Skip to content

Latest commit

 

History

23 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

Rust CVE Sniffer

Check Rust dependencies for known security advisories. Start in your browser with one Cargo.lock, or use the Windows desktop app and CLI for local workspace scans.

Open the public scanner | Download the Windows app | Documentation

Build and verify Advisory service Browser dependency tracing

Start here

Scan in your browser

  1. Open the public scanner.
  2. Choose your project's Cargo.lock, up to 1 MiB.
  3. Select Scan dependencies.
  4. Review each advisory's What to do next panel, affected versions, source evidence and recorded dependency paths.
  5. Use Copy issue summary for the filtered view, or export complete JSON or HTML reports.

See the browser quick start and troubleshooting for a walkthrough and help with incomplete scans.

Scanning runs on your device with WebAssembly. The browser downloads public advisory data; your lockfile and dependency names are not uploaded. No account, repository access or target code execution is needed.

A Rust source file or Cargo.toml alone does not establish exact dependency versions. Use Cargo.lock. This is known dependency advisory matching, not a source code audit or proof of exploitability.

Use the Windows desktop app

Download the latest portable ZIP, extract the entire archive into a writable folder, then open Start Scanner.bat. The current desktop release is v0.5.0. It bundles the scanner and cargo-audit, so Rust and Cargo are not required for the portable edition. Windows PowerShell 5.1 and Windows Forms are required; the application is unsigned.

See the desktop and CLI guide for setup, build commands, workspace context, reports and limitations.

Use the CLI

The CLI scans a local project and can write reports for scripts or CI. Follow the CLI setup and examples. The portable Windows package includes its tools; building from source requires a Rust toolchain. Use --skip-deny for an audit-only scan and read the documented exit codes rather than treating every nonzero exit as a crash.

Choose the right edition

Capability Public browser scanner Windows desktop CLI
Input One Cargo.lock Local workspace or Cargo.lock Directory, Cargo.toml or Cargo.lock
Advisory sources RustSec plus supported GitHub-reviewed crates.io advisories via OSV cargo-audit / RustSec; optional cargo-deny in source edition cargo-audit; optional cargo-deny
Processing On your device in a browser worker Local processes Local processes
Dependency context Bounded recorded lockfile relationships Lockfile relationships and supported manifest/workspace declarations Same core context in JSON and HTML
Search and filters Yes Yes Read exported reports
Exports Grouped JSON and HTML JSON, HTML, CSV and desktop enrichment companions JSON, HTML and CSV
Scan comparison Previous successful scan in this tab Saved report comparison No built-in comparison UI
CISA KEV indicators Not implemented Available with explicit freshness and unknown states Not enriched by the CLI
Automatic dependency changes Never Copyable suggestions only Never

The separate Docker web preview is a local development implementation, not the public site's architecture. It sends a lockfile to a local Node server and Docker worker. Do not assume the browser site's privacy or deployment model applies to it.

Results without inflated totals

For the public browser scanner, one linked advisory appears once. All affected packages and installed versions stay inside that result.

  1. Reported IDs and transitive aliases link RustSec, CVE and GHSA records. Titles are not used to guess equivalence.
  2. Repeated source records do not add vulnerabilities. Duplicate identity/package/version entries are merged.
  3. One vulnerability affecting two installed versions counts as one vulnerability group and two affected package versions, not two vulnerabilities.
  4. Advisory warnings are separate from vulnerability totals. Conflicting source evidence requires review and does not carry combined patch advice.
  5. Version pagination and shortened copied summaries do not change counts. Full JSON and HTML exports retain every result and affected version.

Browser JSON uses schema_version: 3 and format: "grouped-advisories". Results are in top-level findings and warnings; affected versions are nested in affected_packages. The CLI's per-tool schema and desktop report formats are separate. See browser counting and export details.

Identity linkage depends on upstream identifiers. Missing aliases can prevent a match; the scanner does not hide potentially distinct vulnerabilities based on similar wording. No findings does not mean a project is secure.

Advisory coverage and freshness

The browser combines RustSec with supported GitHub-reviewed crates.io records from OSV. Withdrawn, unreviewed and unsupported supplementary records are excluded and counted. Coverage metadata and source disagreements remain visible.

The public advisory service refreshes every six hours without redeploying the website. The scanner verifies snapshot hashes, labels live/cached/bundled data, and refuses data not verified within 14 days. Missing supplementary data is labeled RustSec-only, not full combined coverage.

Git, path and other registry packages are outside the browser's crates.io advisory matching scope and are counted as skipped. Lockfile relationships do not establish active features, targets, workspace ownership, runtime reachability or exploitability. See browser scope and service operations.

Quality and evidence

Read the dated browser quality audit for the 2026-09-16 checks: generated overlap cases, vulnerable/patched advisory controls, pinned public-project lockfiles and large-result tests. It records the measurement conditions and limitations rather than making a universal accuracy or performance claim.

The permanent browser quality suite checks 400 generated overlap cases, patch-range ordering, pagination and complete exports with a synthetic 5,000-version result. Additional result and action guidance tests cover alias linkage, warning counts, conflicting patch evidence, filtering and escaped output. Rust integration tests exercise lockfile formats, malformed inputs, exact resource limits and bounded graph traversal. GitHub Actions also checks browser dependency tracing, advisory refreshes, Rust builds and tests, and the Windows package. Use the workflow links above for current status.

Older benchmark and validation documents are retained as historical evidence, not current health indicators. The documentation index separates current guides from dated evidence.

Build, contribute and report problems

  1. Build the browser scanner.
  2. Build and run the CLI or Windows desktop.
  3. Contribute and run focused checks.
  4. Report a scanner security problem.
  5. Open a regular bug report.

Do not attach private lockfiles, credentials or sensitive scan reports to public issues. Deliberately vulnerable test fixtures are scanner inputs, not dependencies of this application.

License

MIT licensed. See LICENSE and third-party notices. Advisory data and bundled components retain their upstream licenses and attribution.

About

Rust dependency CVE scanner with private on-device browser scans, a portable Windows desktop, searchable findings, and reports.

Topics

Resources

Contributing

Security policy

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages