Bug 1918529 - fix some subpixel misalignment issues with gfx.webrender.svg-filter...
[gecko.git] / supply-chain / audits.toml
blob5564fc9ecba0149006c9084be834bebf907696a8
2 # cargo-vet audits file
4 [[wildcard-audits.audio_thread_priority]]
5 who = "Paul Adenot <paul@paul.cx>"
6 criteria = "safe-to-deploy"
7 user-id = 1258 # Paul Adenot (padenot)
8 start = "2019-05-09"
9 end = "2024-04-24"
10 notes = """
11 I've written most of this crate, the rest has been either written and in any
12 case has been reviewed by Mozilla developers.
13 """
15 [[wildcard-audits.authenticator]]
16 who = "John M. Schanck <jschanck@mozilla.com>"
17 criteria = "safe-to-deploy"
18 user-id = 175410 # John Schanck (jschanck)
19 start = "2022-11-15"
20 end = "2025-09-25"
21 notes = "Maintained by the CryptoEng team at Mozilla."
23 [[wildcard-audits.bhttp]]
24 who = "Martin Thomson <mt@lowentropy.net>"
25 criteria = "safe-to-deploy"
26 user-id = 128763 # Martin Thomson (martinthomson)
27 start = "2022-08-04"
28 end = "2024-03-09"
29 notes = "Though the code is safe to run and deploy, the code for processing HTTP/1.1 messages (the `read-http` feature, specifically) is not suited for deployment in real applications, either clients or servers.  Some features necessary for live deployment are not implemented, such as the proper handling of some types of response (e.g., a response to a HEAD request).  Software that processes HTTP/1.1 messages requires a large number of compatibility tweaks if it is to be deployed interoperably.  This feature only exists to support basic validation tools and is unlikely to be widely compatible."
31 [[wildcard-audits.breakpad-symbols]]
32 who = "Alex Franchuk <afranchuk@mozilla.com>"
33 criteria = "safe-to-deploy"
34 user-id = 72814 # Gabriele Svelto (gabrielesvelto)
35 start = "2022-11-30"
36 end = "2025-02-28"
37 notes = "This crate is written and maintained by mozilla employees."
39 [[wildcard-audits.cachemap2]]
40 who = "Alex Franchuk <afranchuk@mozilla.com>"
41 criteria = "safe-to-deploy"
42 user-id = 106639 # Alex Franchuk (afranchuk)
43 start = "2023-03-21"
44 end = "2025-02-28"
45 notes = "This crate is written and solely maintained by a mozilla employee."
47 [[wildcard-audits.cexpr]]
48 who = "Emilio Cobos Álvarez <emilio@crisal.io>"
49 criteria = "safe-to-deploy"
50 user-id = 3788 # Emilio Cobos Álvarez (emilio)
51 start = "2021-06-21"
52 end = "2024-04-21"
53 notes = "No unsafe code, rather straight-forward parser."
55 [[wildcard-audits.clubcard]]
56 who = "John M. Schanck <jschanck@mozilla.com>"
57 criteria = "safe-to-deploy"
58 user-id = 175410 # John Schanck (jschanck)
59 start = "2024-10-01"
60 end = "2025-10-01"
61 notes = "Maintained by the CryptoEng team at Mozilla."
63 [[wildcard-audits.clubcard-crlite]]
64 who = "John M. Schanck <jschanck@mozilla.com>"
65 criteria = "safe-to-deploy"
66 user-id = 175410 # John Schanck (jschanck)
67 start = "2024-10-01"
68 end = "2025-10-01"
69 notes = "Maintained by the CryptoEng team at Mozilla."
71 [[wildcard-audits.cocoa]]
72 who = "Bobby Holley <bobbyholley@gmail.com>"
73 criteria = "safe-to-deploy"
74 user-id = 2396 # Josh Matthews (jdm)
75 start = "2019-07-23"
76 end = "2023-05-04"
77 renew = false
78 notes = "I've reviewed every source contribution that was neither authored nor reviewed by Mozilla."
80 [[wildcard-audits.cocoa]]
81 who = "Bobby Holley <bobbyholley@gmail.com>"
82 criteria = "safe-to-deploy"
83 user-id = 5946 # Jeff Muizelaar (jrmuizel)
84 start = "2022-11-01"
85 end = "2023-05-04"
86 renew = false
87 notes = "I've reviewed every source contribution that was neither authored nor reviewed by Mozilla."
89 [[wildcard-audits.cocoa-foundation]]
90 who = "Bobby Holley <bobbyholley@gmail.com>"
91 criteria = "safe-to-deploy"
92 user-id = 2396 # Josh Matthews (jdm)
93 start = "2020-07-20"
94 end = "2023-05-04"
95 renew = false
96 notes = "I've reviewed every source contribution that was neither authored nor reviewed by Mozilla."
98 [[wildcard-audits.cocoa-foundation]]
99 who = "Bobby Holley <bobbyholley@gmail.com>"
100 criteria = "safe-to-deploy"
101 user-id = 5946 # Jeff Muizelaar (jrmuizel)
102 start = "2023-03-16"
103 end = "2023-05-04"
104 renew = false
105 notes = "I've reviewed every source contribution that was neither authored nor reviewed by Mozilla."
107 [[wildcard-audits.core-foundation]]
108 who = "Bobby Holley <bobbyholley@gmail.com>"
109 criteria = "safe-to-deploy"
110 user-id = 2396 # Josh Matthews (jdm)
111 start = "2019-11-12"
112 end = "2023-05-04"
113 renew = false
114 notes = "I've reviewed every source contribution that was neither authored nor reviewed by Mozilla."
116 [[wildcard-audits.core-foundation]]
117 who = "Bobby Holley <bobbyholley@gmail.com>"
118 criteria = "safe-to-deploy"
119 user-id = 5946 # Jeff Muizelaar (jrmuizel)
120 start = "2019-03-29"
121 end = "2023-05-04"
122 renew = false
123 notes = "I've reviewed every source contribution that was neither authored nor reviewed by Mozilla."
125 [[wildcard-audits.core-foundation-sys]]
126 who = "Bobby Holley <bobbyholley@gmail.com>"
127 criteria = "safe-to-deploy"
128 user-id = 2396 # Josh Matthews (jdm)
129 start = "2019-11-12"
130 end = "2023-05-04"
131 renew = false
132 notes = "I've reviewed every source contribution that was neither authored nor reviewed by Mozilla."
134 [[wildcard-audits.core-foundation-sys]]
135 who = "Bobby Holley <bobbyholley@gmail.com>"
136 criteria = "safe-to-deploy"
137 user-id = 5946 # Jeff Muizelaar (jrmuizel)
138 start = "2020-10-14"
139 end = "2023-05-04"
140 renew = false
141 notes = "I've reviewed every source contribution that was neither authored nor reviewed by Mozilla."
143 [[wildcard-audits.core-graphics]]
144 who = "Bobby Holley <bobbyholley@gmail.com>"
145 criteria = "safe-to-deploy"
146 user-id = 2396 # Josh Matthews (jdm)
147 start = "2019-10-28"
148 end = "2023-05-04"
149 renew = false
150 notes = "I've reviewed every source contribution that was neither authored nor reviewed by Mozilla."
152 [[wildcard-audits.core-graphics]]
153 who = "Bobby Holley <bobbyholley@gmail.com>"
154 criteria = "safe-to-deploy"
155 user-id = 5946 # Jeff Muizelaar (jrmuizel)
156 start = "2020-12-08"
157 end = "2023-05-04"
158 renew = false
159 notes = "I've reviewed every source contribution that was neither authored nor reviewed by Mozilla."
161 [[wildcard-audits.core-graphics-types]]
162 who = "Bobby Holley <bobbyholley@gmail.com>"
163 criteria = "safe-to-deploy"
164 user-id = 2396 # Josh Matthews (jdm)
165 start = "2020-07-20"
166 end = "2023-05-04"
167 renew = false
168 notes = "I've reviewed every source contribution that was neither authored nor reviewed by Mozilla."
170 [[wildcard-audits.core-text]]
171 who = "Bobby Holley <bobbyholley@gmail.com>"
172 criteria = "safe-to-deploy"
173 user-id = 2396 # Josh Matthews (jdm)
174 start = "2019-03-29"
175 end = "2023-05-04"
176 renew = false
177 notes = "I've reviewed every source contribution that was neither authored nor reviewed by Mozilla."
179 [[wildcard-audits.core-text]]
180 who = "Bobby Holley <bobbyholley@gmail.com>"
181 criteria = "safe-to-deploy"
182 user-id = 5946 # Jeff Muizelaar (jrmuizel)
183 start = "2021-02-14"
184 end = "2023-05-04"
185 renew = false
186 notes = "I've reviewed every source contribution that was neither authored nor reviewed by Mozilla."
188 [[wildcard-audits.dogear]]
189 who = "Bobby Holley <bobbyholley@gmail.com>"
190 criteria = "safe-to-deploy"
191 user-id = 27901 # Lina Butler (linabutler)
192 start = "2019-03-04"
193 end = "2024-05-05"
194 notes = "Lina developed this crate as Mozilla staff."
196 [[wildcard-audits.encoding_rs]]
197 who = "Henri Sivonen <hsivonen@hsivonen.fi>"
198 criteria = "safe-to-deploy"
199 user-id = 4484 # Henri Sivonen (hsivonen)
200 start = "2019-02-26"
201 end = "2025-10-23"
202 notes = "I, Henri Sivonen, wrote encoding_rs for Gecko and have reviewed contributions by others. There are two caveats to the certification: 1) The crate does things that are documented to be UB but that do not appear to actually be UB due to integer types differing from the general rule; https://github.com/hsivonen/encoding_rs/issues/79 . 2) It would be prudent to re-review the code that reinterprets buffers of integers as SIMD vectors; see https://github.com/hsivonen/encoding_rs/issues/87 ."
204 [[wildcard-audits.etagere]]
205 who = "Nicolas Silva <nical@fastmail.com>"
206 criteria = "safe-to-deploy"
207 user-id = 1281 # Nicolas Silva (nical)
208 start = "2020-11-12"
209 end = "2025-06-01"
210 notes = "I am the author of this crate."
212 [[wildcard-audits.euclid]]
213 who = "Nicolas Silva <nical@fastmail.com>"
214 criteria = "safe-to-deploy"
215 user-id = 1281 # Nicolas Silva (nical)
216 start = "2019-03-14"
217 end = "2025-04-25"
218 notes = "I wrote most of the commits in the euclid reprository and review every change that is not produced by me."
220 [[wildcard-audits.framehop]]
221 who = "Alex Franchuk <afranchuk@mozilla.com>"
222 criteria = "safe-to-deploy"
223 user-id = 20227 # Markus Stange (mstange)
224 start = "2022-03-12"
225 end = "2025-02-28"
226 notes = "This crate is written and solely maintained by a mozilla employee."
228 [[wildcard-audits.freetype]]
229 who = "Bobby Holley <bobbyholley@gmail.com>"
230 criteria = "safe-to-deploy"
231 user-id = 2396 # Josh Matthews (jdm)
232 start = "2020-02-28"
233 end = "2023-05-04"
234 renew = false
235 notes = "All code written or reviewed by Mozilla staff."
237 [[wildcard-audits.gleam]]
238 who = "Bobby Holley <bobbyholley@gmail.com>"
239 criteria = "safe-to-deploy"
240 user-id = 1039
241 start = "2019-03-01"
242 end = "2023-05-04"
243 renew = false
244 notes = "All code written or reviewed by Mozilla."
246 [[wildcard-audits.gleam]]
247 who = "Bobby Holley <bobbyholley@gmail.com>"
248 criteria = "safe-to-deploy"
249 user-id = 2396 # Josh Matthews (jdm)
250 start = "2019-03-18"
251 end = "2023-05-04"
252 renew = false
253 notes = "All code written or reviewed by Mozilla."
255 [[wildcard-audits.gleam]]
256 who = "Bobby Holley <bobbyholley@gmail.com>"
257 criteria = "safe-to-deploy"
258 user-id = 5946 # Jeff Muizelaar (jrmuizel)
259 start = "2023-04-21"
260 end = "2023-05-04"
261 renew = false
262 notes = "All code written or reviewed by Mozilla."
264 [[wildcard-audits.glean]]
265 who = "Chris H-C <chutten@mozilla.com>"
266 criteria = "safe-to-deploy"
267 user-id = 48 # Jan-Erik Rediger (badboy)
268 start = "2020-11-10"
269 end = "2025-02-12"
270 notes = "The Glean SDKs are maintained by the Glean Team at Mozilla."
272 [[wildcard-audits.glean]]
273 who = "Travis Long <tlong@mozilla.com>"
274 criteria = "safe-to-deploy"
275 user-id = 66068
276 start = "2024-02-12"
277 end = "2025-02-13"
279 [[wildcard-audits.glean-core]]
280 who = "Chris H-C <chutten@mozilla.com>"
281 criteria = "safe-to-deploy"
282 user-id = 48 # Jan-Erik Rediger (badboy)
283 start = "2019-09-24"
284 end = "2025-02-12"
285 notes = "The Glean SDKs are maintained by the Glean Team at Mozilla."
287 [[wildcard-audits.glean-core]]
288 who = "Travis Long <tlong@mozilla.com>"
289 criteria = "safe-to-deploy"
290 user-id = 66068
291 start = "2020-07-10"
292 end = "2025-02-13"
294 [[wildcard-audits.glslopt]]
295 who = "Jamie Nicol <jnicol@mozilla.com>"
296 criteria = "safe-to-deploy"
297 user-id = 84794 # Jamie Nicol (jamienicol)
298 start = "2020-04-07"
299 end = "2025-08-30"
301 [[wildcard-audits.io-surface]]
302 who = "Bobby Holley <bobbyholley@gmail.com>"
303 criteria = "safe-to-deploy"
304 user-id = 2396 # Josh Matthews (jdm)
305 start = "2019-07-23"
306 end = "2023-05-04"
307 renew = false
308 notes = "I've reviewed every source contribution that was neither authored nor reviewed by Mozilla."
310 [[wildcard-audits.macho-unwind-info]]
311 who = "Alex Franchuk <afranchuk@mozilla.com>"
312 criteria = "safe-to-deploy"
313 user-id = 20227 # Markus Stange (mstange)
314 start = "2022-01-31"
315 end = "2025-02-28"
316 notes = "This crate is written and solely maintained by a mozilla employee."
318 [[wildcard-audits.marionette]]
319 who = "Henrik Skupin <mail@hskupin.info>"
320 criteria = "safe-to-run"
321 user-id = 22262
322 start = "2020-11-03"
323 end = "2025-01-31"
324 notes = "Maintained by the DevTools team at Mozilla and has no unsafe code."
326 [[wildcard-audits.minidump]]
327 who = "Alex Franchuk <afranchuk@mozilla.com>"
328 criteria = "safe-to-deploy"
329 user-id = 72814 # Gabriele Svelto (gabrielesvelto)
330 start = "2022-11-30"
331 end = "2025-02-28"
332 notes = "This crate is written and maintained by mozilla employees."
334 [[wildcard-audits.minidump-common]]
335 who = "Alex Franchuk <afranchuk@mozilla.com>"
336 criteria = "safe-to-deploy"
337 user-id = 72814 # Gabriele Svelto (gabrielesvelto)
338 start = "2022-11-30"
339 end = "2025-02-28"
340 notes = "This crate is written and maintained by mozilla employees."
342 [[wildcard-audits.minidump-unwind]]
343 who = "Alex Franchuk <afranchuk@mozilla.com>"
344 criteria = "safe-to-deploy"
345 user-id = 72814 # Gabriele Svelto (gabrielesvelto)
346 start = "2023-05-17"
347 end = "2025-02-28"
348 notes = "This crate is written and maintained by mozilla employees."
350 [[wildcard-audits.mozdevice]]
351 who = "Henrik Skupin <mail@hskupin.info>"
352 criteria = "safe-to-run"
353 user-id = 22262
354 start = "2020-11-03"
355 end = "2025-01-31"
356 notes = "Maintained by the DevTools team at Mozilla and has no unsafe code."
358 [[wildcard-audits.mozprofile]]
359 who = "Henrik Skupin <mail@hskupin.info>"
360 criteria = "safe-to-deploy"
361 user-id = 22262
362 start = "2020-11-03"
363 end = "2025-01-31"
364 notes = "Maintained by the DevTools team at Mozilla and has no unsafe code."
366 [[wildcard-audits.mozrunner]]
367 who = "Henrik Skupin <mail@hskupin.info>"
368 criteria = "safe-to-deploy"
369 user-id = 22262
370 start = "2020-11-03"
371 end = "2025-01-31"
372 notes = "Maintained by the DevTools team at Mozilla and has no unsafe code."
374 [[wildcard-audits.mozversion]]
375 who = "Henrik Skupin <mail@hskupin.info>"
376 criteria = "safe-to-run"
377 user-id = 22262
378 start = "2020-11-03"
379 end = "2025-01-31"
380 notes = "Maintained by the DevTools team at Mozilla and has no unsafe code."
382 [[wildcard-audits.nss-gk-api]]
383 who = "John M. Schanck <jschanck@mozilla.com>"
384 criteria = "safe-to-deploy"
385 user-id = 175410 # John Schanck (jschanck)
386 start = "2022-11-14"
387 end = "2024-06-20"
388 notes = "Maintained by the CryptoEng team at Mozilla."
390 [[wildcard-audits.ohttp]]
391 who = "Martin Thomson <mt@lowentropy.net>"
392 criteria = "safe-to-deploy"
393 user-id = 128763 # Martin Thomson (martinthomson)
394 start = "2022-08-04"
395 end = "2024-03-09"
396 notes = "This code contains two cryptographic back ends.  No unsafe code is contained if the Rust `hpke` crate is used (the `rust-hpke` feature).  Using NSS (the `nss` feature) involves extensive use of bindings to the native code provided by NSS.  This interface uses wrappers that attempt to add safety to a fundamentally very dangerous library, but those wrappers have only been validated for use following the needs of this crate."
398 [[wildcard-audits.pe-unwind-info]]
399 who = "Alex Franchuk <afranchuk@mozilla.com>"
400 criteria = "safe-to-deploy"
401 user-id = 106639 # Alex Franchuk (afranchuk)
402 start = "2023-07-25"
403 end = "2025-02-28"
404 notes = "This crate is written and solely maintained by a mozilla employee."
406 [[wildcard-audits.qcms]]
407 who = "Jeff Muizelaar <jmuizelaar@mozilla.com>"
408 criteria = "safe-to-deploy"
409 user-id = 5946 # Jeff Muizelaar (jrmuizel)
410 start = "2020-11-05"
411 end = "2025-01-09"
412 notes = "Maintained by the Graphics team at Mozilla in mozilla-central."
414 [[wildcard-audits.rust_cascade]]
415 who = "Dana Keeler <dkeeler@mozilla.com>"
416 criteria = "safe-to-deploy"
417 user-id = 57462 # Dana Keeler (mozkeeler)
418 start = "2019-11-15"
419 end = "2024-04-24"
420 notes = "Written and maintained by the security engineering team at Mozilla."
