Check Rust dependencies for known security advisories. Start in your browser with one Cargo.lock, or use the Windows desktop app and CLI for local workspace scans.
Open the public scanner | Download the Windows app | Documentation
- Open the public scanner.
- Choose your project's
Cargo.lock, up to 1 MiB. - Select Scan dependencies.
- Review each advisory's What to do next panel, affected versions, source evidence and recorded dependency paths.
- Use Copy issue summary for the filtered view, or export complete JSON or HTML reports.
See the browser quick start and troubleshooting for a walkthrough and help with incomplete scans.
Scanning runs on your device with WebAssembly. The browser downloads public advisory data; your lockfile and dependency names are not uploaded. No account, repository access or target code execution is needed.
A Rust source file or Cargo.toml alone does not establish exact dependency versions. Use Cargo.lock. This is known dependency advisory matching, not a source code audit or proof of exploitability.
Download the latest portable ZIP, extract the entire archive into a writable folder, then open Start Scanner.bat. The current desktop release is v0.5.0. It bundles the scanner and cargo-audit, so Rust and Cargo are not required for the portable edition. Windows PowerShell 5.1 and Windows Forms are required; the application is unsigned.
See the desktop and CLI guide for setup, build commands, workspace context, reports and limitations.
The CLI scans a local project and can write reports for scripts or CI. Follow the CLI setup and examples. The portable Windows package includes its tools; building from source requires a Rust toolchain. Use --skip-deny for an audit-only scan and read the documented exit codes rather than treating every nonzero exit as a crash.
| Capability | Public browser scanner | Windows desktop | CLI |
|---|---|---|---|
| Input | One Cargo.lock | Local workspace or Cargo.lock | Directory, Cargo.toml or Cargo.lock |
| Advisory sources | RustSec plus supported GitHub-reviewed crates.io advisories via OSV | cargo-audit / RustSec; optional cargo-deny in source edition | cargo-audit; optional cargo-deny |
| Processing | On your device in a browser worker | Local processes | Local processes |
| Dependency context | Bounded recorded lockfile relationships | Lockfile relationships and supported manifest/workspace declarations | Same core context in JSON and HTML |
| Search and filters | Yes | Yes | Read exported reports |
| Exports | Grouped JSON and HTML | JSON, HTML, CSV and desktop enrichment companions | JSON, HTML and CSV |
| Scan comparison | Previous successful scan in this tab | Saved report comparison | No built-in comparison UI |
| CISA KEV indicators | Not implemented | Available with explicit freshness and unknown states | Not enriched by the CLI |
| Automatic dependency changes | Never | Copyable suggestions only | Never |
The separate Docker web preview is a local development implementation, not the public site's architecture. It sends a lockfile to a local Node server and Docker worker. Do not assume the browser site's privacy or deployment model applies to it.
For the public browser scanner, one linked advisory appears once. All affected packages and installed versions stay inside that result.
- Reported IDs and transitive aliases link RustSec, CVE and GHSA records. Titles are not used to guess equivalence.
- Repeated source records do not add vulnerabilities. Duplicate identity/package/version entries are merged.
- One vulnerability affecting two installed versions counts as one vulnerability group and two affected package versions, not two vulnerabilities.
- Advisory warnings are separate from vulnerability totals. Conflicting source evidence requires review and does not carry combined patch advice.
- Version pagination and shortened copied summaries do not change counts. Full JSON and HTML exports retain every result and affected version.
Browser JSON uses schema_version: 3 and format: "grouped-advisories". Results are in top-level findings and warnings; affected versions are nested in affected_packages. The CLI's per-tool schema and desktop report formats are separate. See browser counting and export details.
Identity linkage depends on upstream identifiers. Missing aliases can prevent a match; the scanner does not hide potentially distinct vulnerabilities based on similar wording. No findings does not mean a project is secure.
The browser combines RustSec with supported GitHub-reviewed crates.io records from OSV. Withdrawn, unreviewed and unsupported supplementary records are excluded and counted. Coverage metadata and source disagreements remain visible.
The public advisory service refreshes every six hours without redeploying the website. The scanner verifies snapshot hashes, labels live/cached/bundled data, and refuses data not verified within 14 days. Missing supplementary data is labeled RustSec-only, not full combined coverage.
Git, path and other registry packages are outside the browser's crates.io advisory matching scope and are counted as skipped. Lockfile relationships do not establish active features, targets, workspace ownership, runtime reachability or exploitability. See browser scope and service operations.
Read the dated browser quality audit for the 2026-09-16 checks: generated overlap cases, vulnerable/patched advisory controls, pinned public-project lockfiles and large-result tests. It records the measurement conditions and limitations rather than making a universal accuracy or performance claim.
The permanent browser quality suite checks 400 generated overlap cases, patch-range ordering, pagination and complete exports with a synthetic 5,000-version result. Additional result and action guidance tests cover alias linkage, warning counts, conflicting patch evidence, filtering and escaped output. Rust integration tests exercise lockfile formats, malformed inputs, exact resource limits and bounded graph traversal. GitHub Actions also checks browser dependency tracing, advisory refreshes, Rust builds and tests, and the Windows package. Use the workflow links above for current status.
Older benchmark and validation documents are retained as historical evidence, not current health indicators. The documentation index separates current guides from dated evidence.
- Build the browser scanner.
- Build and run the CLI or Windows desktop.
- Contribute and run focused checks.
- Report a scanner security problem.
- Open a regular bug report.
Do not attach private lockfiles, credentials or sensitive scan reports to public issues. Deliberately vulnerable test fixtures are scanner inputs, not dependencies of this application.
MIT licensed. See LICENSE and third-party notices. Advisory data and bundled components retain their upstream licenses and attribution.