root Library)

   -> libgit2-sys-0.14.2+1.5.1.crate

     -> libssh2-sys-0.2.23.crate

       -> openssl-sys-0.9.80.crate

         -> ❌ openssl-src-111.24.0+1.1.1s.crate (Vulnerable Library)

Medium 5.5 Not Defined 0.2% openssl-src-111.24.0+1.1.1s.crate None
WS-2023-0223

Path to dependency file: /Cargo.toml

Path to vulnerable library: /Cargo.toml

Dependency Hierarchy:

-> stderrlog-0.5.4.crate (Root Library)

   -> ❌ atty-0.2.14.crate (Vulnerable Library)

Medium 5.3 Not Defined atty-0.2.14.crate None
WS-2023-0223

Path to dependency file: /Cargo.toml

Path to vulnerable library: /Cargo.toml

Dependency Hierarchy:

-> structopt-0.3.26.crate (Root Library)

   -> clap-2.34.0.crate

     -> ❌ atty-0.2.14.crate (Vulnerable Library)

Medium 5.3 Not Defined atty-0.2.14.crate None
CVE-2023-5678

Path to dependency file: /Cargo.toml

Path to vulnerable library: /Cargo.toml

Dependency Hierarchy:

-> git2-0.16.1.crate (Root Library)

   -> libgit2-sys-0.14.2+1.5.1.crate

     -> libssh2-sys-0.2.23.crate

       -> openssl-sys-0.9.80.crate

         -> ❌ openssl-src-111.24.0+1.1.1s.crate (Vulnerable Library)

Medium 5.3 Not Defined 0.1% openssl-src-111.24.0+1.1.1s.crate Upgrade to version: OpenSSL_1_1_1x,openssl-3.0.13,openssl-3.1.5 None
CVE-2023-3817

Path to dependency file: /Cargo.toml

Path to vulnerable library: /Cargo.toml

Dependency Hierarchy:

-> git2-0.16.1.crate (Root Library)

   -> libgit2-sys-0.14.2+1.5.1.crate

     -> libssh2-sys-0.2.23.crate

       -> openssl-sys-0.9.80.crate

         -> ❌ openssl-src-111.24.0+1.1.1s.crate (Vulnerable Library)

Medium 5.3 Not Defined 0.2% openssl-src-111.24.0+1.1.1s.crate None
CVE-2023-0465

Path to dependency file: /Cargo.toml

Path to vulnerable library: /Cargo.toml

Dependency Hierarchy:

-> git2-0.16.1.crate (Root Library)

   -> libgit2-sys-0.14.2+1.5.1.crate

     -> libssh2-sys-0.2.23.crate

       -> openssl-sys-0.9.80.crate

         -> ❌ openssl-src-111.24.0+1.1.1s.crate (Vulnerable Library)

Medium 5.3 Not Defined 0.3% openssl-src-111.24.0+1.1.1s.crate None
CVE-2022-4203

Path to dependency file: /Cargo.toml

Path to vulnerable library: /Cargo.toml

Dependency Hierarchy:

-> git2-0.16.1.crate (Root Library)

   -> libgit2-sys-0.14.2+1.5.1.crate

     -> libssh2-sys-0.2.23.crate

       -> openssl-sys-0.9.80.crate

         -> ❌ openssl-src-111.24.0+1.1.1s.crate (Vulnerable Library)

Medium 4.9 Not Defined 0.3% openssl-src-111.24.0+1.1.1s.crate Upgrade to version: openssl-3.0.8 None
CVE-2024-12224

Path to dependency file: /Cargo.toml

Path to vulnerable library: /Cargo.toml

Dependency Hierarchy:

-> git2-0.16.1.crate (Root Library)

   -> url-2.3.1.crate

     -> ❌ idna-0.3.0.crate (Vulnerable Library)

Medium 4.8 Not Defined 0.0% idna-0.3.0.crate None
CVE-2024-12224

Path to dependency file: /Cargo.toml

Path to vulnerable library: /Cargo.toml

Dependency Hierarchy:

-> url-2.3.1.crate (Root Library)

   -> ❌ idna-0.3.0.crate (Vulnerable Library)

Medium 4.8 Not Defined 0.0% idna-0.3.0.crate None
CVE-2024-12224

Path to dependency file: /Cargo.toml

Path to vulnerable library: /Cargo.toml

Dependency Hierarchy:

-> actix-web-4.3.0.crate (Root Library)

   -> url-2.3.1.crate

     -> ❌ idna-0.3.0.crate (Vulnerable Library)

Medium 4.8 Not Defined 0.0% idna-0.3.0.crate None

Total libraries scanned: 285
Scan token: d0cc785e4756485eb0dbb81e87e10f9f