422 [[wildcard-audits.unicode-normalization]]
423 who = "Manish Goregaokar <manishsmail@gmail.com>"
424 criteria = "safe-to-deploy"
425 user-id = 1139 # Manish Goregaokar (Manishearth)
426 start = "2019-11-06"
427 end = "2024-05-03"
428 notes = "All code written or reviewed by Manish"
430 [[wildcard-audits.unicode-segmentation]]
431 who = "Manish Goregaokar <manishsmail@gmail.com>"
432 criteria = "safe-to-deploy"
433 user-id = 1139 # Manish Goregaokar (Manishearth)
434 start = "2019-05-15"
435 end = "2024-05-03"
436 notes = "All code written or reviewed by Manish"
438 [[wildcard-audits.unicode-width]]
439 who = "Manish Goregaokar <manishsmail@gmail.com>"
440 criteria = "safe-to-deploy"
441 user-id = 1139 # Manish Goregaokar (Manishearth)
442 start = "2019-12-05"
443 end = "2024-05-03"
444 notes = "All code written or reviewed by Manish"
446 [[wildcard-audits.unicode-xid]]
447 who = "Manish Goregaokar <manishsmail@gmail.com>"
448 criteria = "safe-to-deploy"
449 user-id = 1139 # Manish Goregaokar (Manishearth)
450 start = "2019-07-25"
451 end = "2024-05-03"
452 notes = "All code written or reviewed by Manish"
454 [[wildcard-audits.uniffi]]
455 who = "Ben Dean-Kawamura <bdk@mozilla.com>"
456 criteria = "safe-to-deploy"
457 user-id = 127697 # bendk
458 start = "2021-10-27"
459 end = "2024-12-11"
460 notes = "Maintained by the Glean and Application Services teams"
462 [[wildcard-audits.uniffi]]
463 who = "Jan-Erik Rediger <jrediger@mozilla.com>"
464 criteria = "safe-to-deploy"
465 user-id = 48 # Jan-Erik Rediger (badboy)
466 start = "2022-05-05"
467 end = "2024-06-21"
468 notes = "Maintained by the Glean and Application Services teams"
470 [[wildcard-audits.uniffi_bindgen]]
471 who = "Ben Dean-Kawamura <bdk@mozilla.com>"
472 criteria = "safe-to-deploy"
473 user-id = 127697 # bendk
474 start = "2021-10-27"
475 end = "2024-12-11"
476 notes = "Maintained by the Glean and Application Services teams"
478 [[wildcard-audits.uniffi_bindgen]]
479 who = "Jan-Erik Rediger <jrediger@mozilla.com>"
480 criteria = "safe-to-deploy"
481 user-id = 48 # Jan-Erik Rediger (badboy)
482 start = "2022-05-05"
483 end = "2024-06-21"
484 notes = "Maintained by the Glean and Application Services teams"
486 [[wildcard-audits.uniffi_build]]
487 who = "Ben Dean-Kawamura <bdk@mozilla.com>"
488 criteria = "safe-to-deploy"
489 user-id = 127697 # bendk
490 start = "2021-10-27"
491 end = "2024-12-11"
492 notes = "Maintained by the Glean and Application Services teams"
494 [[wildcard-audits.uniffi_build]]
495 who = "Jan-Erik Rediger <jrediger@mozilla.com>"
496 criteria = "safe-to-deploy"
497 user-id = 48 # Jan-Erik Rediger (badboy)
498 start = "2022-05-05"
499 end = "2024-06-21"
500 notes = "Maintained by the Glean and Application Services teams"
502 [[wildcard-audits.uniffi_checksum_derive]]
503 who = "Ben Dean-Kawamura <bdk@mozilla.com>"
504 criteria = "safe-to-deploy"
505 user-id = 127697 # bendk
506 start = "2023-01-27"
507 end = "2024-12-11"
508 notes = "Maintained by the Glean and Application Services teams"
510 [[wildcard-audits.uniffi_checksum_derive]]
511 who = "Jan-Erik Rediger <jrediger@mozilla.com>"
512 criteria = "safe-to-deploy"
513 user-id = 48 # Jan-Erik Rediger (badboy)
514 start = "2022-12-16"
515 end = "2024-06-21"
516 notes = "Maintained by the Glean and Application Services teams"
518 [[wildcard-audits.uniffi_core]]
519 who = "Ben Dean-Kawamura <bdk@mozilla.com>"
520 criteria = "safe-to-deploy"
521 user-id = 127697 # bendk
522 start = "2023-01-27"
523 end = "2024-12-11"
524 notes = "Maintained by the Glean and Application Services teams"
526 [[wildcard-audits.uniffi_core]]
527 who = "Jan-Erik Rediger <jrediger@mozilla.com>"
528 criteria = "safe-to-deploy"
529 user-id = 48 # Jan-Erik Rediger (badboy)
530 start = "2023-06-21"
531 end = "2024-06-21"
532 notes = "Maintained by the Glean and Application Services teams"
534 [[wildcard-audits.uniffi_macros]]
535 who = "Ben Dean-Kawamura <bdk@mozilla.com>"
536 criteria = "safe-to-deploy"
537 user-id = 127697 # bendk
538 start = "2021-10-27"
539 end = "2024-12-11"
540 notes = "Maintained by the Glean and Application Services teams"
542 [[wildcard-audits.uniffi_macros]]
543 who = "Jan-Erik Rediger <jrediger@mozilla.com>"
544 criteria = "safe-to-deploy"
545 user-id = 48 # Jan-Erik Rediger (badboy)
546 start = "2022-05-05"
547 end = "2024-06-21"
548 notes = "Maintained by the Glean and Application Services teams"
550 [[wildcard-audits.uniffi_meta]]
551 who = "Ben Dean-Kawamura <bdk@mozilla.com>"
552 criteria = "safe-to-deploy"
553 user-id = 127697 # bendk
554 start = "2022-09-13"
555 end = "2024-12-11"
556 notes = "Maintained by the Glean and Application Services teams"
558 [[wildcard-audits.uniffi_meta]]
559 who = "Jan-Erik Rediger <jrediger@mozilla.com>"
560 criteria = "safe-to-deploy"
561 user-id = 48 # Jan-Erik Rediger (badboy)
562 start = "2022-08-31"
563 end = "2024-06-21"
564 notes = "Maintained by the Glean and Application Services teams"
566 [[wildcard-audits.uniffi_testing]]
567 who = "Ben Dean-Kawamura <bdk@mozilla.com>"
568 criteria = "safe-to-deploy"
569 user-id = 127697 # bendk
570 start = "2023-01-27"
571 end = "2024-12-11"
572 notes = "Maintained by the Glean and Application Services teams"
574 [[wildcard-audits.uniffi_testing]]
575 who = "Jan-Erik Rediger <jrediger@mozilla.com>"
576 criteria = "safe-to-deploy"
577 user-id = 48 # Jan-Erik Rediger (badboy)
578 start = "2022-12-16"
579 end = "2024-06-21"
580 notes = "Maintained by the Glean and Application Services teams"
582 [[wildcard-audits.uniffi_udl]]
583 who = "Ben Dean-Kawamura <bdk@mozilla.com>"
584 criteria = "safe-to-deploy"
585 user-id = 127697 # bendk
586 start = "2023-10-18"
587 end = "2024-12-11"
588 notes = "Maintained by the Glean and Application Services teams"
590 [[wildcard-audits.utf8_iter]]
591 who = "Makoto Kato <m_kato@ga2.so-net.ne.jp>"
592 criteria = "safe-to-deploy"
593 user-id = 4484 # Henri Sivonen (hsivonen)
594 start = "2022-04-19"
595 end = "2024-06-16"
596 notes = "Maintained by Henri Sivonen who works at Mozilla."
598 [[wildcard-audits.webdriver]]
599 who = "Henrik Skupin <mail@hskupin.info>"
600 criteria = "safe-to-deploy"
601 user-id = 22262
602 start = "2020-11-03"
603 end = "2025-01-31"
604 notes = "Maintained by the DevTools team at Mozilla and has no unsafe code."
606 [[audits.aa-stroke]]
607 who = "Lee Salzman <lsalzman@mozilla.com>"
608 criteria = "safe-to-deploy"
609 version = "0.1.0"
610 notes = "Written and maintained by Gfx team at Mozilla."
612 [[audits.ahash]]
613 who = "Mike Hommey <mh+mozilla@glandium.org>"
614 criteria = "safe-to-deploy"
615 delta = "0.7.6 -> 0.7.8"
617 [[audits.ahash]]
618 who = "Erich Gubler <erichdongubler@gmail.com>"
619 criteria = "safe-to-deploy"
620 delta = "0.8.7 -> 0.8.11"
622 [[audits.aho-corasick]]
623 who = "Mike Hommey <mh+mozilla@glandium.org>"
624 criteria = "safe-to-deploy"
625 delta = "0.7.18 -> 0.7.20"
627 [[audits.allocator-api2]]
628 who = "Nicolas Silva <nical@fastmail.com>"
629 criteria = "safe-to-deploy"
630 version = "0.2.18"
632 [[audits.alsa]]
633 who = "Mike Hommey <mh+mozilla@glandium.org>"
634 criteria = "safe-to-deploy"
635 delta = "0.4.3 -> 0.7.0"
637 [[audits.alsa]]
638 who = "Mike Hommey <mh+mozilla@glandium.org>"
639 criteria = "safe-to-deploy"
640 delta = "0.7.0 -> 0.8.1"
642 [[audits.android_logger]]
643 who = "Jan-Erik Rediger <jrediger@mozilla.com>"
644 criteria = "safe-to-deploy"
645 version = "0.11.0"
646 notes = "Small crate, wrapping Android log functionality, reviewed by janerik"
648 [[audits.android_logger]]
649 who = "Jan-Erik Rediger <jrediger@mozilla.com>"
650 criteria = "safe-to-deploy"
651 delta = "0.11.0 -> 0.11.1"
652 notes = "Small crate, wrapping Android log functionality, now switched to properly using MaybeUninit"
654 [[audits.android_logger]]
655 who = "Mike Hommey <mh+mozilla@glandium.org>"
656 criteria = "safe-to-deploy"
657 delta = "0.11.1 -> 0.11.3"
659 [[audits.android_logger]]
660 who = "Chris H-C <chutten@mozilla.com>"
661 criteria = "safe-to-deploy"
662 delta = "0.11.3 -> 0.12.0"
663 notes = "Small wrapper crate. This update fixes log level filtering."
665 [[audits.android_system_properties]]
666 who = "Nicolas Silva <nical@fastmail.com>"
667 criteria = "safe-to-deploy"
668 version = "0.1.2"
669 notes = "I wrote this crate, reviewed by jimb. It is mostly a Rust port of some C++ code we already ship."
671 [[audits.android_system_properties]]
672 who = "Mike Hommey <mh+mozilla@glandium.org>"
673 criteria = "safe-to-deploy"
674 delta = "0.1.2 -> 0.1.4"
676 [[audits.android_system_properties]]
677 who = "Mike Hommey <mh+mozilla@glandium.org>"
678 criteria = "safe-to-deploy"
679 delta = "0.1.4 -> 0.1.5"
681 [[audits.any_all_workaround]]
682 who = "Henri Sivonen <hsivonen@hsivonen.fi>"
683 criteria = "safe-to-deploy"
684 version = "0.1.0"
685 notes = "The little code that is in this crate I reviewed and modified from packed_simd (which has previously been vendored in full instead of just this small part)."
687 [[audits.any_all_workaround]]
688 who = "Henri Sivonen <hsivonen@hsivonen.fi>"
689 criteria = "safe-to-deploy"
690 delta = "0.1.0 -> 0.1.0@git:7fb1b7034c9f172aade21ee1c8554e8d8a48af80"
691 importable = false
692 notes = "This is a trivial workaround copied from elsewhere in m-c, specifically qcms."
694 [[audits.anyhow]]
695 who = "Mike Hommey <mh+mozilla@glandium.org>"
696 criteria = "safe-to-deploy"
697 delta = "1.0.57 -> 1.0.61"
699 [[audits.anyhow]]
700 who = "Bobby Holley <bobbyholley@gmail.com>"
701 criteria = "safe-to-deploy"
702 delta = "1.0.58 -> 1.0.57"
703 notes = "No functional differences, just CI config and docs."
705 [[audits.anyhow]]
706 who = "Mike Hommey <mh+mozilla@glandium.org>"
707 criteria = "safe-to-deploy"
708 delta = "1.0.61 -> 1.0.62"
710 [[audits.anyhow]]
711 who = "Mike Hommey <mh+mozilla@glandium.org>"
712 criteria = "safe-to-deploy"
713 delta = "1.0.62 -> 1.0.68"
715 [[audits.anyhow]]
716 who = "Mike Hommey <mh+mozilla@glandium.org>"
717 criteria = "safe-to-deploy"
718 delta = "1.0.68 -> 1.0.69"
720 [[audits.app_units]]
721 who = "Emilio Cobos Álvarez <emilio@crisal.io>"
722 criteria = "safe-to-deploy"
723 version = "0.7.1"
724 notes = """
725 I'm pretty familiar with this crate. It provides a fixed-point numeric type.
726 The code is pretty straight-forward, there's no unsafe code at all.
729 [[audits.app_units]]
730 who = "Nicolas Silva <nical@fastmail.com>"
731 criteria = "safe-to-deploy"
732 version = "0.7.3"
734 [[audits.app_units]]
735 who = "Emilio Cobos Álvarez <emilio@crisal.io>"
736 criteria = "safe-to-deploy"
737 delta = "0.7.1 -> 0.7.2"
738 notes = "Adding repr(transparent) plus a couple minor clean-ups, no functional changes from 0.7.1."
740 [[audits.arbitrary]]
741 who = "Mike Hommey <mh+mozilla@glandium.org>"
742 criteria = "safe-to-run"
743 delta = "1.1.0 -> 1.1.1"
745 [[audits.arbitrary]]
746 who = "Mike Hommey <mh+mozilla@glandium.org>"
747 criteria = "safe-to-run"
748 delta = "1.1.1 -> 1.1.3"
750 [[audits.arbitrary]]
751 who = "Mike Hommey <mh+mozilla@glandium.org>"
752 criteria = "safe-to-run"
753 delta = "1.1.3 -> 1.2.0"
755 [[audits.arbitrary]]
756 who = "Mike Hommey <mh+mozilla@glandium.org>"
757 criteria = "safe-to-run"
758 delta = "1.2.0 -> 1.2.3"
760 [[audits.arraystring]]
761 who = "Henri Sivonen <hsivonen@hsivonen.fi>"
762 criteria = "safe-to-deploy"
763 version = "0.3.0"
765 [[audits.arrayvec]]
766 who = "Alex Franchuk <afranchuk@mozilla.com>"
767 criteria = "safe-to-deploy"
768 delta = "0.7.2 -> 0.7.6"
769 notes = "Manually verified new unsafe pointer arithmetic."
771 [[audits.ash]]
772 who = "Jim Blandy <jimb@red-bean.com>"
773 criteria = "safe-to-deploy"
774 delta = "0.37.0+1.3.209 -> 0.37.1+1.3.235"
775 notes = """
776 Nicolas Silva, Jim Blandy, and Teodor Tanasoaia audited ash master
777 branch commits from e43e9c0c to 6bd82768 inclusive.
780 [[audits.ash]]
781 who = "Nicolas Silva <nical@fastmail.com>"
782 criteria = "safe-to-deploy"
783 delta = "0.37.1+1.3.235 -> 0.37.2+1.3.238"
785 [[audits.ash]]
786 who = "Teodor Tanasoaia <ttanasoaia@mozilla.com>"
787 criteria = "safe-to-deploy"
788 delta = "0.37.2+1.3.238 -> 0.37.3+1.3.251"
790 [[audits.ash]]
791 who = "Erich Gubler <erichdongubler@gmail.com>"
792 criteria = "safe-to-deploy"
793 delta = "0.37.3+1.3.251 -> 0.38.0+1.3.281"
794 notes = """
795 There are many sweeping changes to code generation that make this review intimidating, at first.
796 However, I have audited all hand-written code, and vetted changes to the code generator (with some
797 auditing of generated output to ensure correspondence to my mental model). Vulkan is an inherently
798 unsafe API, but this crate makes many of the preparatory steps for calling Vulkan APIs safer and
799 easier to use.
802 [[audits.ashmem]]
803 who = "Matthew Gregan <kinetik@flim.org>"
804 criteria = "safe-to-deploy"
805 version = "0.1.2"
806 notes = """
807 Small unsafe wrapper around Android 8.0's ASharedMemory native API that falls
808 back to older private ioctl-based API at runtime on earlier OS releases.  The
809 shim code is small and doesn't inspect the API arguments, so is unlikely to
810 expose any safety issues beyond those presented by the native OS API.
813 [[audits.askama]]
814 who = "Bobby Holley <bobbyholley@gmail.com>"
815 criteria = "safe-to-deploy"
816 version = "0.11.1"
817 notes = """
818 Just contains some traits and re-exports for use by a broader package of related
819 crates. No unsafe code or ambient capability usage.
822 [[audits.async-task]]
823 who = "Nika Layzell <nika@thelayzells.com>"
824 criteria = "safe-to-deploy"
825 delta = "4.0.3 -> 4.0.3@git:f6488e35beccb26eb6e85847b02aa78a42cd3d0e"
826 notes = "Recorded by bholley, confirmed over slack."
828 [[audits.async-task]]
829 who = "Nika Layzell <nika@thelayzells.com>"
830 criteria = "safe-to-deploy"
831 delta = "4.0.3 -> 4.3.0"
832 notes = "Main addition is the new FallibleTask type, which I implemented. No risky unsafe code changes."
834 [[audits.async-trait]]
835 who = "Mike Hommey <mh+mozilla@glandium.org>"
836 criteria = "safe-to-deploy"
837 delta = "0.1.56 -> 0.1.57"
839 [[audits.async-trait]]
840 who = "Mike Hommey <mh+mozilla@glandium.org>"
841 criteria = "safe-to-deploy"
842 delta = "0.1.57 -> 0.1.60"
844 [[audits.async-trait]]
845 who = "Mike Hommey <mh+mozilla@glandium.org>"
846 criteria = "safe-to-deploy"
847 delta = "0.1.60 -> 0.1.64"
849 [[audits.atomic_refcell]]
850 who = "Bobby Holley <bholley@mozilla.com>"
851 criteria = "safe-to-deploy"
852 version = "0.1.8"
853 notes = "I maintain this crate and have reviewed every line."
855 [[audits.atomic_refcell]]
856 who = "Mike Hommey <mh+mozilla@glandium.org>"
857 criteria = "safe-to-deploy"
858 delta = "0.1.8 -> 0.1.9"
860 [[audits.audio-mixer]]
861 who = "Chun-Min Chang <chun.m.chang@gmail.com>"
862 criteria = "safe-to-deploy"
863 version = "0.1.2"
864 notes = "audio-mixer is a Mozilla-developed package."
866 [[audits.audio-mixer]]
867 who = "Mike Hommey <mh+mozilla@glandium.org>"
868 criteria = "safe-to-deploy"
869 delta = "0.1.2 -> 0.1.3"
871 [[audits.audio-mixer]]
872 who = "Paul Adenot <paul@paul.cx>"
873 criteria = "safe-to-deploy"
874 delta = "0.1.3 -> 0.2.0"
875 notes = "(I wrote all of this code)"
877 [[audits.authenticator]]
878 who = "John M. Schanck <jschanck@mozilla.com>"
879 criteria = "safe-to-deploy"
880 version = "0.4.0-alpha.13"
881 notes = "Maintained by the CryptoEng team at Mozilla."
883 [[audits.authenticator]]
884 who = "John M. Schanck <jschanck@mozilla.com>"
885 criteria = "safe-to-deploy"
886 delta = "0.4.0-alpha.24 -> 0.4.0"
888 [[audits.autocfg]]
889 who = "Josh Stone <jistone@redhat.com>"
890 criteria = "safe-to-deploy"
891 version = "1.1.0"
892 notes = "All code written or reviewed by Josh Stone."
894 [[audits.base64]]
895 who = "Mike Hommey <mh+mozilla@glandium.org>"
896 criteria = "safe-to-deploy"
897 delta = "0.13.0 -> 0.13.1"
899 [[audits.bindgen]]
900 who = "Emilio Cobos Álvarez <emilio@crisal.io>"
901 criteria = "safe-to-deploy"
902 version = "0.59.2"
903 notes = "I'm the primary author and maintainer of the crate."
905 [[audits.bindgen]]
906 who = "Emilio Cobos Álvarez <emilio@crisal.io>"
907 criteria = "safe-to-deploy"
908 delta = "0.59.2 -> 0.63.0"
910 [[audits.bindgen]]
911 who = "Mike Hommey <mh+mozilla@glandium.org>"
912 criteria = "safe-to-deploy"
913 delta = "0.63.0 -> 0.64.0"
915 [[audits.bindgen]]
916 who = "Mike Hommey <mh+mozilla@glandium.org>"
917 criteria = "safe-to-deploy"
918 delta = "0.64.0 -> 0.66.1"
920 [[audits.bindgen]]
921 who = "Mike Hommey <mh+mozilla@glandium.org>"
922 criteria = "safe-to-deploy"
923 delta = "0.66.1 -> 0.68.1"
925 [[audits.bindgen]]
926 who = "Andreas Pehrson <apehrson@mozilla.com>"
927 criteria = "safe-to-deploy"
928 delta = "0.68.1 -> 0.69.1"
930 [[audits.bindgen]]
931 who = "Mike Hommey <mh+mozilla@glandium.org>"
932 criteria = "safe-to-deploy"
933 delta = "0.69.1 -> 0.69.2"
935 [[audits.bindgen]]
936 who = "Emilio Cobos Álvarez <emilio@crisal.io>"
937 criteria = "safe-to-deploy"
938 delta = "0.69.2 -> 0.69.4"
940 [[audits.bit-set]]
941 who = "Aria Beingessner <a.beingessner@gmail.com>"
942 criteria = "safe-to-deploy"
943 version = "0.5.2"
944 notes = "Another crate I own via contain-rs that is ancient and maintenance mode, no known issues."
946 [[audits.bit-set]]
947 who = "Mike Hommey <mh+mozilla@glandium.org>"
948 criteria = "safe-to-deploy"
949 delta = "0.5.2 -> 0.5.3"
951 [[audits.bit-set]]
952 who = "Teodor Tanasoaia <ttanasoaia@mozilla.com>"
953 criteria = "safe-to-deploy"
954 delta = "0.5.3 -> 0.6.0"
956 [[audits.bit-set]]
957 who = "Jim Blandy <jimb@red-bean.com>"
958 criteria = "safe-to-deploy"
959 delta = "0.6.0 -> 0.8.0"
961 [[audits.bit-vec]]
962 who = "Aria Beingessner <a.beingessner@gmail.com>"
963 criteria = "safe-to-deploy"
964 version = "0.6.3"
965 notes = "Another crate I own via contain-rs that is ancient and in maintenance mode but otherwise perfectly fine."
967 [[audits.bit-vec]]
968 who = "Teodor Tanasoaia <ttanasoaia@mozilla.com>"
969 criteria = "safe-to-deploy"
970 delta = "0.6.3 -> 0.7.0"
972 [[audits.bit-vec]]
973 who = "Jim Blandy <jimb@red-bean.com>"
974 criteria = "safe-to-deploy"
975 delta = "0.7.0 -> 0.8.0"
977 [[audits.bitflags]]
978 who = "Alex Franchuk <afranchuk@mozilla.com>"
979 criteria = "safe-to-deploy"
980 delta = "1.3.2 -> 2.0.2"
981 notes = "Removal of some unsafe code/methods. No changes to externals, just some refactoring (mostly internal)."
983 [[audits.bitflags]]
984 who = "Nicolas Silva <nical@fastmail.com>"
985 criteria = "safe-to-deploy"
986 delta = "2.0.2 -> 2.1.0"
988 [[audits.bitflags]]
989 who = "Teodor Tanasoaia <ttanasoaia@mozilla.com>"
990 criteria = "safe-to-deploy"
991 delta = "2.2.1 -> 2.3.2"
993 [[audits.bitflags]]
994 who = "Mike Hommey <mh+mozilla@glandium.org>"
995 criteria = "safe-to-deploy"
996 delta = "2.3.3 -> 2.4.0"
998 [[audits.bitflags]]
999 who = [
1000     "Teodor Tanasoaia <ttanasoaia@mozilla.com>",
1001     "Erich Gubler <erichdongubler@gmail.com>",
1003 criteria = "safe-to-deploy"
1004 delta = "2.6.0 -> 2.7.0"
1006 [[audits.bitreader]]
1007 who = "Bobby Holley <bobbyholley@gmail.com>"
1008 criteria = "safe-to-deploy"
1009 delta = "0.3.7 -> 0.3.6"
1010 notes = "No material changes."
1012 [[audits.block-buffer]]
1013 who = "Mike Hommey <mh+mozilla@glandium.org>"
1014 criteria = "safe-to-deploy"
1015 delta = "0.10.2 -> 0.10.3"
1017 [[audits.build-parallel]]
1018 who = "Jeff Muizelaar <jmuizelaar@mozilla.com>"
1019 criteria = "safe-to-deploy"
1020 version = "0.1.2"
1022 [[audits.bumpalo]]
1023 who = "Bobby Holley <bobbyholley@gmail.com>"
1024 criteria = "safe-to-run"
1025 delta = "3.9.1 -> 3.10.0"
1026 notes = """
1027 Some nontrivial functional changes but certainly meets the no-malware bar of
1028 safe-to-run. If we needed safe-to-deploy for this in m-c I'd ask Nick to re-
1029 certify this version, but we don't, so this is fine for now.
1032 [[audits.bumpalo]]
1033 who = "Mike Hommey <mh+mozilla@glandium.org>"
1034 criteria = "safe-to-run"
1035 delta = "3.11.1 -> 3.12.0"
1037 [[audits.bytes]]
1038 who = "Mike Hommey <mh+mozilla@glandium.org>"
1039 criteria = "safe-to-deploy"
1040 delta = "1.1.0 -> 1.2.1"
1042 [[audits.bytes]]
1043 who = "Mike Hommey <mh+mozilla@glandium.org>"
1044 criteria = "safe-to-deploy"
1045 delta = "1.2.1 -> 1.3.0"
1047 [[audits.bytes]]
1048 who = "Mike Hommey <mh+mozilla@glandium.org>"
1049 criteria = "safe-to-deploy"
1050 delta = "1.3.0 -> 1.4.0"
1052 [[audits.calendrical_calculations]]
1053 who = "André Bargull <andre.bargull@gmail.com>"
1054 criteria = "safe-to-deploy"
1055 version = "0.1.0"
1056 notes = "This has no unsafe code and uses no ambient capabilities."
1058 [[audits.calendrical_calculations]]
1059 who = "André Bargull <andre.bargull@gmail.com>"
1060 criteria = "safe-to-deploy"
1061 delta = "0.1.0 -> 0.1.1"
1063 [[audits.camino]]
1064 who = "Mike Hommey <mh+mozilla@glandium.org>"
1065 criteria = "safe-to-deploy"
1066 delta = "1.0.9 -> 1.1.1"
1068 [[audits.camino]]
1069 who = "Mike Hommey <mh+mozilla@glandium.org>"
1070 criteria = "safe-to-deploy"
1071 delta = "1.1.1 -> 1.1.2"
1073 [[audits.camino]]
1074 who = "Bobby Holley <bobbyholley@gmail.com>"
1075 criteria = "safe-to-deploy"
1076 delta = "1.1.4 -> 1.1.2"
1077 notes = "Older version, just lacks a few APIs and tests from the newer version."
1079 [[audits.cargo_metadata]]
1080 who = "Jan-Erik Rediger <jrediger@mozilla.com>"
1081 criteria = "safe-to-deploy"
1082 version = "0.15.2"
1083 notes = "I reviewed the whole code base. Parser for the output of cargo-metadata, relying mostly on serde. No unsafe code used."
1085 [[audits.cargo_metadata]]
1086 who = "Mike Hommey <mh+mozilla@glandium.org>"
1087 criteria = "safe-to-deploy"
1088 delta = "0.15.2 -> 0.15.3"
1090 [[audits.cc]]
1091 who = "Mike Hommey <mh+mozilla@glandium.org>"
1092 criteria = "safe-to-deploy"
1093 delta = "1.0.73 -> 1.0.78"
1095 [[audits.cc]]
1096 who = "Erich Gubler <erichdongubler@gmail.com>"
1097 criteria = "safe-to-deploy"
1098 delta = "1.0.89 -> 1.2.10"
1100 [[audits.cfg_aliases]]
1101 who = "Alex Franchuk <afranchuk@mozilla.com>"
1102 criteria = "safe-to-deploy"
1103 delta = "0.1.1 -> 0.2.1"
1104 notes = "Very minor changes."
1106 [[audits.cgl]]
1107 who = "Sotaro Ikeda <sotaro.ikeda.g@gmail.com>"
1108 criteria = "safe-to-deploy"
1109 version = "0.3.2"
1111 [[audits.chardetng]]
1112 who = "Henri Sivonen <hsivonen@hsivonen.fi>"
1113 criteria = "safe-to-deploy"
1114 version = "0.1.9"
1115 notes = "I, Henri Sivonen, wrote this (safe-code-only) crate for Gecko even though the crate is published via crates.io."
1117 [[audits.chardetng]]
1118 who = "Bobby Holley <bobbyholley@gmail.com>"
1119 criteria = "safe-to-deploy"
1120 delta = "0.1.9 -> 0.1.9@git:3484d3e3ebdc8931493aa5df4d7ee9360a90e76b"
1122 [[audits.chardetng_c]]
1123 who = "Henri Sivonen <hsivonen@hsivonen.fi>"
1124 criteria = "safe-to-deploy"
1125 version = "0.1.2"
1126 notes = "I, Henri Sivonen, wrote this crate for Gecko even though it is published via crates.io. The buffer input assumes Rust slice constraints for the start pointer. In Gecko, this is taken care of by mozilla::Span, but the C API doesn't conform to idiomatic C constraints on this point."
1128 [[audits.chardetng_c]]
1129 who = "Bobby Holley <bobbyholley@gmail.com>"
1130 criteria = "safe-to-deploy"
1131 delta = "0.1.2 -> 0.1.2@git:ed8a4c6f900a90d4dbc1d64b856e61490a1c3570"
1133 [[audits.circular]]
1134 who = "Alex Franchuk <afranchuk@mozilla.com>"
1135 criteria = "safe-to-deploy"
1136 version = "0.3.0"
1137 notes = "No dependencies. Unsafe code is necessary to provide functionality and was manually verified to be correct."
1139 [[audits.clang-sys]]
1140 who = "Mike Hommey <mh+mozilla@glandium.org>"
1141 criteria = "safe-to-deploy"
1142 delta = "1.3.3 -> 1.4.0"
1144 [[audits.clang-sys]]
1145 who = "Mike Hommey <mh+mozilla@glandium.org>"
1146 criteria = "safe-to-deploy"
1147 delta = "1.4.0 -> 1.6.0"
1149 [[audits.clang-sys]]
1150 who = "Erich Gubler <erichdongubler@gmail.com>"
1151 criteria = "safe-to-deploy"
1152 delta = "1.6.0 -> 1.7.0"
1153 notes = """
1154 Adds several new symbols for Clang versions 11.0, 12.0, 16.0, and 17.0, conditionally enabled based
1155 on Cargo feature flags. Some other minor internal refactors were implemented that shouldn't change
1156 functionality otherwise.
1159 [[audits.clap-verbosity-flag]]
1160 who = "Kershaw Chang <kershaw@mozilla.com>"
1161 criteria = "safe-to-run"
1162 version = "2.2.0"
1164 [[audits.clap-verbosity-flag]]
1165 who = "Max Inden <mail@max-inden.de>"
1166 criteria = "safe-to-run"
1167 delta = "2.2.0 -> 3.0.1"
1169 [[audits.clap_lex]]
1170 who = "Mike Hommey <mh+mozilla@glandium.org>"
1171 criteria = "safe-to-deploy"
1172 delta = "0.2.0 -> 0.2.2"
1174 [[audits.clap_lex]]
1175 who = "Mike Hommey <mh+mozilla@glandium.org>"
1176 criteria = "safe-to-deploy"
1177 delta = "0.2.2 -> 0.2.4"
1179 [[audits.clubcard]]
1180 who = "John M. Schanck <jschanck@mozilla.com>"
1181 criteria = "safe-to-deploy"
1182 version = "0.3.1"
1183 notes = "This crate is maintained by the CryptoEng team at Mozilla and it contains no unsafe code."
1185 [[audits.clubcard-crlite]]
1186 who = "John M. Schanck <jschanck@mozilla.com>"
1187 criteria = "safe-to-deploy"
1188 version = "0.2.1"
1189 notes = "This crate is maintained by the CryptoEng team at Mozilla and it contains no unsafe code."
1191 [[audits.comedy]]
1192 who = "Nick Alexander <nalexander@mozilla.com>"
1193 criteria = "safe-to-deploy"
1194 version = "0.2.0"
1195 notes = """
1196 The comedy crate was written by Adam Gashlin for Mozilla's use.  The entire
1197 comedy 0.2.0 crate is full of `unsafe` code and makes many assumptions about
1198 memory and layout, but there is no particular processing of untrusted input
1199 here.
1202 [[audits.cookie]]
1203 who = "Mike Hommey <mh+mozilla@glandium.org>"
1204 criteria = "safe-to-run"
1205 delta = "0.16.0 -> 0.16.2"
1207 [[audits.core-foundation]]
1208 who = "Teodor Tanasoaia <ttanasoaia@mozilla.com>"
1209 criteria = "safe-to-deploy"
1210 delta = "0.9.3 -> 0.9.4"
1211 notes = "I've reviewed every source contribution that was neither authored nor reviewed by Mozilla."
1213 [[audits.core-graphics]]
1214 who = "Teodor Tanasoaia <ttanasoaia@mozilla.com>"
1215 criteria = "safe-to-deploy"
1216 delta = "0.22.3 -> 0.23.1"
1218 [[audits.core-graphics-types]]
1219 who = "Teodor Tanasoaia <ttanasoaia@mozilla.com>"
1220 criteria = "safe-to-deploy"
1221 delta = "0.1.1 -> 0.1.2"
1223 [[audits.core-graphics-types]]
1224 who = "Teodor Tanasoaia <ttanasoaia@mozilla.com>"
1225 criteria = "safe-to-deploy"
1226 delta = "0.1.2 -> 0.1.3"
1227 notes = "I've reviewed every source contribution that was neither authored nor reviewed by Mozilla."
1229 [[audits.core-text]]
1230 who = "Teodor Tanasoaia <ttanasoaia@mozilla.com>"
1231 criteria = "safe-to-deploy"
1232 delta = "19.2.0 -> 20.0.0"
1234 [[audits.core-text]]
1235 who = "Jonathan Kew <jfkthame@gmail.com>"
1236 criteria = "safe-to-deploy"
1237 delta = "20.0.0 -> 20.1.0"
1238 notes = """
1239 The bulk of the 20.0.0 -> 20.1.0 changes were purely cosmetic clippy and rustfmt changes.
1241 The only substantive change was the addition of wrappers to expose two additional Core Text APIs,
1242 the variants of CTFontCreateWithName and CTFontCreateWithFontDescriptor that accept a CTFontOptions
1243 parameter. These are directly parallel to the existing versions without CTFontOptions, and do not
1244 introduce any new forms of risk.
1247 [[audits.core_maths]]
1248 who = "Makoto Kato <m_kato@ga2.so-net.ne.jp>"
1249 criteria = "safe-to-deploy"
1250 version = "0.1.0"
1252 [[audits.coreaudio-sys]]
1253 who = "Mike Hommey <mh+mozilla@glandium.org>"
1254 criteria = "safe-to-deploy"
1255 delta = "0.2.10 -> 0.2.11"
1257 [[audits.coreaudio-sys]]
1258 who = "Mike Hommey <mh+mozilla@glandium.org>"
1259 criteria = "safe-to-deploy"
1260 delta = "0.2.11 -> 0.2.12"
1262 [[audits.coreaudio-sys]]
1263 who = "Mike Hommey <mh+mozilla@glandium.org>"
1264 criteria = "safe-to-deploy"
1265 delta = "0.2.12 -> 0.2.13"
1267 [[audits.coreaudio-sys]]
1268 who = "Andreas Pehrson <apehrson@mozilla.com>"
1269 criteria = "safe-to-deploy"
1270 delta = "0.2.13 -> 0.2.14"
1272 [[audits.cose]]
1273 who = "Mathew Hodson <mathew.hodson@gmail.com>"
1274 criteria = "safe-to-deploy"
1275 delta = "0.1.4 -> 0.1.4@git:43c22248d136c8b38fe42ea709d08da6355cf04b"
1277 [[audits.cpufeatures]]
1278 who = "Mike Hommey <mh+mozilla@glandium.org>"
1279 criteria = "safe-to-deploy"
1280 delta = "0.2.2 -> 0.2.4"
1282 [[audits.cpufeatures]]
1283 who = "Mike Hommey <mh+mozilla@glandium.org>"
1284 criteria = "safe-to-deploy"
1285 delta = "0.2.4 -> 0.2.5"
1287 [[audits.cpufeatures]]
1288 who = "Gabriele Svelto <gsvelto@mozilla.com>"
1289 criteria = "safe-to-deploy"
1290 delta = "0.2.7 -> 0.2.8"
1291 notes = "This release contains a single fix for an issue that affected Firefox"
1293 [[audits.crash-context]]
1294 who = "Gabriele Svelto <gsvelto@mozilla.com>"
1295 criteria = "safe-to-deploy"
1296 version = "0.5.1"
1297 notes = "Mozilla employees contributed to this crate and the remaining code was fully audited"
1299 [[audits.crash-context]]
1300 who = "Alex Franchuk <afranchuk@mozilla.com>"
1301 criteria = "safe-to-deploy"
1302 delta = "0.5.1 -> 0.6.0"
1303 notes = """
1304 There are few changes. The main change is the removal of `winapi` in favor of
1305 manually-generated bindings (which are minimal). The few small bugfixes are
1306 sound.
1309 [[audits.crash-context]]
1310 who = "Gabriele Svelto <gsvelto@mozilla.com>"
1311 criteria = "safe-to-deploy"
1312 delta = "0.6.0 -> 0.6.1"
1314 [[audits.crc32fast]]
1315 who = "Alex Franchuk <afranchuk@mozilla.com>"
1316 criteria = "safe-to-deploy"
1317 delta = "1.3.2 -> 1.4.2"
1318 notes = "Minor, safe changes."
1320 [[audits.crossbeam-channel]]
1321 who = "Mike Hommey <mh+mozilla@glandium.org>"
1322 criteria = "safe-to-deploy"
1323 delta = "0.5.4 -> 0.5.6"
1325 [[audits.crossbeam-channel]]
1326 who = "Glenn Watson <git@intuitionlibrary.com>"
1327 criteria = "safe-to-deploy"
1328 delta = "0.5.12 -> 0.5.13"
1330 [[audits.crossbeam-deque]]
1331 who = "Mike Hommey <mh+mozilla@glandium.org>"
1332 criteria = "safe-to-deploy"
1333 delta = "0.8.1 -> 0.8.2"
1335 [[audits.crossbeam-epoch]]
1336 who = "Mike Hommey <mh+mozilla@glandium.org>"
1337 criteria = "safe-to-deploy"
1338 delta = "0.9.8 -> 0.9.10"
1340 [[audits.crossbeam-epoch]]
1341 who = "Mike Hommey <mh+mozilla@glandium.org>"
1342 criteria = "safe-to-deploy"
1343 delta = "0.9.10 -> 0.9.13"
1345 [[audits.crossbeam-epoch]]
1346 who = "Mike Hommey <mh+mozilla@glandium.org>"
1347 criteria = "safe-to-deploy"
1348 delta = "0.9.13 -> 0.9.14"
1350 [[audits.crossbeam-queue]]
1351 who = "Matthew Gregan <kinetik@flim.org>"
1352 criteria = "safe-to-deploy"
1353 version = "0.3.8"
1355 [[audits.crossbeam-utils]]
1356 who = "Mike Hommey <mh+mozilla@glandium.org>"
1357 criteria = "safe-to-deploy"
1358 delta = "0.8.8 -> 0.8.11"
1360 [[audits.crossbeam-utils]]
1361 who = "Mike Hommey <mh+mozilla@glandium.org>"
1362 criteria = "safe-to-deploy"
1363 delta = "0.8.11 -> 0.8.14"
1365 [[audits.crossbeam-utils]]
1366 who = "Alex Franchuk <afranchuk@mozilla.com>"
1367 criteria = "safe-to-deploy"
1368 delta = "0.8.19 -> 0.8.20"
1369 notes = "Minor changes."
1371 [[audits.crypto-common]]
1372 who = "Mike Hommey <mh+mozilla@glandium.org>"
1373 criteria = "safe-to-deploy"
1374 delta = "0.1.3 -> 0.1.6"
1376 [[audits.cssparser]]
1377 who = "Emilio Cobos Álvarez <emilio@crisal.io>"
1378 criteria = "safe-to-deploy"
1379 version = "0.29.6"
1380 notes = """
1381 I've reviewed or authored most of the recent changes to this library, and it
1382 was developed by other mozilla folks. Unsafe code there is reasonable (utf-8
1383 casts for serialization and parsing).
1386 [[audits.cssparser]]
1387 who = "Bobby Holley <bobbyholley@gmail.com>"
1388 criteria = "safe-to-deploy"
1389 delta = "0.29.6 -> 0.31.0"
1390 notes = """
1391 All the changes in this release were authored by Mozilla staff, except the
1392 uninit_array stuff, which looks fine.
1395 [[audits.cssparser]]
1396 who = "Mike Hommey <mh+mozilla@glandium.org>"
1397 criteria = "safe-to-deploy"
1398 delta = "0.31.0 -> 0.31.2"
1400 [[audits.cssparser]]
1401 who = "Emilio Cobos Álvarez <emilio@crisal.io>"
1402 criteria = "safe-to-deploy"
1403 delta = "0.31.2 -> 0.32.0"
1404 notes = "All changes were either authored or reviewed by Mozilla employees."
1406 [[audits.cssparser]]
1407 who = "Emilio Cobos Álvarez <emilio@crisal.io>"
1408 criteria = "safe-to-deploy"
1409 delta = "0.32.0 -> 0.33.0"
1410 notes = """
1411 Mozilla authored. Breaking changes from 0.32 involve splitting color APIs into
1412 their own crate and removing an unused line number offset mechanism.
1415 [[audits.cssparser]]
1416 who = "Emilio Cobos Álvarez <emilio@crisal.io>"
1417 criteria = "safe-to-deploy"
1418 delta = "0.33.0 -> 0.33.0@git:aaa966d9d6ae70c4b8a62bb5e3a14c068bb7dff0"
1419 notes = "Only one minimal change exposing a previously-private enumeration."
1421 [[audits.cssparser]]
1422 who = "Emilio Cobos Álvarez <emilio@crisal.io>"
1423 criteria = "safe-to-deploy"
1424 delta = "0.33.0 -> 0.34.0"
1425 notes = "I'm the publisher of the crate, and either myself or other Mozilla folks have been authors or reviewers of all the changes."
1427 [[audits.cssparser-color]]
1428 who = "Emilio Cobos Álvarez <emilio@crisal.io>"
1429 criteria = "safe-to-deploy"
1430 version = "0.1.0"
1431 notes = "This code used to live in cssparser's color module. Only moved out. Mozilla-authored."
1433 [[audits.cssparser-macros]]
1434 who = "Emilio Cobos Álvarez <emilio@crisal.io>"
1435 criteria = "safe-to-deploy"
1436 version = "0.6.0"
1437 notes = """
1438 Trivial crate with a single proc macro to compute the max length of the inputs
1439 to a match expression.
1442 [[audits.cssparser-macros]]
1443 who = "Mike Hommey <mh+mozilla@glandium.org>"
1444 criteria = "safe-to-deploy"
1445 delta = "0.6.0 -> 0.6.1"
1447 [[audits.cssparser-macros]]
1448 who = "Emilio Cobos Álvarez <emilio@crisal.io>"
1449 criteria = "safe-to-deploy"
1450 delta = "0.6.1 -> 0.6.1@git:aaa966d9d6ae70c4b8a62bb5e3a14c068bb7dff0"
1451 notes = "No changes from already-certified upstream, but needed because it lives in the same git repo as the cssparser crate."
1453 [[audits.cstr]]
1454 who = "Emilio Cobos Álvarez <emilio@crisal.io>"
1455 criteria = "safe-to-deploy"
1456 version = "0.2.10"
1457 notes = """
1458 I've reviewed the code of the crate thoroughly. It generates an unsafe block
1459 which is statically guaranteed to be safe. Inputs to the macro have to be
1460 static so there's no uncontrolled input whatsoever.
1463 [[audits.cstr]]
1464 who = "Mike Hommey <mh+mozilla@glandium.org>"
1465 criteria = "safe-to-deploy"
1466 delta = "0.2.10 -> 0.2.11"
1468 [[audits.cubeb]]
1469 who = "Matthew Gregan <kinetik@flim.org>"
1470 criteria = "safe-to-deploy"
1471 version = "0.10.1"
1472 notes = """
1473 Mozilla-developed package.
1476 [[audits.cubeb]]
1477 who = "Matthew Gregan <kinetik@flim.org>"
1478 criteria = "safe-to-deploy"
1479 delta = "0.10.1 -> 0.10.2"
1481 [[audits.cubeb]]
1482 who = "Mike Hommey <mh+mozilla@glandium.org>"
1483 criteria = "safe-to-deploy"
1484 delta = "0.10.2 -> 0.10.3"
1486 [[audits.cubeb]]
1487 who = "Andreas Pehrson <apehrson@mozilla.com>"
1488 criteria = "safe-to-deploy"
1489 delta = "0.10.3 -> 0.12.0"
1491 [[audits.cubeb]]
1492 who = "Andreas Pehrson <apehrson@mozilla.com>"
1493 criteria = "safe-to-deploy"
1494 delta = "0.12.0 -> 0.13.0"
1496 [[audits.cubeb-backend]]
1497 who = "Matthew Gregan <kinetik@flim.org>"
1498 criteria = "safe-to-deploy"
1499 version = "0.10.1"
1500 notes = """
1501 Mozilla-developed package.
1504 [[audits.cubeb-backend]]
1505 who = "Matthew Gregan <kinetik@flim.org>"
1506 criteria = "safe-to-deploy"
1507 delta = "0.10.1 -> 0.10.2"
1509 [[audits.cubeb-backend]]
1510 who = "Paul Adenot <paul@paul.cx>"
1511 criteria = "safe-to-deploy"
1512 delta = "0.10.2 -> 0.10.3"
1513 notes = """
1514 Mozilla-developed package.
1517 [[audits.cubeb-backend]]
1518 who = "Andreas Pehrson <apehrson@mozilla.com>"
1519 criteria = "safe-to-deploy"
1520 delta = "0.10.3 -> 0.10.7"
1522 [[audits.cubeb-backend]]
1523 who = "Andreas Pehrson <apehrson@mozilla.com>"
1524 criteria = "safe-to-deploy"
1525 delta = "0.10.7 -> 0.12.0"
1527 [[audits.cubeb-backend]]
1528 who = "Andreas Pehrson <apehrson@mozilla.com>"
1529 criteria = "safe-to-deploy"
1530 delta = "0.12.0 -> 0.13.0"
1532 [[audits.cubeb-core]]
1533 who = "Matthew Gregan <kinetik@flim.org>"
1534 criteria = "safe-to-deploy"
1535 version = "0.10.1"
1536 notes = """
1537 Mozilla-developed package.
1540 [[audits.cubeb-core]]
1541 who = "Matthew Gregan <kinetik@flim.org>"
1542 criteria = "safe-to-deploy"
1543 delta = "0.10.1 -> 0.10.2"
1545 [[audits.cubeb-core]]
1546 who = "Paul Adenot <paul@paul.cx>"
1547 criteria = "safe-to-deploy"
1548 delta = "0.10.2 -> 0.10.3"
1549 notes = """
1550 Mozilla-developed package.
1553 [[audits.cubeb-core]]
1554 who = "Mike Hommey <mh+mozilla@glandium.org>"
1555 criteria = "safe-to-deploy"
1556 delta = "0.10.3 -> 0.10.4"
1558 [[audits.cubeb-core]]
1559 who = "Andreas Pehrson <apehrson@mozilla.com>"
1560 criteria = "safe-to-deploy"
1561 delta = "0.10.4 -> 0.10.7"
1563 [[audits.cubeb-core]]
1564 who = "Andreas Pehrson <apehrson@mozilla.com>"
1565 criteria = "safe-to-deploy"
1566 delta = "0.10.7 -> 0.12.0"
1568 [[audits.cubeb-core]]
1569 who = "Andreas Pehrson <apehrson@mozilla.com>"
1570 criteria = "safe-to-deploy"
1571 delta = "0.12.0 -> 0.13.0"
1573 [[audits.cubeb-sys]]
1574 who = "Matthew Gregan <kinetik@flim.org>"
1575 criteria = "safe-to-deploy"
1576 version = "0.10.1"
1577 notes = """
1578 Mozilla-developed package.
1581 [[audits.cubeb-sys]]
1582 who = "Matthew Gregan <kinetik@flim.org>"
1583 criteria = "safe-to-deploy"
1584 delta = "0.10.1 -> 0.10.2"
1586 [[audits.cubeb-sys]]
1587 who = "Paul Adenot <paul@paul.cx>"
1588 criteria = "safe-to-deploy"
1589 delta = "0.10.2 -> 0.10.3"
1590 notes = """
1591 Mozilla-developed package.
1594 [[audits.cubeb-sys]]
1595 who = "Andreas Pehrson <apehrson@mozilla.com>"
1596 criteria = "safe-to-deploy"
1597 delta = "0.10.3 -> 0.10.7"
1599 [[audits.cubeb-sys]]
1600 who = "Andreas Pehrson <apehrson@mozilla.com>"
1601 criteria = "safe-to-deploy"
1602 delta = "0.10.7 -> 0.12.0"
1604 [[audits.cubeb-sys]]
1605 who = "Andreas Pehrson <apehrson@mozilla.com>"
1606 criteria = "safe-to-deploy"
1607 delta = "0.12.0 -> 0.13.0"
1609 [[audits.d3d12]]
1610 who = "Jim Blandy <jimb@red-bean.com>"
1611 criteria = "safe-to-deploy"
1612 delta = "0.4.1 -> 0.5.0"
1613 notes = "The commits between 0.4.1 and 0.5.0 were all audited by Dzmitry Malyshau or myself."
1615 [[audits.d3d12]]
1616 who = "Nicolas Silva <nical@fastmail.com>"
1617 criteria = "safe-to-deploy"
1618 delta = "0.5.0 -> 0.7.0"
1620 [[audits.d3d12]]
1621 who = [
1622     "Erich Gubler <egubler@mozilla.com>",
1623     "Jim Blandy <jimb@red-bean.com>",
1624     "Nicolas Silva <nical@fastmail.com>",
1625     "Erich Gubler <erichdongubler@gmail.com>",
1626     "Teodor Tanasoaia <ttanasoaia@mozilla.com>",
1628 criteria = "safe-to-deploy"
1629 delta = "0.7.0 -> 0.19.0"
1631 [[audits.d3d12]]
1632 who = "Erich Gubler <erichdongubler@gmail.com>"
1633 criteria = "safe-to-deploy"
1634 delta = "0.19.0 -> 0.20.0"
1636 [[audits.d3d12]]
1637 who = "Jim Blandy <jimb@red-bean.com>"
1638 criteria = "safe-to-deploy"
1639 delta = "0.20.0 -> 22.0.0"
1641 [[audits.d3d12]]
1642 who = "Jim Blandy <jimb@red-bean.com>"
1643 criteria = "safe-to-deploy"
1644 delta = "22.0.0 -> 22.0.0@git:c6a3d927345a81eeb13e9e3720002c4cc6f25e54"
1645 importable = false
1647 [[audits.darling]]
1648 who = "Mike Hommey <mh+mozilla@glandium.org>"
1649 criteria = "safe-to-deploy"
1650 delta = "0.13.4 -> 0.14.2"
1652 [[audits.darling]]
1653 who = "Mike Hommey <mh+mozilla@glandium.org>"
1654 criteria = "safe-to-deploy"
1655 delta = "0.14.2 -> 0.14.3"
1657 [[audits.darling]]
1658 who = "Mike Hommey <mh+mozilla@glandium.org>"
1659 criteria = "safe-to-deploy"
1660 delta = "0.14.3 -> 0.20.1"
1662 [[audits.darling]]
1663 who = "Ben Dean-Kawamura <bdk@mozilla.com>"
1664 criteria = "safe-to-deploy"
1665 delta = "0.20.1 -> 0.20.10"
1667 [[audits.darling_core]]
1668 who = "Mike Hommey <mh+mozilla@glandium.org>"
1669 criteria = "safe-to-deploy"
1670 delta = "0.13.4 -> 0.14.2"
1672 [[audits.darling_core]]
1673 who = "Mike Hommey <mh+mozilla@glandium.org>"
1674 criteria = "safe-to-deploy"
1675 delta = "0.14.2 -> 0.14.3"
1677 [[audits.darling_core]]
1678 who = "Mike Hommey <mh+mozilla@glandium.org>"
1679 criteria = "safe-to-deploy"
1680 delta = "0.14.3 -> 0.20.1"
1682 [[audits.darling_core]]
1683 who = "Ben Dean-Kawamura <bdk@mozilla.com>"
1684 criteria = "safe-to-deploy"
1685 delta = "0.20.1 -> 0.20.10"
1687 [[audits.darling_macro]]
1688 who = "Mike Hommey <mh+mozilla@glandium.org>"
1689 criteria = "safe-to-deploy"
1690 delta = "0.13.4 -> 0.14.2"
1692 [[audits.darling_macro]]
1693 who = "Mike Hommey <mh+mozilla@glandium.org>"
1694 criteria = "safe-to-deploy"
1695 delta = "0.14.2 -> 0.14.3"
1697 [[audits.darling_macro]]
1698 who = "Mike Hommey <mh+mozilla@glandium.org>"
1699 criteria = "safe-to-deploy"
1700 delta = "0.14.3 -> 0.20.1"
1702 [[audits.darling_macro]]
1703 who = "Ben Dean-Kawamura <bdk@mozilla.com>"
1704 criteria = "safe-to-deploy"
1705 delta = "0.20.1 -> 0.20.10"
1707 [[audits.data-encoding]]
1708 who = "Mike Hommey <mh+mozilla@glandium.org>"
1709 criteria = "safe-to-deploy"
1710 delta = "2.3.2 -> 2.3.3"
1712 [[audits.debug_tree]]
1713 who = "Benjamin Beurdouche <beurdouche@mozilla.com>"
1714 criteria = "safe-to-deploy"
1715 version = "0.4.0"
1717 [[audits.debugid]]
1718 who = "Gabriele Svelto <gsvelto@mozilla.com>"
1719 criteria = "safe-to-deploy"
1720 version = "0.8.0"
1721 notes = "This crates was written by Sentry and I've fully audited it as Firefox crash reporting machinery relies on it."
1723 [[audits.deranged]]
1724 who = "Alex Franchuk <afranchuk@mozilla.com>"
1725 criteria = "safe-to-deploy"
1726 version = "0.3.11"
1727 notes = """
1728 This crate contains a decent bit of `unsafe` code, however all internal
1729 unsafety is verified with copious assertions (many are compile-time), and
1730 otherwise the unsafety is documented and left to the caller to verify.
1733 [[audits.derive_arbitrary]]
1734 who = "Mike Hommey <mh+mozilla@glandium.org>"
1735 criteria = "safe-to-run"
1736 delta = "1.1.0 -> 1.1.1"
1738 [[audits.derive_arbitrary]]
1739 who = "Mike Hommey <mh+mozilla@glandium.org>"
1740 criteria = "safe-to-run"
1741 delta = "1.1.1 -> 1.1.3"
1743 [[audits.derive_arbitrary]]
1744 who = "Mike Hommey <mh+mozilla@glandium.org>"
1745 criteria = "safe-to-run"
1746 delta = "1.1.3 -> 1.2.1"
1748 [[audits.derive_arbitrary]]
1749 who = "Mike Hommey <mh+mozilla@glandium.org>"
1750 criteria = "safe-to-run"
1751 delta = "1.2.1 -> 1.2.3"
1753 [[audits.derive_arbitrary]]
1754 who = "Mike Hommey <mh+mozilla@glandium.org>"
1755 criteria = "safe-to-run"
1756 delta = "1.3.0 -> 1.3.1"
1758 [[audits.derive_more]]
1759 who = "Mike Hommey <mh+mozilla@glandium.org>"
1760 criteria = "safe-to-deploy"
1761 delta = "0.99.17 -> 1.0.0-beta.2"
1763 [[audits.devd-rs]]
1764 who = "Mike Hommey <mh+mozilla@glandium.org>"
1765 criteria = "safe-to-deploy"
1766 delta = "0.3.4 -> 0.3.5"
1768 [[audits.devd-rs]]
1769 who = "Mike Hommey <mh+mozilla@glandium.org>"
1770 criteria = "safe-to-deploy"
1771 delta = "0.3.5 -> 0.3.6"
1773 [[audits.digest]]
1774 who = "Mike Hommey <mh+mozilla@glandium.org>"
1775 criteria = "safe-to-deploy"
1776 delta = "0.10.3 -> 0.10.6"
1778 [[audits.diplomat]]
1779 who = "Makoto Kato <m_kato@ga2.so-net.ne.jp>"
1780 criteria = "safe-to-deploy"
1781 version = "0.5.2"
1782 notes = "This crate is FFI wrapper generator using by ICU4X ffi libraries. This uses unsafe code to convert paramenters, I have reviewed this and generated headers."
1784 [[audits.diplomat]]
1785 who = "Makoto Kato <m_kato@ga2.so-net.ne.jp>"
1786 criteria = "safe-to-deploy"
1787 delta = "0.5.2 -> 0.5.2@git:8d125999893fedfdf30595e97334c21ec4b18da9"
1789 [[audits.diplomat]]
1790 who = "Makoto Kato <m_kato@ga2.so-net.ne.jp>"
1791 criteria = "safe-to-deploy"
1792 delta = "0.5.2 -> 0.7.0"
1794 [[audits.diplomat]]
1795 who = "Makoto Kato <m_kato@ga2.so-net.ne.jp>"
1796 criteria = "safe-to-deploy"
1797 delta = "0.7.0 -> 0.8.0"
1799 [[audits.diplomat-runtime]]
1800 who = "Makoto Kato <m_kato@ga2.so-net.ne.jp>"
1801 criteria = "safe-to-deploy"
1802 version = "0.5.2"
1803 notes = "This crate is FFI wrapper generator runtime using by ICU4X ffi libraries. This uses unsafe code for memory access of FFI. I have reviewed carefully."
1805 [[audits.diplomat-runtime]]
1806 who = "Makoto Kato <m_kato@ga2.so-net.ne.jp>"
1807 criteria = "safe-to-deploy"
1808 delta = "0.5.2 -> 0.5.2@git:8d125999893fedfdf30595e97334c21ec4b18da9"
1810 [[audits.diplomat-runtime]]
1811 who = "Makoto Kato <m_kato@ga2.so-net.ne.jp>"
1812 criteria = "safe-to-deploy"
1813 delta = "0.5.2 -> 0.7.0"
1815 [[audits.diplomat-runtime]]
1816 who = "Makoto Kato <m_kato@ga2.so-net.ne.jp>"
1817 criteria = "safe-to-deploy"
1818 delta = "0.7.0 -> 0.8.0"
1820 [[audits.diplomat_core]]
1821 who = "Makoto Kato <m_kato@ga2.so-net.ne.jp>"
1822 criteria = "safe-to-deploy"
1823 version = "0.5.2"
1824 notes = "This crate contains unsafe code, no network and no file access."
1826 [[audits.diplomat_core]]
1827 who = "Makoto Kato <m_kato@ga2.so-net.ne.jp>"
1828 criteria = "safe-to-deploy"
1829 delta = "0.5.2 -> 0.5.2@git:8d125999893fedfdf30595e97334c21ec4b18da9"
1831 [[audits.diplomat_core]]
1832 who = "Makoto Kato <m_kato@ga2.so-net.ne.jp>"
1833 criteria = "safe-to-deploy"
1834 delta = "0.5.2 -> 0.7.0"
1836 [[audits.diplomat_core]]
1837 who = "Makoto Kato <m_kato@ga2.so-net.ne.jp>"
1838 criteria = "safe-to-deploy"
1839 delta = "0.7.0 -> 0.8.0"
1841 [[audits.displaydoc]]
1842 who = "Makoto Kato <m_kato@ga2.so-net.ne.jp>"
1843 criteria = "safe-to-deploy"
1844 version = "0.2.3"
1845 notes = """
1846 This crate is convenient macros to implement core::fmt::Display trait.
1847 Although `unsafe` is used for test code to call `libc::abort()`, it has no `unsafe` code in this crate. And there is no file access.
1848 It meets the criteria for safe-to-deploy.
1851 [[audits.displaydoc]]
1852 who = "Mike Hommey <mh+mozilla@glandium.org>"
1853 criteria = "safe-to-deploy"
1854 delta = "0.2.3 -> 0.2.4"
1856 [[audits.document-features]]
1857 who = "Erich Gubler <erichdongubler@gmail.com>"
1858 criteria = "safe-to-deploy"
1859 version = "0.2.8"
1861 [[audits.document-features]]
1862 who = "Erich Gubler <erichdongubler@gmail.com>"
1863 criteria = "safe-to-deploy"
1864 delta = "0.2.8 -> 0.2.9"
1866 [[audits.document-features]]
1867 who = "Erich Gubler <erichdongubler@gmail.com>"
1868 criteria = "safe-to-deploy"
1869 delta = "0.2.9 -> 0.2.10"
1871 [[audits.dogear]]
1872 who = "Sammy Khamis <skhamis@mozilla.com>"
1873 criteria = "safe-to-deploy"
1874 delta = "0.4.0 -> 0.5.0"
1875 notes = "The repository for this crate belongs in the Mozilla org."
1877 [[audits.dtoa-short]]
1878 who = "Bobby Holley <bobbyholley@gmail.com>"
1879 criteria = "safe-to-deploy"
1880 version = "0.3.3"
1882 [[audits.dwrote]]
1883 who = "Bobby Holley <bobbyholley@gmail.com>"
1884 criteria = "safe-to-deploy"
1885 version = "0.11.0"
1886 notes = "All code written or reviewed by Mozilla staff."
1888 [[audits.either]]
1889 who = "Mike Hommey <mh+mozilla@glandium.org>"
1890 criteria = "safe-to-deploy"
1891 delta = "1.6.1 -> 1.7.0"
1893 [[audits.either]]
1894 who = "Mike Hommey <mh+mozilla@glandium.org>"
1895 criteria = "safe-to-deploy"
1896 delta = "1.7.0 -> 1.8.0"
1898 [[audits.either]]
1899 who = "Mike Hommey <mh+mozilla@glandium.org>"
1900 criteria = "safe-to-deploy"
1901 delta = "1.8.0 -> 1.8.1"
1903 [[audits.embed-manifest]]
1904 who = "Alex Franchuk <afranchuk@mozilla.com>"
1905 criteria = "safe-to-deploy"
1906 version = "1.4.0"
1907 notes = "Necessary dependencies, all environment variable access is for build script vars set by cargo."
1909 [[audits.encoding_c]]
1910 who = "Henri Sivonen <hsivonen@hsivonen.fi>"
1911 criteria = "safe-to-deploy"
1912 version = "0.9.8"
1913 notes = "I, Henri Sivonen, wrote encoding_c for Gecko even though it is published via crates.io. There are two caveats: 1) the C API is designed to be used together with mozilla::Span and is unidiomatic for zero-length inputs otherwise. 2) It is idiomatic in C and C++ to pass uninitialized buffers as output buffers. This is generally documented to be UB in Rust, but idiomatic C and C++ usage here relies on this not actually being UB for buffers of integers (which these buffers are). See https://github.com/hsivonen/encoding_rs/issues/79#issuecomment-1211870361"
1915 [[audits.encoding_c_mem]]
1916 who = "Henri Sivonen <hsivonen@hsivonen.fi>"
1917 criteria = "safe-to-deploy"
1918 version = "0.2.6"
1919 notes = """
1920 I, Henri Sivonen, wrote encoding_c_mem for Gecko even though it is published via crates.io. There are two caveats: 1) the C API is designed to be used together with mozilla::Span and is unidiomatic for zero-length inputs otherwise. 2) It is idiomatic in C and C
1921 ++ to pass uninitialized buffers as output buffers. This is generally documented to be UB in Rust, but idiomatic C and C++ usage here relies on this not actually being UB for buffers of integers (which these buffers are). See https://github.com/hsivonen/encoding_rs/i
1922 ssues/79#issuecomment-1211870361
1925 [[audits.encoding_rs]]
1926 who = "Henri Sivonen <hsivonen@hsivonen.fi>"
1927 criteria = "safe-to-deploy"
1928 version = "0.8.31"
1929 notes = "I, Henri Sivonen, wrote encoding_rs for Gecko and have reviewed contributions by others. There are two caveats to the certification: 1) The crate does things that are documented to be UB but that do not appear to actually be UB due to integer types differing from the general rule; https://github.com/hsivonen/encoding_rs/issues/79 . 2) It would be prudent to re-review the code that reinterprets buffers of integers as SIMD vectors; see https://github.com/hsivonen/encoding_rs/issues/87 ."
1931 [[audits.encoding_rs]]
1932 who = "Mike Hommey <mh+mozilla@glandium.org>"
1933 criteria = "safe-to-deploy"
1934 delta = "0.8.31 -> 0.8.32"
1936 [[audits.enum-map]]
1937 who = "Kershaw Chang <kershaw@mozilla.com>"
1938 criteria = "safe-to-deploy"
1939 version = "2.7.3"
1941 [[audits.enum-map-derive]]
1942 who = "Kershaw Chang <kershaw@mozilla.com>"
1943 criteria = "safe-to-deploy"
1944 version = "0.17.0"
1946 [[audits.enum-primitive-derive]]
1947 who = "Gabriele Svelto <gsvelto@mozilla.com>"
1948 criteria = "safe-to-deploy"
1949 version = "0.2.2"
1951 [[audits.enumset]]
1952 who = "Mike Hommey <mh+mozilla@glandium.org>"
1953 criteria = "safe-to-deploy"
1954 delta = "1.0.11 -> 1.0.12"
1956 [[audits.enumset]]
1957 who = "Mike Hommey <mh+mozilla@glandium.org>"
1958 criteria = "safe-to-deploy"
1959 delta = "1.0.12 -> 1.1.2"
1961 [[audits.enumset_derive]]
1962 who = "Mike Hommey <mh+mozilla@glandium.org>"
1963 criteria = "safe-to-deploy"
1964 delta = "0.6.0 -> 0.6.1"
1966 [[audits.enumset_derive]]
1967 who = "Mike Hommey <mh+mozilla@glandium.org>"
1968 criteria = "safe-to-deploy"
1969 delta = "0.6.1 -> 0.8.1"
1971 [[audits.env_logger]]
1972 who = "Mike Hommey <mh+mozilla@glandium.org>"
1973 criteria = "safe-to-deploy"
1974 delta = "0.9.0 -> 0.9.3"
1976 [[audits.env_logger]]
1977 who = "Nicolas Silva <nical@fastmail.com>"
1978 criteria = "safe-to-deploy"
1979 delta = "0.9.3 -> 0.10.0"
1981 [[audits.errno]]
1982 who = "Mike Hommey <mh+mozilla@glandium.org>"
1983 criteria = "safe-to-deploy"
1984 delta = "0.3.1 -> 0.3.3"
1986 [[audits.extend]]
1987 who = "Ben Dean-Kawamura <bdk@mozilla.com>"
1988 criteria = "safe-to-deploy"
1989 version = "1.1.2"
1990 notes = "Inspected the crate and noted that the impl block comes directly from the proc-macro input.  If no new code can be added by this crate, I don't think there can be any issues."
1992 [[audits.extend]]
1993 who = "Mike Hommey <mh+mozilla@glandium.org>"
1994 criteria = "safe-to-deploy"
1995 delta = "1.1.2 -> 1.2.0"
1997 [[audits.fallible_collections]]
1998 who = "Mike Hommey <mh+mozilla@glandium.org>"
1999 criteria = "safe-to-deploy"
2000 delta = "0.4.4 -> 0.4.5"
2002 [[audits.fallible_collections]]
2003 who = "Mike Hommey <mh+mozilla@glandium.org>"
2004 criteria = "safe-to-deploy"
2005 delta = "0.4.5 -> 0.4.6"
2006 notes = "The changes in this version are mine."
2008 [[audits.fallible_collections]]
2009 who = "Mike Hommey <mh+mozilla@glandium.org>"
2010 criteria = "safe-to-deploy"
2011 delta = "0.4.6 -> 0.4.9"
2012 notes = "Mostly soundness fixes."
2014 [[audits.fastrand]]
2015 who = "Mike Hommey <mh+mozilla@glandium.org>"
2016 criteria = "safe-to-deploy"
2017 delta = "1.7.0 -> 1.8.0"
2019 [[audits.fastrand]]
2020 who = "Mike Hommey <mh+mozilla@glandium.org>"
2021 criteria = "safe-to-deploy"
2022 delta = "1.8.0 -> 1.9.0"
2024 [[audits.fastrand]]
2025 who = "Mike Hommey <mh+mozilla@glandium.org>"
2026 criteria = "safe-to-deploy"
2027 delta = "1.9.0 -> 2.0.0"
2029 [[audits.fastrand]]
2030 who = "Mike Hommey <mh+mozilla@glandium.org>"
2031 criteria = "safe-to-deploy"
2032 delta = "2.0.1 -> 2.1.0"
2034 [[audits.filetime_win]]
2035 who = "Nick Alexander <nalexander@mozilla.com>"
2036 criteria = "safe-to-deploy"
2037 version = "0.2.0"
2038 notes = """
2039 filetime_win was written by Adam Gashlin for Mozilla's use.  The `unsafe` code
2040 blocks in filetime_win 0.2.0 are straight-forward invocations of `mem::zeroed`
2041 and expected invocations of Win32 APIs (with error handling as appropriate).
2044 [[audits.flagset]]
2045 who = "Ryan Hunt <rhunt@eqrion.net>"
2046 criteria = "safe-to-deploy"
2047 version = "0.4.3"
2048 notes = "Uses no ambient capabilities, vetted the one instance of unsafe."
2050 [[audits.flate2]]
2051 who = "Mike Hommey <mh+mozilla@glandium.org>"
2052 criteria = "safe-to-deploy"
2053 delta = "1.0.24 -> 1.0.25"
2055 [[audits.flate2]]
2056 who = "Alex Franchuk <afranchuk@mozilla.com>"
2057 criteria = "safe-to-deploy"
2058 delta = "1.0.28 -> 1.0.30"
2059 notes = "Some new unsafe code, however it has been verified and there are unit tests as well."
2061 [[audits.fluent]]
2062 who = "Zibi Braniecki <zibi@unicode.org>"
2063 criteria = "safe-to-deploy"
2064 version = "0.16.0"
2066 [[audits.fluent-bundle]]
2067 who = "Zibi Braniecki <zibi@unicode.org>"
2068 criteria = "safe-to-deploy"
2069 version = "0.15.2"
2071 [[audits.fluent-fallback]]
2072 who = "Zibi Braniecki <zibi@unicode.org>"
2073 criteria = "safe-to-deploy"
2074 version = "0.6.0"
2076 [[audits.fluent-fallback]]
2077 who = "Greg Tatum <tatum.creative@gmail.com>"
2078 criteria = "safe-to-deploy"
2079 delta = "0.6.0 -> 0.7.0"
2081 [[audits.fluent-langneg]]
2082 who = "Zibi Braniecki <zibi@unicode.org>"
2083 criteria = "safe-to-deploy"
2084 version = "0.13.0"
2086 [[audits.fluent-pseudo]]
2087 who = "Zibi Braniecki <zibi@unicode.org>"
2088 criteria = "safe-to-deploy"
2089 version = "0.3.1"
2091 [[audits.fluent-syntax]]
2092 who = "Zibi Braniecki <zibi@unicode.org>"
2093 criteria = "safe-to-deploy"
2094 version = "0.11.0"
2096 [[audits.fluent-testing]]
2097 who = "Zibi Braniecki <zibi@unicode.org>"
2098 criteria = "safe-to-run"
2099 version = "0.0.2"
2101 [[audits.fluent-testing]]
2102 who = "Greg Tatum <tatum.creative@gmail.com>"
2103 criteria = "safe-to-run"
2104 delta = "0.0.2 -> 0.0.3"
2106 [[audits.fnv]]
2107 who = "Bobby Holley <bobbyholley@gmail.com>"
2108 criteria = "safe-to-deploy"
2109 version = "1.0.7"
2110 notes = "Simple hasher implementation with no unsafe code."
2112 [[audits.foreign-types]]
2113 who = "Teodor Tanasoaia <ttanasoaia@mozilla.com>"
2114 criteria = "safe-to-deploy"
2115 delta = "0.3.2 -> 0.5.0"
2117 [[audits.foreign-types-macros]]
2118 who = "Teodor Tanasoaia <ttanasoaia@mozilla.com>"
2119 criteria = "safe-to-deploy"
2120 version = "0.2.3"
2122 [[audits.foreign-types-shared]]
2123 who = "Teodor Tanasoaia <ttanasoaia@mozilla.com>"
2124 criteria = "safe-to-deploy"
2125 delta = "0.1.1 -> 0.3.1"
2127 [[audits.form_urlencoded]]
2128 who = "Valentin Gosu <valentin.gosu@gmail.com>"
2129 criteria = "safe-to-deploy"
2130 version = "1.2.0"
2132 [[audits.form_urlencoded]]
2133 who = "Valentin Gosu <valentin.gosu@gmail.com>"
2134 criteria = "safe-to-deploy"
2135 delta = "1.2.0 -> 1.2.1"
2137 [[audits.fs-err]]
2138 who = "Mike Hommey <mh+mozilla@glandium.org>"
2139 criteria = "safe-to-deploy"
2140 delta = "2.7.0 -> 2.8.1"
2142 [[audits.fs-err]]
2143 who = "Mike Hommey <mh+mozilla@glandium.org>"
2144 criteria = "safe-to-deploy"
2145 delta = "2.8.1 -> 2.9.0"
2147 [[audits.futures]]
2148 who = "Mike Hommey <mh+mozilla@glandium.org>"
2149 criteria = "safe-to-deploy"
2150 delta = "0.3.21 -> 0.3.23"
2152 [[audits.futures]]
2153 who = "Mike Hommey <mh+mozilla@glandium.org>"
2154 criteria = "safe-to-deploy"
2155 delta = "0.3.23 -> 0.3.25"
2157 [[audits.futures]]
2158 who = "Mike Hommey <mh+mozilla@glandium.org>"
2159 criteria = "safe-to-deploy"
2160 delta = "0.3.25 -> 0.3.26"
2162 [[audits.futures]]
2163 who = "Mike Hommey <mh+mozilla@glandium.org>"
2164 criteria = "safe-to-deploy"
2165 delta = "0.3.26 -> 0.3.28"
2167 [[audits.futures-channel]]
2168 who = "Mike Hommey <mh+mozilla@glandium.org>"
2169 criteria = "safe-to-deploy"
2170 delta = "0.3.21 -> 0.3.23"
2172 [[audits.futures-channel]]
2173 who = "Mike Hommey <mh+mozilla@glandium.org>"
2174 criteria = "safe-to-deploy"
2175 delta = "0.3.23 -> 0.3.25"
2177 [[audits.futures-channel]]
2178 who = "Mike Hommey <mh+mozilla@glandium.org>"
2179 criteria = "safe-to-deploy"
2180 delta = "0.3.25 -> 0.3.26"
2182 [[audits.futures-channel]]
2183 who = "Bobby Holley <bobbyholley@gmail.com>"
2184 criteria = "safe-to-deploy"
2185 delta = "0.3.27 -> 0.3.26"
2187 [[audits.futures-channel]]
2188 who = "Mike Hommey <mh+mozilla@glandium.org>"
2189 criteria = "safe-to-deploy"
2190 delta = "0.3.27 -> 0.3.28"
2192 [[audits.futures-core]]
2193 who = "Mike Hommey <mh+mozilla@glandium.org>"
2194 criteria = "safe-to-deploy"
2195 delta = "0.3.21 -> 0.3.23"
2197 [[audits.futures-core]]
2198 who = "Mike Hommey <mh+mozilla@glandium.org>"
2199 criteria = "safe-to-deploy"
2200 delta = "0.3.23 -> 0.3.25"
2202 [[audits.futures-core]]
2203 who = "Mike Hommey <mh+mozilla@glandium.org>"
2204 criteria = "safe-to-deploy"
2205 delta = "0.3.25 -> 0.3.26"
2207 [[audits.futures-core]]
2208 who = "Bobby Holley <bobbyholley@gmail.com>"
2209 criteria = "safe-to-deploy"
2210 delta = "0.3.27 -> 0.3.26"
2212 [[audits.futures-core]]
2213 who = "Mike Hommey <mh+mozilla@glandium.org>"
2214 criteria = "safe-to-deploy"
2215 delta = "0.3.27 -> 0.3.28"
2217 [[audits.futures-executor]]
2218 who = "Mike Hommey <mh+mozilla@glandium.org>"
2219 criteria = "safe-to-deploy"
2220 delta = "0.3.21 -> 0.3.23"
2222 [[audits.futures-executor]]
2223 who = "Mike Hommey <mh+mozilla@glandium.org>"
2224 criteria = "safe-to-deploy"
2225 delta = "0.3.23 -> 0.3.25"
2227 [[audits.futures-executor]]
2228 who = "Mike Hommey <mh+mozilla@glandium.org>"
2229 criteria = "safe-to-deploy"
2230 delta = "0.3.25 -> 0.3.26"
2232 [[audits.futures-executor]]
2233 who = "Bobby Holley <bobbyholley@gmail.com>"
2234 criteria = "safe-to-deploy"
2235 delta = "0.3.27 -> 0.3.23"
2237 [[audits.futures-executor]]
2238 who = "Mike Hommey <mh+mozilla@glandium.org>"
2239 criteria = "safe-to-deploy"
2240 delta = "0.3.27 -> 0.3.28"
2242 [[audits.futures-io]]
2243 who = "Mike Hommey <mh+mozilla@glandium.org>"
2244 criteria = "safe-to-deploy"
2245 delta = "0.3.21 -> 0.3.23"
2247 [[audits.futures-io]]
2248 who = "Mike Hommey <mh+mozilla@glandium.org>"
2249 criteria = "safe-to-deploy"
2250 delta = "0.3.23 -> 0.3.25"
2252 [[audits.futures-io]]
2253 who = "Mike Hommey <mh+mozilla@glandium.org>"
2254 criteria = "safe-to-deploy"
2255 delta = "0.3.25 -> 0.3.26"
2257 [[audits.futures-io]]
2258 who = "Bobby Holley <bobbyholley@gmail.com>"
2259 criteria = "safe-to-deploy"
2260 delta = "0.3.27 -> 0.3.23"
2262 [[audits.futures-io]]
2263 who = "Mike Hommey <mh+mozilla@glandium.org>"
2264 criteria = "safe-to-deploy"
2265 delta = "0.3.27 -> 0.3.28"
2267 [[audits.futures-macro]]
2268 who = "Mike Hommey <mh+mozilla@glandium.org>"
2269 criteria = "safe-to-deploy"
2270 delta = "0.3.21 -> 0.3.23"
2272 [[audits.futures-macro]]
2273 who = "Mike Hommey <mh+mozilla@glandium.org>"
2274 criteria = "safe-to-deploy"
2275 delta = "0.3.23 -> 0.3.25"
2277 [[audits.futures-macro]]
2278 who = "Mike Hommey <mh+mozilla@glandium.org>"
2279 criteria = "safe-to-deploy"
2280 delta = "0.3.25 -> 0.3.26"
2282 [[audits.futures-macro]]
2283 who = "Mike Hommey <mh+mozilla@glandium.org>"
2284 criteria = "safe-to-deploy"
2285 delta = "0.3.26 -> 0.3.28"
2287 [[audits.futures-sink]]
2288 who = "Mike Hommey <mh+mozilla@glandium.org>"
2289 criteria = "safe-to-deploy"
2290 delta = "0.3.21 -> 0.3.23"
2292 [[audits.futures-sink]]
2293 who = "Mike Hommey <mh+mozilla@glandium.org>"
2294 criteria = "safe-to-deploy"
2295 delta = "0.3.23 -> 0.3.25"
2297 [[audits.futures-sink]]
2298 who = "Mike Hommey <mh+mozilla@glandium.org>"
2299 criteria = "safe-to-deploy"
2300 delta = "0.3.25 -> 0.3.26"
2302 [[audits.futures-sink]]
2303 who = "Bobby Holley <bobbyholley@gmail.com>"
2304 criteria = "safe-to-deploy"
2305 delta = "0.3.27 -> 0.3.23"
2307 [[audits.futures-sink]]
2308 who = "Mike Hommey <mh+mozilla@glandium.org>"
2309 criteria = "safe-to-deploy"
2310 delta = "0.3.27 -> 0.3.28"
2312 [[audits.futures-task]]
2313 who = "Mike Hommey <mh+mozilla@glandium.org>"
2314 criteria = "safe-to-deploy"
2315 delta = "0.3.21 -> 0.3.23"
2317 [[audits.futures-task]]
2318 who = "Mike Hommey <mh+mozilla@glandium.org>"
2319 criteria = "safe-to-deploy"
2320 delta = "0.3.23 -> 0.3.25"
2322 [[audits.futures-task]]
2323 who = "Mike Hommey <mh+mozilla@glandium.org>"
2324 criteria = "safe-to-deploy"
2325 delta = "0.3.25 -> 0.3.26"
2327 [[audits.futures-task]]
2328 who = "Mike Hommey <mh+mozilla@glandium.org>"
2329 criteria = "safe-to-deploy"
2330 delta = "0.3.26 -> 0.3.28"
2332 [[audits.futures-util]]
2333 who = "Mike Hommey <mh+mozilla@glandium.org>"
2334 criteria = "safe-to-deploy"
2335 delta = "0.3.21 -> 0.3.23"
2337 [[audits.futures-util]]
2338 who = "Mike Hommey <mh+mozilla@glandium.org>"
2339 criteria = "safe-to-deploy"
2340 delta = "0.3.23 -> 0.3.25"
2342 [[audits.futures-util]]
2343 who = "Mike Hommey <mh+mozilla@glandium.org>"
2344 criteria = "safe-to-deploy"
2345 delta = "0.3.25 -> 0.3.26"
2347 [[audits.futures-util]]
2348 who = "Mike Hommey <mh+mozilla@glandium.org>"
2349 criteria = "safe-to-deploy"
2350 delta = "0.3.26 -> 0.3.28"
2352 [[audits.fxhash]]
2353 who = "Bobby Holley <bobbyholley@gmail.com>"
2354 criteria = "safe-to-deploy"
2355 version = "0.2.1"
2356 notes = "Straightforward crate with no unsafe code, does what it says on the tin."
2358 [[audits.generic-array]]
2359 who = "Mike Hommey <mh+mozilla@glandium.org>"
2360 criteria = "safe-to-deploy"
2361 delta = "0.14.5 -> 0.14.6"
2363 [[audits.getrandom]]
2364 who = "Mike Hommey <mh+mozilla@glandium.org>"
2365 criteria = "safe-to-deploy"
2366 delta = "0.2.6 -> 0.2.7"
2368 [[audits.getrandom]]
2369 who = "Mike Hommey <mh+mozilla@glandium.org>"
2370 criteria = "safe-to-deploy"
2371 delta = "0.2.7 -> 0.2.8"
2373 [[audits.getrandom]]
2374 who = "Yannis Juglaret <yjuglaret@mozilla.com>"
2375 criteria = "safe-to-deploy"
2376 delta = "0.2.8 -> 0.2.9"
2378 [[audits.getrandom]]
2379 who = "Simon Friedberger <simon@mozilla.com>"
2380 criteria = "safe-to-deploy"
2381 delta = "0.2.10 -> 0.2.11"
2383 [[audits.gimli]]
2384 who = "Alex Franchuk <afranchuk@mozilla.com>"
2385 criteria = "safe-to-deploy"
2386 version = "0.30.0"
2387 notes = """
2388 Unsafe code blocks are sound. Minimal dependencies used. No use of
2389 side-effectful std functions.
2392 [[audits.gleam]]
2393 who = "Jamie Nicol <jnicol@mozilla.com>"
2394 criteria = "safe-to-deploy"
2395 delta = "0.13.1 -> 0.15.0"
2397 [[audits.glob]]
2398 who = "Mike Hommey <mh+mozilla@glandium.org>"
2399 criteria = "safe-to-deploy"
2400 delta = "0.3.0 -> 0.3.1"
2402 [[audits.glsl]]
2403 who = "Mike Hommey <mh+mozilla@glandium.org>"
2404 criteria = "safe-to-deploy"
2405 delta = "6.0.1 -> 6.0.2"
2406 notes = "I'm the author of the changes in this version of the crate."
2408 [[audits.goblin]]
2409 who = "Jan-Erik Rediger <jrediger@mozilla.com>"
2410 criteria = "safe-to-deploy"
2411 delta = "0.1.3 -> 0.5.4"
2412 notes = "Several bugfixes since 2019. This version is also in use by Mozilla's crash reporting tooling, e.g. minidump-writer"
2414 [[audits.goblin]]
2415 who = "Gabriele Svelto <gsvelto@mozilla.com>"
2416 criteria = "safe-to-deploy"
2417 delta = "0.5.4 -> 0.6.0"
2418 notes = "Mostly bug fixes and some added functionality"
2420 [[audits.goblin]]
2421 who = "Gabriele Svelto <gsvelto@mozilla.com>"
2422 criteria = "safe-to-deploy"
2423 delta = "0.6.0 -> 0.7.1"
2425 [[audits.goblin]]
2426 who = "Alex Franchuk <afranchuk@mozilla.com>"
2427 criteria = "safe-to-deploy"
2428 delta = "0.7.1 -> 0.8.0"
2429 notes = "Fairly straightforward feature improvements."
2431 [[audits.goblin]]
2432 who = "Alexandre Lissy <lissyx+mozillians@lissyx.dyndns.org>"
2433 criteria = "safe-to-deploy"
2434 delta = "0.8.0 -> 0.8.1"
2435 notes = "Updating goblin to 0.8.1 that includes my fix for Elf SectionHeader parsing"
2437 [[audits.goblin]]
2438 who = "Alex Franchuk <afranchuk@mozilla.com>"
2439 criteria = "safe-to-deploy"
2440 delta = "0.8.1 -> 0.8.2"
2441 notes = "Removes the TE feature/functionality, otherwise no meaningful changes."
2443 [[audits.gpu-alloc]]
2444 who = "Teodor Tanasoaia <ttanasoaia@mozilla.com>"
2445 criteria = "safe-to-deploy"
2446 delta = "0.5.3 -> 0.6.0"
2448 [[audits.gpu-alloc-types]]
2449 who = "Teodor Tanasoaia <ttanasoaia@mozilla.com>"
2450 criteria = "safe-to-deploy"
2451 delta = "0.2.0 -> 0.3.0"
2453 [[audits.gpu-allocator]]
2454 who = "Erich Gubler <erichdongubler@gmail.com>"
2455 criteria = "safe-to-deploy"
2456 version = "0.25.0"
2458 [[audits.gpu-allocator]]
2459 who = "Erich Gubler <erichdongubler@gmail.com>"
2460 criteria = "safe-to-deploy"
2461 delta = "0.25.0 -> 0.26.0"
2462 notes = "New Metal backend is written with no `unsafe`. New `unsafe` usage of DX12's platform APIs appear correct and safe. Otherwise, minimal changes."
2464 [[audits.gpu-allocator]]
2465 who = "Jim Blandy <jimb@red-bean.com>"
2466 criteria = "safe-to-deploy"
2467 delta = "0.26.0 -> 0.27.0"
2469 [[audits.gpu-descriptor]]
2470 who = "Mike Hommey <mh+mozilla@glandium.org>"
2471 criteria = "safe-to-deploy"
2472 delta = "0.2.2 -> 0.2.3"
2474 [[audits.gpu-descriptor]]
2475 who = "Erich Gubler <erichdongubler@gmail.com>"
2476 criteria = "safe-to-deploy"
2477 delta = "0.2.3 -> 0.3.0"
2479 [[audits.gpu-descriptor-types]]
2480 who = "Erich Gubler <erichdongubler@gmail.com>"
2481 criteria = "safe-to-deploy"
2482 delta = "0.1.1 -> 0.2.0"
2484 [[audits.guid_win]]
2485 who = "Bobby Holley <bobbyholley@gmail.com>"
2486 criteria = "safe-to-deploy"
2487 version = "0.2.0"
2488 notes = """
2489 This crate has some unsafe code for the FFI bits, which I've reviewed carefully.
2490 It uses the deprecated mem::uninitialized(), which is generally sketchy. However
2491 the usage is pretty straightforward and while it's technically UB, it seems no
2492 more likely to lead to miscompilation than any other use of mem::uninitialized.
2495 [[audits.h2]]
2496 who = "Mike Hommey <mh+mozilla@glandium.org>"
2497 criteria = "safe-to-run"
2498 delta = "0.3.13 -> 0.3.14"
2500 [[audits.h2]]
2501 who = "Mike Hommey <mh+mozilla@glandium.org>"
2502 criteria = "safe-to-run"
2503 delta = "0.3.14 -> 0.3.15"
2505 [[audits.half]]
2506 who = "John M. Schanck <jschanck@mozilla.com>"
2507 criteria = "safe-to-deploy"
2508 version = "1.8.2"
2509 notes = """
2510 This crate contains unsafe code for bitwise casts to/from binary16 floating-point
2511 format. I've reviewed these and found no issues. There are no uses of ambient
2512 capabilities.
2515 [[audits.hashbrown]]
2516 who = "Mike Hommey <mh+mozilla@glandium.org>"
2517 criteria = "safe-to-deploy"
2518 version = "0.12.3"
2519 notes = "This version is used in rust's libstd, so effectively we're already trusting it"
2521 [[audits.hashlink]]
2522 who = "Mike Hommey <mh+mozilla@glandium.org>"
2523 criteria = "safe-to-deploy"
2524 delta = "0.7.0 -> 0.8.1"
2526 [[audits.hashlink]]
2527 who = "Mike Hommey <mh+mozilla@glandium.org>"
2528 criteria = "safe-to-deploy"
2529 delta = "0.8.1 -> 0.8.2"
2530 notes = "Only dependency changes."
2532 [[audits.hashlink]]
2533 who = "Mark Hammond <mhammond@mozilla.com>"
2534 criteria = "safe-to-deploy"
2535 delta = "0.8.1 -> 0.9.1"
2536 notes = "New CursorMut struct and other relatively straight-forward changes."
2538 [[audits.hashlink]]
2539 who = "Erich Gubler <erichdongubler@gmail.com>"
2540 criteria = "safe-to-deploy"
2541 delta = "0.9.1 -> 0.10.0"
2543 [[audits.headers]]
2544 who = "Mike Hommey <mh+mozilla@glandium.org>"
2545 criteria = "safe-to-run"
2546 delta = "0.3.7 -> 0.3.8"
2548 [[audits.headers-core]]
2549 who = "Bobby Holley <bobbyholley@gmail.com>"
2550 criteria = "safe-to-deploy"
2551 version = "0.2.0"
2552 notes = "Trivial crate, no unsafe code."
2554 [[audits.heck]]
2555 who = "Mike Hommey <mh+mozilla@glandium.org>"
2556 criteria = "safe-to-deploy"
2557 delta = "0.4.0 -> 0.4.1"
2559 [[audits.hermit-abi]]
2560 who = "Mike Hommey <mh+mozilla@glandium.org>"
2561 criteria = "safe-to-deploy"
2562 delta = "0.1.19 -> 0.2.6"
2564 [[audits.hex]]
2565 who = "Simon Friedberger <simon@mozilla.com>"
2566 criteria = "safe-to-deploy"
2567 version = "0.4.3"
2569 [[audits.http]]
2570 who = "Mike Hommey <mh+mozilla@glandium.org>"
2571 criteria = "safe-to-run"
2572 delta = "0.2.8 -> 0.2.9"
2574 [[audits.httparse]]
2575 who = "Mike Hommey <mh+mozilla@glandium.org>"
2576 criteria = "safe-to-run"
2577 delta = "1.7.1 -> 1.8.0"
2579 [[audits.hyper]]
2580 who = "Mike Hommey <mh+mozilla@glandium.org>"
2581 criteria = "safe-to-run"
2582 delta = "0.14.19 -> 0.14.20"
2584 [[audits.hyper]]
2585 who = "Mike Hommey <mh+mozilla@glandium.org>"
2586 criteria = "safe-to-run"
2587 delta = "0.14.20 -> 0.14.22"
2589 [[audits.hyper]]
2590 who = "Mike Hommey <mh+mozilla@glandium.org>"
2591 criteria = "safe-to-run"
2592 delta = "0.14.22 -> 0.14.23"
2594 [[audits.hyper]]
2595 who = "Mike Hommey <mh+mozilla@glandium.org>"
2596 criteria = "safe-to-run"
2597 delta = "0.14.23 -> 0.14.24"
2599 [[audits.icu_calendar]]
2600 who = "André Bargull <andre.bargull@gmail.com>"
2601 criteria = "safe-to-deploy"
2602 version = "1.4.0"
2603 notes = "This has no unsafe code and uses no ambient capabilities."
2605 [[audits.icu_calendar]]
2606 who = "André Bargull <andre.bargull@gmail.com>"
2607 criteria = "safe-to-deploy"
2608 delta = "1.4.0 -> 1.5.1"
2610 [[audits.icu_calendar]]
2611 who = "Max Inden <mail@max-inden.de>"
2612 criteria = "safe-to-deploy"
2613 delta = "1.5.1 -> 1.5.2"
2615 [[audits.icu_calendar_data]]
2616 who = "André Bargull <andre.bargull@gmail.com>"
2617 criteria = "safe-to-deploy"
2618 version = "1.4.0"
2619 notes = "This crate is data only for icu_calendar. There is no filesystem / network access."
2621 [[audits.icu_calendar_data]]
2622 who = "André Bargull <andre.bargull@gmail.com>"
2623 criteria = "safe-to-deploy"
2624 delta = "1.4.0 -> 1.5.0"
2626 [[audits.icu_capi]]
2627 who = "Makoto Kato <m_kato@ga2.so-net.ne.jp>"
2628 criteria = "safe-to-deploy"
2629 version = "1.2.2"
2630 notes = "This crate is C/C++ FFI for ICU4X using diplomat crate. no unsafe and no file access etc on this crate."
2632 [[audits.icu_capi]]
2633 who = "Makoto Kato <m_kato@ga2.so-net.ne.jp>"
2634 criteria = "safe-to-deploy"
2635 delta = "1.2.2 -> 1.4.0"
2637 [[audits.icu_capi]]
2638 who = "Makoto Kato <m_kato@ga2.so-net.ne.jp>"
2639 criteria = "safe-to-deploy"
2640 delta = "1.4.0 -> 1.5.0"
2642 [[audits.icu_collections]]
2643 who = "Makoto Kato <m_kato@ga2.so-net.ne.jp>"
2644 criteria = "safe-to-deploy"
2645 version = "1.2.0"
2646 notes = "This crate is used by ICU4X for internal data structure. There is no fileaccess and network access. This uses unsafe block, but we confirm data is valid before."
2648 [[audits.icu_collections]]
2649 who = "Makoto Kato <m_kato@ga2.so-net.ne.jp>"
2650 criteria = "safe-to-deploy"
2651 delta = "1.2.0 -> 1.4.0"
2653 [[audits.icu_collections]]
2654 who = "Makoto Kato <m_kato@ga2.so-net.ne.jp>"
2655 criteria = "safe-to-deploy"
2656 delta = "1.4.0 -> 1.5.0"
2658 [[audits.icu_locid]]
2659 who = "Makoto Kato <m_kato@ga2.so-net.ne.jp>"
2660 criteria = "safe-to-deploy"
2661 version = "1.2.0"
2662 notes = "This has unsafe block to handle ascii string in utf-8 string. I've vetted the one instance of unsafe code."
2664 [[audits.icu_locid]]
2665 who = "Makoto Kato <m_kato@ga2.so-net.ne.jp>"
2666 criteria = "safe-to-deploy"
2667 delta = "1.2.0 -> 1.4.0"
2669 [[audits.icu_locid]]
2670 who = "Makoto Kato <m_kato@ga2.so-net.ne.jp>"
2671 criteria = "safe-to-deploy"
2672 delta = "1.4.0 -> 1.5.0"
2674 [[audits.icu_locid_transform]]
2675 who = "Makoto Kato <m_kato@ga2.so-net.ne.jp>"
2676 criteria = "safe-to-deploy"
2677 version = "1.4.0"
2678 notes = "This crate doesn't contain network and file access. Although this has unsafe block, the reason is added in the comment block. I audited code."
2680 [[audits.icu_locid_transform]]
2681 who = "Makoto Kato <m_kato@ga2.so-net.ne.jp>"
2682 criteria = "safe-to-deploy"
2683 delta = "1.4.0 -> 1.5.0"
2685 [[audits.icu_locid_transform_data]]
2686 who = "Jonathan Kew <jkew@mozilla.com>"
2687 criteria = "safe-to-deploy"
2688 version = "1.4.0"
2689 notes = "Compile-time static for the icu_locid_transform crate."
2691 [[audits.icu_locid_transform_data]]
2692 who = "Makoto Kato <m_kato@ga2.so-net.ne.jp>"
2693 criteria = "safe-to-deploy"
2694 delta = "1.4.0 -> 1.5.0"
2696 [[audits.icu_normalizer]]
2697 who = "Henri Sivonen <hsivonen@hsivonen.fi>"
2698 criteria = "safe-to-deploy"
2699 version = "1.5.0"
2700 notes = "I, Henri Sivonen, am the principal author of this crate."
2702 [[audits.icu_normalizer_data]]
2703 who = "Henri Sivonen <hsivonen@hsivonen.fi>"
2704 criteria = "safe-to-deploy"
2705 version = "1.5.0"
2707 [[audits.icu_properties]]
2708 who = "Jonathan Kew <jkew@mozilla.com>"
2709 criteria = "safe-to-deploy"
2710 version = "1.4.0"
2711 notes = "This is used by ICU4X for character property lookup. The few (4) usages of unsafe have comments clarifying their safety."
2713 [[audits.icu_properties]]
2714 who = "Makoto Kato <m_kato@ga2.so-net.ne.jp>"
2715 criteria = "safe-to-deploy"
2716 delta = "1.4.0 -> 1.5.0"
2718 [[audits.icu_properties_data]]
2719 who = "Jonathan Kew <jkew@mozilla.com>"
2720 criteria = "safe-to-deploy"
2721 version = "1.4.0"
2722 notes = "Compile-time static data for the icu_properties crate."
2724 [[audits.icu_properties_data]]
2725 who = "Makoto Kato <m_kato@ga2.so-net.ne.jp>"
2726 criteria = "safe-to-deploy"
2727 delta = "1.4.0 -> 1.5.0"
2729 [[audits.icu_provider]]
2730 who = "Makoto Kato <m_kato@ga2.so-net.ne.jp>"
2731 criteria = "safe-to-deploy"
2732 version = "1.2.0"
2733 notes = "Although this has unsafe block, this has a commnet why this is safety and I audited code. Also, this doesn't have file access and network access."
2735 [[audits.icu_provider]]
2736 who = "Makoto Kato <m_kato@ga2.so-net.ne.jp>"
2737 criteria = "safe-to-deploy"
2738 delta = "1.2.0 -> 1.4.0"
2740 [[audits.icu_provider]]
2741 who = "Makoto Kato <m_kato@ga2.so-net.ne.jp>"
2742 criteria = "safe-to-deploy"
2743 delta = "1.4.0 -> 1.5.0"
2745 [[audits.icu_provider_adapters]]
2746 who = "Makoto Kato <m_kato@ga2.so-net.ne.jp>"
2747 criteria = "safe-to-deploy"
2748 version = "1.2.0"
2749 notes = "This is one of ICU4X data provider crates that depends on data type. This has no unsafe code and uses no ambient capabilities."
2751 [[audits.icu_provider_adapters]]
2752 who = "Makoto Kato <m_kato@ga2.so-net.ne.jp>"
2753 criteria = "safe-to-deploy"
2754 delta = "1.2.0 -> 1.4.0"
2756 [[audits.icu_provider_adapters]]
2757 who = "Makoto Kato <m_kato@ga2.so-net.ne.jp>"
2758 criteria = "safe-to-deploy"
2759 delta = "1.4.0 -> 1.5.0"
2761 [[audits.icu_provider_macros]]
2762 who = "Makoto Kato <m_kato@ga2.so-net.ne.jp>"
2763 criteria = "safe-to-deploy"
2764 version = "1.2.0"
2765 notes = "This crate is macros for ICU4X's data provider implementer. This has no unsafe code and uses no ambient capabilities."
2767 [[audits.icu_provider_macros]]
2768 who = "Makoto Kato <m_kato@ga2.so-net.ne.jp>"
2769 criteria = "safe-to-deploy"
2770 delta = "1.2.0 -> 1.2.0@git:14e9a3a9857be74582abe2dfa7ab799c5eaac873"
2772 [[audits.icu_provider_macros]]
2773 who = "Makoto Kato <m_kato@ga2.so-net.ne.jp>"
2774 criteria = "safe-to-deploy"
2775 delta = "1.2.0 -> 1.4.0"
2777 [[audits.icu_provider_macros]]
2778 who = "Makoto Kato <m_kato@ga2.so-net.ne.jp>"
2779 criteria = "safe-to-deploy"
2780 delta = "1.4.0 -> 1.5.0"
2782 [[audits.icu_segmenter]]
2783 who = "Makoto Kato <m_kato@ga2.so-net.ne.jp>"
2784 criteria = "safe-to-deploy"
2785 version = "1.2.1"
2786 notes = "Original authors are Makoto Kato and Ting-Yu Lin who work at Mozilla. This crate uses unsafe to matrix calculation, but it is safety to check length. And there is no filesystem / network access."
2788 [[audits.icu_segmenter]]
2789 who = "Makoto Kato <m_kato@ga2.so-net.ne.jp>"
2790 criteria = "safe-to-deploy"
2791 delta = "1.2.1 -> 1.4.0"
2793 [[audits.icu_segmenter]]
2794 who = "Makoto Kato <m_kato@ga2.so-net.ne.jp>"
2795 criteria = "safe-to-deploy"
2796 delta = "1.4.0 -> 1.5.0"
2798 [[audits.icu_segmenter_data]]
2799 who = "Makoto Kato <m_kato@ga2.so-net.ne.jp>"
2800 criteria = "safe-to-deploy"
2801 version = "1.4.0"
2802 notes = "This crate is data only for icu_segmenter. There is no filesystem / network access."
2804 [[audits.icu_segmenter_data]]
2805 who = "Makoto Kato <m_kato@ga2.so-net.ne.jp>"
2806 criteria = "safe-to-deploy"
2807 delta = "1.4.0 -> 1.5.0"
2809 [[audits.idna]]
2810 who = "Bobby Holley <bobbyholley@gmail.com>"
2811 criteria = "safe-to-deploy"
2812 delta = "0.3.0 -> 0.2.3"
2813 notes = "Backwards diff with some algorithm changes, no unsafe code."
2815 [[audits.idna]]
2816 who = "Valentin Gosu <valentin.gosu@gmail.com>"
2817 criteria = "safe-to-deploy"
2818 delta = "0.4.0 -> 0.5.0"
2820 [[audits.idna]]
2821 who = "Henri Sivonen <hsivonen@hsivonen.fi>"
2822 criteria = "safe-to-deploy"
2823 delta = "0.5.0 -> 1.0.2"
2824 notes = "In the 0.5.0 to 1.0.2 delta, I, Henri Sivonen, rewrote the non-Punycode internals of the crate and made the changes to the Punycode code."
2826 [[audits.idna]]
2827 who = "Valentin Gosu <valentin.gosu@gmail.com>"
2828 criteria = "safe-to-deploy"
2829 delta = "1.0.2 -> 1.0.3"
2831 [[audits.idna_adapter]]
2832 who = "Valentin Gosu <valentin.gosu@gmail.com>"
2833 criteria = "safe-to-deploy"
2834 version = "1.2.0"
2836 [[audits.indexmap]]
2837 who = "Mike Hommey <mh+mozilla@glandium.org>"
2838 criteria = "safe-to-deploy"
2839 delta = "1.8.2 -> 1.9.1"
2841 [[audits.indexmap]]
2842 who = "Mike Hommey <mh+mozilla@glandium.org>"
2843 criteria = "safe-to-deploy"
2844 delta = "1.9.1 -> 1.9.2"
2846 [[audits.indexmap]]
2847 who = "Erich Gubler <erichdongubler@gmail.com>"
2848 criteria = "safe-to-deploy"
2849 delta = "2.2.6 -> 2.7.1"
2851 [[audits.inherent]]
2852 who = "Mike Hommey <mh+mozilla@glandium.org>"
2853 criteria = "safe-to-deploy"
2854 delta = "1.0.1 -> 1.0.2"
2856 [[audits.inherent]]
2857 who = "Mike Hommey <mh+mozilla@glandium.org>"
2858 criteria = "safe-to-deploy"
2859 delta = "1.0.2 -> 1.0.3"
2861 [[audits.inherent]]
2862 who = "Mike Hommey <mh+mozilla@glandium.org>"
2863 criteria = "safe-to-deploy"
2864 delta = "1.0.3 -> 1.0.4"
2866 [[audits.inplace_it]]
2867 who = "Mike Hommey <mh+mozilla@glandium.org>"
2868 criteria = "safe-to-deploy"
2869 delta = "0.3.3 -> 0.3.4"
2871 [[audits.intl-memoizer]]
2872 who = "Zibi Braniecki <zibi@unicode.org>"
2873 criteria = "safe-to-deploy"
2874 version = "0.5.1"
2876 [[audits.intl_pluralrules]]
2877 who = "Zibi Braniecki <zibi@unicode.org>"
2878 criteria = "safe-to-deploy"
2879 version = "7.0.1"
2881 [[audits.intl_pluralrules]]
2882 who = "Makoto Kato <m_kato@ga2.so-net.ne.jp>"
2883 criteria = "safe-to-deploy"
2884 delta = "7.0.1 -> 7.0.2"
2886 [[audits.itertools]]
2887 who = "Mike Hommey <mh+mozilla@glandium.org>"
2888 criteria = "safe-to-deploy"
2889 delta = "0.10.3 -> 0.10.5"
2891 [[audits.itoa]]
2892 who = "Mike Hommey <mh+mozilla@glandium.org>"
2893 criteria = "safe-to-deploy"
2894 delta = "1.0.2 -> 1.0.3"
2896 [[audits.itoa]]
2897 who = "Mike Hommey <mh+mozilla@glandium.org>"
2898 criteria = "safe-to-deploy"
2899 delta = "1.0.3 -> 1.0.5"
2901 [[audits.jobserver]]
2902 who = "Mike Hommey <mh+mozilla@glandium.org>"
2903 criteria = "safe-to-deploy"
2904 delta = "0.1.24 -> 0.1.25"
2906 [[audits.keccak]]
2907 who = "Simon Friedberger <simon@mozilla.com>"
2908 criteria = "safe-to-deploy"
2909 delta = "0.1.2 -> 0.1.3"
2911 [[audits.khronos-egl]]
2912 who = "Nicolas Silva <nical@fastmail.com>"
2913 criteria = "safe-to-deploy"
2914 delta = "4.1.0 -> 6.0.0"
2916 [[audits.leak]]
2917 who = "Sotaro Ikeda <sotaro.ikeda.g@gmail.com>"
2918 criteria = "safe-to-deploy"
2919 version = "0.1.2"
2921 [[audits.leaky-cow]]
2922 who = "Sotaro Ikeda <sotaro.ikeda.g@gmail.com>"
2923 criteria = "safe-to-deploy"
2924 version = "0.1.1"
2926 [[audits.libc]]
2927 who = "Mike Hommey <mh+mozilla@glandium.org>"
2928 criteria = "safe-to-deploy"
2929 delta = "0.2.126 -> 0.2.132"
2931 [[audits.libc]]
2932 who = "Mike Hommey <mh+mozilla@glandium.org>"
2933 criteria = "safe-to-deploy"
2934 delta = "0.2.132 -> 0.2.138"
2936 [[audits.libc]]
2937 who = "Mike Hommey <mh+mozilla@glandium.org>"
2938 criteria = "safe-to-deploy"
2939 delta = "0.2.138 -> 0.2.139"
2941 [[audits.libc]]
2942 who = "Mike Hommey <mh+mozilla@glandium.org>"
2943 criteria = "safe-to-deploy"
2944 delta = "0.2.147 -> 0.2.148"
2946 [[audits.libc]]
2947 who = "Alex Franchuk <afranchuk@mozilla.com>"
2948 criteria = "safe-to-deploy"
2949 delta = "0.2.154 -> 0.2.158"
2951 [[audits.libloading]]
2952 who = "Mike Hommey <mh+mozilla@glandium.org>"
2953 criteria = "safe-to-deploy"
2954 delta = "0.7.3 -> 0.7.4"
2956 [[audits.libloading]]
2957 who = "Erich Gubler <erichdongubler@gmail.com>"
2958 criteria = "safe-to-deploy"
2959 delta = "0.7.4 -> 0.8.3"
2961 [[audits.libm]]
2962 who = "Makoto Kato <m_kato@ga2.so-net.ne.jp>"
2963 criteria = "safe-to-deploy"
2964 version = "0.2.6"
2965 notes = "This crate uses unsafe block, but this doesn't have network and file access. I audited code."
2967 [[audits.libsqlite3-sys]]
2968 who = "Ben Dean-Kawamura <bdk@mozilla.com>"
2969 criteria = "safe-to-deploy"
2970 delta = "0.25.2 -> 0.26.0"
2972 [[audits.libsqlite3-sys]]
2973 who = "Mark Hammond <mhammond@mozilla.com>"
2974 criteria = "safe-to-deploy"
2975 delta = "0.26.0 -> 0.27.0"
2977 [[audits.libsqlite3-sys]]
2978 who = "Mark Hammond <mhammond@mozilla.com>"
2979 criteria = "safe-to-deploy"
2980 delta = "0.27.0 -> 0.28.0"
2982 [[audits.libsqlite3-sys]]
2983 who = "Erich Gubler <erichdongubler@gmail.com>"
2984 criteria = "safe-to-deploy"
2985 delta = "0.28.0 -> 0.31.0"
2987 [[audits.libz-rs-sys]]
2988 who = "Mike Hommey <mh+mozilla@glandium.org>"
2989 criteria = "safe-to-deploy"
2990 delta = "0.2.1 -> 0.2.1@git:4aa430ccb77537d0d60dab8db993ca51bb1194c5"
2991 importable = false
2993 [[audits.linked-hash-map]]
2994 who = "Aria Beingessner <a.beingessner@gmail.com>"
2995 criteria = "safe-to-deploy"
2996 version = "0.5.4"
2997 notes = "I own this crate (I am contain-rs) and 0.5.4 passes miri. This code is very old and used by lots of people, so I'm pretty confident in it, even though it's in maintenance-mode and missing some nice-to-have APIs."
2999 [[audits.linked-hash-map]]
3000 who = "Alex Franchuk <afranchuk@mozilla.com>"
3001 criteria = "safe-to-deploy"
3002 delta = "0.5.4 -> 0.5.6"
3003 notes = "New unsafe code has debug assertions and meets invariants. All other changes are formatting-related."
3005 [[audits.linked-hash-map]]
3006 who = "Mike Hommey <mh+mozilla@glandium.org>"
3007 criteria = "safe-to-run"
3008 delta = "0.5.4 -> 0.5.6"
3010 [[audits.litemap]]
3011 who = "Makoto Kato <m_kato@ga2.so-net.ne.jp>"
3012 criteria = "safe-to-deploy"
3013 version = "0.7.0"
3014 notes = "This crete has no unsafe code, no file acceess and no network access."
3016 [[audits.litemap]]
3017 who = "Makoto Kato <m_kato@ga2.so-net.ne.jp>"
3018 criteria = "safe-to-deploy"
3019 delta = "0.7.0 -> 0.7.2"
3021 [[audits.litemap]]
3022 who = "Makoto Kato <m_kato@ga2.so-net.ne.jp>"
3023 criteria = "safe-to-deploy"
3024 delta = "0.7.2 -> 0.7.3"
3026 [[audits.litrs]]
3027 who = "Erich Gubler <erichdongubler@gmail.com>"
3028 criteria = "safe-to-deploy"
3029 version = "0.4.1"
3031 [[audits.lmdb-rkv]]
3032 who = "Bobby Holley <bobbyholley@gmail.com>"
3033 criteria = "safe-to-deploy"
3034 version = "0.14.0"
3035 notes = "Victor and Myk developed this crate at Mozilla."
3037 [[audits.lock_api]]
3038 who = "Mike Hommey <mh+mozilla@glandium.org>"
3039 criteria = "safe-to-deploy"
3040 delta = "0.4.7 -> 0.4.9"
3042 [[audits.log]]
3043 who = "Mike Hommey <mh+mozilla@glandium.org>"
3044 criteria = "safe-to-deploy"
3045 version = "0.4.17"
3047 [[audits.mach2]]
3048 who = "Gabriele Svelto <gsvelto@mozilla.com>"
3049 criteria = "safe-to-deploy"
3050 version = "0.4.1"
3052 [[audits.malloc_buf]]
3053 who = "Bobby Holley <bobbyholley@gmail.com>"
3054 criteria = "safe-to-deploy"
3055 version = "0.0.6"
3056 notes = """
3057 Very small crate for managing malloc-ed buffers, primarily for use in the objc crate.
3058 There is an edge-case condition that passes slice::from_raw_parts(0x1, 0) which I'm
3059 not entirely certain is technically sound, but in either case I am reasonably confident
3060 it's not exploitable.
3063 [[audits.malloc_size_of_derive]]
3064 who = "Bobby Holley <bobbyholley@gmail.com>"
3065 criteria = "safe-to-deploy"
3066 version = "0.1.2"
3067 notes = """
3068 This was originally servo code which I put on crates.io some years ago but didn't
3069 examine at the time, so I examined it now. I didn't perform a full logic review
3070 but convinced myself that any generated code will be entirely safe to deploy.
3073 [[audits.matches]]
3074 who = "Bobby Holley <bobbyholley@gmail.com>"
3075 criteria = "safe-to-deploy"
3076 version = "0.1.9"
3077 notes = "This is a trivial crate."
3079 [[audits.matches]]
3080 who = "Mike Hommey <mh+mozilla@glandium.org>"
3081 criteria = "safe-to-deploy"
3082 delta = "0.1.9 -> 0.1.10"
3084 [[audits.maybe-async]]
3085 who = "Benjamin Beurdouche <beurdouche@mozilla.com>"
3086 criteria = "safe-to-deploy"
3087 version = "0.2.10"
3089 [[audits.md-5]]
3090 who = "Dana Keeler <dkeeler@mozilla.com>"
3091 criteria = "safe-to-deploy"
3092 version = "0.10.5"
3094 [[audits.memmap2]]
3095 who = "Mike Hommey <mh+mozilla@glandium.org>"
3096 criteria = "safe-to-deploy"
3097 delta = "0.5.4 -> 0.5.7"
3099 [[audits.memmap2]]
3100 who = "Mike Hommey <mh+mozilla@glandium.org>"
3101 criteria = "safe-to-deploy"
3102 delta = "0.5.7 -> 0.5.8"
3104 [[audits.memmap2]]
3105 who = "Mike Hommey <mh+mozilla@glandium.org>"
3106 criteria = "safe-to-deploy"
3107 delta = "0.5.8 -> 0.5.9"
3109 [[audits.memmap2]]
3110 who = "Gabriele Svelto <gsvelto@mozilla.com>"
3111 criteria = "safe-to-deploy"
3112 delta = "0.5.9 -> 0.8.0"
3114 [[audits.memmap2]]
3115 who = "Mike Hommey <mh+mozilla@glandium.org>"
3116 criteria = "safe-to-deploy"
3117 delta = "0.8.0 -> 0.9.3"
3119 [[audits.memoffset]]
3120 who = "Gabriele Svelto <gsvelto@mozilla.com>"
3121 criteria = "safe-to-deploy"
3122 delta = "0.6.5 -> 0.7.1"
3124 [[audits.memoffset]]
3125 who = "Gabriele Svelto <gsvelto@mozilla.com>"
3126 criteria = "safe-to-deploy"
3127 delta = "0.8.0 -> 0.9.0"
3129 [[audits.metal]]
3130 who = "Jim Blandy <jimb@red-bean.com>"
3131 criteria = "safe-to-deploy"
3132 version = "0.23.1"
3133 notes = "This audit treats Dzmitry Malyshau (kvark) as a trusted reviewer."
3135 [[audits.metal]]
3136 who = "Jim Blandy <jimb@red-bean.com>"
3137 criteria = "safe-to-deploy"
3138 delta = "0.23.1 -> 0.24.0"
3139 notes = "This audit treats Dzmitry Malyshau (kvark) as a trusted reviewer."
3141 [[audits.metal]]
3142 who = "Teodor Tanasoaia <ttanasoaia@mozilla.com>"
3143 criteria = "safe-to-deploy"
3144 delta = "0.24.0 -> 0.25.0"
3146 [[audits.metal]]
3147 who = "Erich Gubler <egubler@mozilla.com>"
3148 criteria = "safe-to-deploy"
3149 delta = "0.25.0 -> 0.26.0"
3151 [[audits.metal]]
3152 who = "Nicolas Silva <nical@fastmail.com>, Jim Blandy <jimb@red-bean.com>"
3153 criteria = "safe-to-deploy"
3154 delta = "0.26.0 -> 0.27.0"
3156 [[audits.metal]]
3157 who = "Teodor Tanasoaia <ttanasoaia@mozilla.com>"
3158 criteria = "safe-to-deploy"
3159 delta = "0.27.0 -> 0.27.0@git:ff8fd3d6dc7792852f8a015458d7e6d42d7fb352"
3161 [[audits.metal]]
3162 who = "Erich Gubler <erichdongubler@gmail.com>"
3163 criteria = "safe-to-deploy"
3164 delta = "0.27.0 -> 0.28.0"
3165 notes = "No significantly changed functionality. Some warnings resolved, bumped `core-graphics-types`, newer versions of Metal supported."
3167 [[audits.metal]]
3168 who = "Erich Gubler <erichdongubler@gmail.com>"
3169 criteria = "safe-to-deploy"
3170 delta = "0.28.0 -> 0.29.0"
3172 [[audits.metal]]
3173 who = "Erich Gubler <erichdongubler@gmail.com>"
3174 criteria = "safe-to-deploy"
3175 delta = "0.29.0 -> 0.30.0"
3177 [[audits.metal]]
3178 who = "Teodor Tanasoaia <ttanasoaia@mozilla.com>"
3179 criteria = "safe-to-deploy"
3180 delta = "0.30.0 -> 0.30.0@git:ef768ff9d742ae6a0f4e83ddc8031264e7d460c4"
3182 [[audits.metal]]
3183 who = "Erich Gubler <erichdongubler@gmail.com>"
3184 criteria = "safe-to-deploy"
3185 delta = "0.30.0 -> 0.31.0"
3187 [[audits.midir]]
3188 who = "Bobby Holley <bobbyholley@gmail.com>"
3189 criteria = "safe-to-deploy"
3190 delta = "0.7.0 -> 0.7.0@git:519e651241e867af3391db08f9ae6400bc023e18"
3192 [[audits.midir]]
3193 who = "Mike Hommey <mh+mozilla@glandium.org>"
3194 criteria = "safe-to-deploy"
3195 delta = "0.7.0 -> 0.7.0@git:85156e360a37d851734118104619f86bd18e94c6"
3196 importable = false
3198 [[audits.minidump-common]]
3199 who = "Gabriele Svelto <gsvelto@mozilla.com>"
3200 criteria = "safe-to-deploy"
3201 version = "0.15.2"
3202 notes = "The code in this crate was written or reviewed by Mozilla employees."
3204 [[audits.minidump-common]]
3205 who = "Gabriele Svelto <gsvelto@mozilla.com>"
3206 criteria = "safe-to-deploy"
3207 delta = "0.15.2 -> 0.17.0"
3209 [[audits.minidump-common]]
3210 who = "Mike Hommey <mh+mozilla@glandium.org>"
3211 criteria = "safe-to-deploy"
3212 delta = "0.17.0 -> 0.17.0@git:87a29fba5e19cfae5ebf73a57ba31504a3872545"
3214 [[audits.minidump-common]]
3215 who = "Gabriele Svelto <gsvelto@mozilla.com>"
3216 criteria = "safe-to-deploy"
3217 delta = "0.17.0 -> 0.19.1"
3218 notes = "All the changes have been authored or reviewed by Mozilla employees"
3220 [[audits.minidump-common]]
3221 who = "Mike Hommey <mh+mozilla@glandium.org>"
3222 criteria = "safe-to-deploy"
3223 delta = "0.17.0@git:87a29fba5e19cfae5ebf73a57ba31504a3872545 -> 0.17.0@git:6ae42a7f992e8a88ebee661bc77bcedb95cd671f"
3225 [[audits.minidump-writer]]
3226 who = "Gabriele Svelto <gsvelto@mozilla.com>"
3227 criteria = "safe-to-deploy"
3228 version = "0.7.0"
3229 notes = "The code in this crate was written or reviewed by Mozilla employees, the crate it evolved from was written specifically for gecko."
3231 [[audits.minidump-writer]]
3232 who = "Alex Franchuk <afranchuk@mozilla.com>"
3233 criteria = "safe-to-deploy"
3234 delta = "0.7.0 -> 0.8.0"
3235 notes = "The code in this crate was written or reviewed by Mozilla employees, the crate it evolved from was written specifically for gecko."
3237 [[audits.minidump-writer]]
3238 who = "Gabriele Svelto <gsvelto@mozilla.com>"
3239 criteria = "safe-to-deploy"
3240 delta = "0.8.0 -> 0.8.1"
3242 [[audits.minidump-writer]]
3243 who = "Gabriele Svelto <gsvelto@mozilla.com>"
3244 criteria = "safe-to-deploy"
3245 delta = "0.8.1 -> 0.8.1@git:491eb330e78e310c32927e5cc3bd2350af1e93f8"
3246 notes = "All the changes were written by a Mozilla employee (me)"
3248 [[audits.minidump-writer]]
3249 who = "Gabriele Svelto <gsvelto@mozilla.com>"
3250 criteria = "safe-to-deploy"
3251 delta = "0.8.1 -> 0.8.3"
3252 notes = "All changes were authored or reviewed by Mozilla employees"
3254 [[audits.minidump-writer]]
3255 who = "Alex Franchuk <afranchuk@mozilla.com>"
3256 criteria = "safe-to-deploy"
3257 delta = "0.8.3 -> 0.8.9"
3258 notes = "Mainly dependency updates and a few small features (in support of mozilla bugs)."
3260 [[audits.minidump-writer]]
3261 who = "Alex Franchuk <afranchuk@mozilla.com>"
3262 criteria = "safe-to-deploy"
3263 delta = "0.8.9 -> 0.10.1"
3264 notes = "Crate written and reviewed by mozilla employees."
3266 [[audits.miniz_oxide]]
3267 who = "Mike Hommey <mh+mozilla@glandium.org>"
3268 criteria = "safe-to-deploy"
3269 delta = "0.5.3 -> 0.6.2"
3271 [[audits.mio]]
3272 who = "Bobby Holley <bobbyholley@gmail.com>"
3273 criteria = "safe-to-run"
3274 delta = "0.6.21 -> 0.6.23"
3276 [[audits.mio]]
3277 who = "Mike Hommey <mh+mozilla@glandium.org>"
3278 criteria = "safe-to-deploy"
3279 delta = "0.8.0 -> 0.8.6"
3281 [[audits.mio]]
3282 who = "Mike Hommey <mh+mozilla@glandium.org>"
3283 criteria = "safe-to-deploy"
3284 delta = "0.8.8 -> 1.0.1"
3286 [[audits.mls-rs]]
3287 who = "Benjamin Beurdouche <beurdouche@mozilla.com>"
3288 criteria = "safe-to-deploy"
3289 version = "0.39.1"
3291 [[audits.mls-rs]]
3292 who = "Benjamin Beurdouche <beurdouche@mozilla.com>"
3293 criteria = "safe-to-deploy"
3294 delta = "0.39.1 -> 0.39.1@git:eedb37e50e3fca51863f460755afd632137da57c"
3295 importable = false
3297 [[audits.mls-rs-codec]]
3298 who = "Benjamin Beurdouche <beurdouche@mozilla.com>"
3299 criteria = "safe-to-deploy"
3300 version = "0.5.3"
3302 [[audits.mls-rs-codec]]
3303 who = "Benjamin Beurdouche <beurdouche@mozilla.com>"
3304 criteria = "safe-to-deploy"
3305 delta = "0.5.3 -> 0.5.3@git:eedb37e50e3fca51863f460755afd632137da57c"
3306 importable = false
3308 [[audits.mls-rs-codec-derive]]
3309 who = "Benjamin Beurdouche <beurdouche@mozilla.com>"
3310 criteria = "safe-to-deploy"
3311 version = "0.1.1"
3312 notes = "No unsafe code"
3314 [[audits.mls-rs-codec-derive]]
3315 who = "Benjamin Beurdouche <beurdouche@mozilla.com>"
3316 criteria = "safe-to-deploy"
3317 delta = "0.1.1 -> 0.1.1@git:eedb37e50e3fca51863f460755afd632137da57c"
3318 importable = false
3320 [[audits.mls-rs-core]]
3321 who = "Benjamin Beurdouche <beurdouche@mozilla.com>"
3322 criteria = "safe-to-deploy"
3323 version = "0.18.0"
3325 [[audits.mls-rs-core]]
3326 who = "Benjamin Beurdouche <beurdouche@mozilla.com>"
3327 criteria = "safe-to-deploy"
3328 delta = "0.18.0 -> 0.18.0@git:eedb37e50e3fca51863f460755afd632137da57c"
3329 importable = false
3331 [[audits.mls-rs-crypto-hpke]]
3332 who = "Benjamin Beurdouche <beurdouche@mozilla.com>"
3333 criteria = "safe-to-deploy"
3334 version = "0.9.0"
3336 [[audits.mls-rs-crypto-hpke]]
3337 who = "Benjamin Beurdouche <beurdouche@mozilla.com>"
3338 criteria = "safe-to-deploy"
3339 delta = "0.9.0 -> 0.9.0@git:eedb37e50e3fca51863f460755afd632137da57c"
3340 importable = false
3342 [[audits.mls-rs-crypto-traits]]
3343 who = "Benjamin Beurdouche <beurdouche@mozilla.com>"
3344 criteria = "safe-to-deploy"
3345 version = "0.10.0"
3347 [[audits.mls-rs-crypto-traits]]
3348 who = "Benjamin Beurdouche <beurdouche@mozilla.com>"
3349 criteria = "safe-to-deploy"
3350 delta = "0.10.0 -> 0.10.0@git:eedb37e50e3fca51863f460755afd632137da57c"
3351 importable = false
3353 [[audits.mls-rs-identity-x509]]
3354 who = "Benjamin Beurdouche <beurdouche@mozilla.com>"
3355 criteria = "safe-to-deploy"
3356 version = "0.11.0"
3358 [[audits.mls-rs-identity-x509]]
3359 who = "Benjamin Beurdouche <beurdouche@mozilla.com>"
3360 criteria = "safe-to-deploy"
3361 delta = "0.11.0 -> 0.11.0@git:eedb37e50e3fca51863f460755afd632137da57c"
3362 importable = false
3364 [[audits.mls-rs-provider-sqlite]]
3365 who = "Benjamin Beurdouche <beurdouche@mozilla.com>"
3366 criteria = "safe-to-deploy"
3367 version = "0.11.0"
3369 [[audits.mls-rs-provider-sqlite]]
3370 who = "Benjamin Beurdouche <beurdouche@mozilla.com>"
3371 criteria = "safe-to-deploy"
3372 delta = "0.11.0 -> 0.11.0@git:eedb37e50e3fca51863f460755afd632137da57c"
3373 importable = false
3375 [[audits.moz_cbor]]
3376 who = "Bobby Holley <bobbyholley@gmail.com>"
3377 criteria = "safe-to-deploy"
3378 version = "0.1.2"
3379 notes = "Developed by Mozilla staff."
3381 [[audits.naga]]
3382 who = "Dzmitry Malyshau <kvark@fastmail.com>"
3383 criteria = "safe-to-deploy"
3384 version = "0.8.0"
3385 notes = """
3386 This crate, up through the indicated version, was written or reviewed
3387 by Dzmitry Malyshau while he was a Mozilla employee. Dzmitry left
3388 Mozilla at the beginning of February 2022. This audit statement was
3389 collected by Jim Blandy, a Mozilla employee, over email in July 2022:
3390 Dzmitry was shown, and agreed to, the 'safe-to-deploy' text.
3393 [[audits.naga]]
3394 who = "Jim Blandy <jimb@red-bean.com>"
3395 criteria = "safe-to-deploy"
3396 delta = "0.8.0 -> 0.9.0"
3398 [[audits.naga]]
3399 who = "Jim Blandy <jimb@red-bean.com>"
3400 criteria = "safe-to-deploy"
3401 delta = "0.9.0 -> 0.10.0"
3403 [[audits.naga]]
3404 who = "Nicolas Silva <nical@fastmail.com>"
3405 criteria = "safe-to-deploy"
3406 delta = "0.10.0 -> 0.11.0"
3408 [[audits.naga]]
3409 who = "Nicolas Silva <nical@fastmail.com>"
3410 criteria = "safe-to-deploy"
3411 delta = "0.11.0 -> 0.12.0"
3413 [[audits.naga]]
3414 who = "Nicolas Silva <nical@fastmail.com>"
3415 criteria = "safe-to-deploy"
3416 delta = "0.12.0 -> 0.13.0"
3418 [[audits.naga]]
3419 who = "Nicolas Silva <nical@fastmail.com>"
3420 criteria = "safe-to-deploy"
3421 delta = "0.13.0 -> 0.14.0"
3423 [[audits.naga]]
3424 who = "Erich Gubler <erichdongubler@gmail.com>"
3425 criteria = "safe-to-deploy"
3426 delta = "0.14.0 -> 0.19.2"
3428 [[audits.naga]]
3429 who = [
3430     "Jim Blandy <jimb@red-bean.com>",
3431     "Nicolas Silva <nical@fastmail.com>",
3432     "Erich Gubler <erichdongubler@gmail.com>",
3433     "Teodor Tanasoaia <ttanasoaia@mozilla.com>",
3435 criteria = "safe-to-deploy"
3436 delta = "0.19.2 -> 0.20.0"
3438 [[audits.naga]]
3439 who = "Jim Blandy <jimb@red-bean.com>"
3440 criteria = "safe-to-deploy"
3441 delta = "0.20.0 -> 22.0.0"
3443 [[audits.naga]]
3444 who = "Erich Gubler <erichdongubler@gmail.com>"
3445 criteria = "safe-to-deploy"
3446 delta = "22.0.0 -> 23.0.0"
3448 [[audits.naga]]
3449 who = [
3450     "Jim Blandy <jimb@red-bean.com>",
3451     "Erich Gubler <erichdongubler@gmail.com>",
3452     "Teodor Tanasoaia <ttanasoaia@mozilla.com>",
3454 criteria = "safe-to-deploy"
3455 delta = "23.0.0 -> 23.0.0@git:aa7bec65b90028e4db6ec8def8589b52097d92f9"
3456 importable = false
3458 [[audits.naga]]
3459 who = "Erich Gubler <erichdongubler@gmail.com>"
3460 criteria = "safe-to-deploy"
3461 delta = "23.0.0 -> 23.1.0"
3463 [[audits.naga]]
3464 who = "Erich Gubler <erichdongubler@gmail.com>"
3465 criteria = "safe-to-deploy"
3466 delta = "23.1.0 -> 24.0.0"
3468 [[audits.net2]]
3469 who = "Mike Hommey <mh+mozilla@glandium.org>"
3470 criteria = "safe-to-run"
3471 delta = "0.2.37 -> 0.2.38"
3473 [[audits.new_debug_unreachable]]
3474 who = "Bobby Holley <bobbyholley@gmail.com>"
3475 criteria = "safe-to-deploy"
3476 version = "1.0.4"
3477 notes = "This is a trivial crate."
3479 [[audits.nix]]
3480 who = "Gabriele Svelto <gsvelto@mozilla.com>"
3481 criteria = "safe-to-deploy"
3482 delta = "0.15.0 -> 0.25.0"
3483 notes = "Plenty of new bindings but also several important bug fixes (including buffer overflows). New unsafe sections are restricted to wrappers and are no more dangerous than calling the C functions."
3485 [[audits.nix]]
3486 who = "Mike Hommey <mh+mozilla@glandium.org>"
3487 criteria = "safe-to-deploy"
3488 delta = "0.25.0 -> 0.25.1"
3490 [[audits.nix]]
3491 who = "Mike Hommey <mh+mozilla@glandium.org>"
3492 criteria = "safe-to-deploy"
3493 delta = "0.25.1 -> 0.26.2"
3495 [[audits.nix]]
3496 who = "Gabriele Svelto <gsvelto@mozilla.com>"
3497 criteria = "safe-to-deploy"
3498 delta = "0.26.2 -> 0.27.1"
3500 [[audits.nix]]
3501 who = "Alex Franchuk <afranchuk@mozilla.com>"
3502 criteria = "safe-to-deploy"
3503 delta = "0.27.1 -> 0.28.0"
3504 notes = """
3505 Many new features and bugfixes. Obviously there's a lot of unsafe code calling
3506 libc, but the usage looks correct.
3509 [[audits.nix]]
3510 who = "Alex Franchuk <afranchuk@mozilla.com>"
3511 criteria = "safe-to-deploy"
3512 delta = "0.28.0 -> 0.29.0"
3514 [[audits.nom]]
3515 who = "Mike Hommey <mh+mozilla@glandium.org>"
3516 criteria = "safe-to-deploy"
3517 delta = "7.1.1 -> 7.1.3"
3519 [[audits.nss-gk-api]]
3520 who = "John M. Schanck <jschanck@mozilla.com>"
3521 criteria = "safe-to-deploy"
3522 version = "0.2.1"
3523 notes = "Maintained by the CryptoEng team at Mozilla."
3525 [[audits.nss-gk-api]]
3526 who = "Benjamin Beurdouche <beurdouche@mozilla.com>"
3527 criteria = "safe-to-deploy"
3528 delta = "0.3.0 -> 0.3.0@git:e48a946811ffd64abc78de3ee284957d8d1c0d63"
3529 importable = false
3531 [[audits.ntapi]]
3532 who = "Mike Hommey <mh+mozilla@glandium.org>"
3533 criteria = "safe-to-deploy"
3534 delta = "0.3.7 -> 0.4.0"
3536 [[audits.num]]
3537 who = "Josh Stone <jistone@redhat.com>"
3538 criteria = "safe-to-deploy"
3539 version = "0.4.0"
3540 notes = "All code written or reviewed by Josh Stone."
3542 [[audits.num-bigint]]
3543 who = "Josh Stone <jistone@redhat.com>"
3544 criteria = "safe-to-deploy"
3545 version = "0.2.6"
3546 notes = "All code written or reviewed by Josh Stone."
3548 [[audits.num-bigint]]
3549 who = "Josh Stone <jistone@redhat.com>"
3550 criteria = "safe-to-deploy"
3551 version = "0.4.3"
3552 notes = "All code written or reviewed by Josh Stone."
3554 [[audits.num-complex]]
3555 who = "Josh Stone <jistone@redhat.com>"
3556 criteria = "safe-to-deploy"
3557 version = "0.4.2"
3558 notes = "All code written or reviewed by Josh Stone."
3560 [[audits.num-conv]]
3561 who = "Alex Franchuk <afranchuk@mozilla.com>"
3562 criteria = "safe-to-deploy"
3563 version = "0.1.0"
3564 notes = """
3565 Very straightforward, simple crate. No dependencies, unsafe, extern,
3566 side-effectful std functions, etc.
3569 [[audits.num-derive]]
3570 who = "Josh Stone <jistone@redhat.com>"
3571 criteria = "safe-to-deploy"
3572 version = "0.3.3"
3573 notes = "All code written or reviewed by Josh Stone."
3575 [[audits.num-derive]]
3576 who = "Mike Hommey <mh+mozilla@glandium.org>"
3577 criteria = "safe-to-deploy"
3578 delta = "0.3.3 -> 0.4.0"
3580 [[audits.num-derive]]
3581 who = "Mike Hommey <mh+mozilla@glandium.org>"
3582 criteria = "safe-to-deploy"
3583 delta = "0.4.0 -> 0.4.2"
3585 [[audits.num-integer]]
3586 who = "Josh Stone <jistone@redhat.com>"
3587 criteria = "safe-to-deploy"
3588 version = "0.1.45"
3589 notes = "All code written or reviewed by Josh Stone."
3591 [[audits.num-iter]]
3592 who = "Josh Stone <jistone@redhat.com>"
3593 criteria = "safe-to-deploy"
3594 version = "0.1.43"
3595 notes = "All code written or reviewed by Josh Stone."
3597 [[audits.num-macros]]
3598 who = "Josh Stone <jistone@redhat.com>"
3599 criteria = "safe-to-deploy"
3600 version = "0.1.40"
3601 notes = "All code written or reviewed by Josh Stone."
3603 [[audits.num-rational]]
3604 who = "Josh Stone <jistone@redhat.com>"
3605 criteria = "safe-to-deploy"
3606 version = "0.4.1"
3607 notes = "All code written or reviewed by Josh Stone."
3609 [[audits.num-traits]]
3610 who = "Josh Stone <jistone@redhat.com>"
3611 criteria = "safe-to-deploy"
3612 version = "0.2.15"
3613 notes = "All code written or reviewed by Josh Stone."
3615 [[audits.num_cpus]]
3616 who = "Mike Hommey <mh+mozilla@glandium.org>"
3617 criteria = "safe-to-deploy"
3618 delta = "1.13.1 -> 1.14.0"
3620 [[audits.num_cpus]]
3621 who = "Mike Hommey <mh+mozilla@glandium.org>"
3622 criteria = "safe-to-deploy"
3623 delta = "1.14.0 -> 1.15.0"
3625 [[audits.objc]]
3626 who = "Mike Hommey <mh+mozilla@glandium.org>"
3627 criteria = "safe-to-deploy"
3628 delta = "0.2.7 -> 0.2.7@git:4de89f5aa9851ceca4d40e7ac1e2759410c04324"
3629 importable = false
3631 [[audits.object]]
3632 who = "Mike Hommey <mh+mozilla@glandium.org>"
3633 criteria = "safe-to-deploy"
3634 delta = "0.28.4 -> 0.30.0"
3636 [[audits.object]]
3637 who = "Mike Hommey <mh+mozilla@glandium.org>"
3638 criteria = "safe-to-deploy"
3639 delta = "0.30.0 -> 0.30.3"
3641 [[audits.object]]
3642 who = "Alex Franchuk <afranchuk@mozilla.com>"
3643 criteria = "safe-to-deploy"
3644 delta = "0.33.0 -> 0.36.4"
3645 notes = "Hardly any new unsafe code, no new dependencies nor side-effectful std functions. Plenty of new tests."
3647 [[audits.once_cell]]
3648 who = "Mike Hommey <mh+mozilla@glandium.org>"
3649 criteria = "safe-to-deploy"
3650 delta = "1.12.0 -> 1.13.1"
3652 [[audits.once_cell]]
3653 who = "Mike Hommey <mh+mozilla@glandium.org>"
3654 criteria = "safe-to-deploy"
3655 delta = "1.13.1 -> 1.16.0"
3657 [[audits.once_cell]]
3658 who = "Mike Hommey <mh+mozilla@glandium.org>"
3659 criteria = "safe-to-deploy"
3660 delta = "1.16.0 -> 1.17.1"
3662 [[audits.once_cell]]
3663 who = "Erich Gubler <erichdongubler@gmail.com>"
3664 criteria = "safe-to-deploy"
3665 delta = "1.20.1 -> 1.20.2"
3666 notes = "This update works around a Cargo bug that forces the addition of `portable-atomic` into a lockfile, which we have never needed to use."
3668 [[audits.oneshot]]
3669 who = "Ben Dean-Kawamura <bdk@mozilla.com>"
3670 criteria = "safe-to-deploy"
3671 version = "0.1.5"
3672 notes = "Small crate, reviewed by bendk.  There is a decent amount of unsafe code, but it's well tested and the crate has been well-used over the years."
3674 [[audits.oneshot]]
3675 who = "Ben Dean-Kawamura <bdk@mozilla.com>"
3676 criteria = "safe-to-deploy"
3677 version = "0.1.5@git:1f3c657c8073aec4f0b6ebac7be33b4851644745"
3678 notes = """
3679 Small crate, reviewed by bendk.  There is a decent amount of unsafe code, but it's well tested and the crate has been well-used over the years.
3681 The git branch is my fork of the official code that removes the `loom` target to avoid pulling in that crate and its dependencies into moz-central.
3682 This doesn't change any of the functionality -- the `loom` target is only used for testing.
3685 [[audits.oneshot-uniffi]]
3686 who = "Ben Dean-Kawamura <bdk@mozilla.com>"
3687 criteria = "safe-to-deploy"
3688 version = "0.1.5"
3689 notes = "This is the essentially same code as `oneshot version 0.1.5` which has already been audited.  The only difference is that it won't pull in `loom` and related dependencies when `mach vendor rust` is run."
3691 [[audits.ordered-float]]
3692 who = "Mike Hommey <mh+mozilla@glandium.org>"
3693 criteria = "safe-to-deploy"
3694 delta = "3.0.0 -> 3.4.0"
3696 [[audits.origin-trial-token]]
3697 who = "Emilio Cobos Álvarez <emilio@crisal.io>"
3698 criteria = "safe-to-deploy"
3699 version = "0.1.1"
3700 notes = """
3701 I'm the author of the crate. The only unsafe code is a view over a byte array
3702 which is properly validated.
3704 Cryptography shenanigans are delegated to the caller so there's no possible
3705 unsoundness there.
3708 [[audits.os_str_bytes]]
3709 who = "Mike Hommey <mh+mozilla@glandium.org>"
3710 criteria = "safe-to-deploy"
3711 delta = "6.1.0 -> 6.3.0"
3713 [[audits.os_str_bytes]]
3714 who = "Mike Hommey <mh+mozilla@glandium.org>"
3715 criteria = "safe-to-deploy"
3716 delta = "6.3.0 -> 6.4.1"
3718 [[audits.oxilangtag]]
3719 who = "Jonathan Kew <jkew@mozilla.com>"
3720 criteria = "safe-to-deploy"
3721 version = "0.1.3"
3722 notes = """
3723 I have reviewed all the code in this (small) crate.
3724 There is no unsafe code present.
3727 [[audits.packed_simd]]
3728 who = "Henri Sivonen <hsivonen@hsivonen.fi>"
3729 criteria = "safe-to-deploy"
3730 delta = "0.3.8 -> 0.3.9"
3731 notes = "The update from 0.3.8 to 0.3.9 makes mechanical changes to accommodate renaming, compiler updates, and CI service updates."
3733 [[audits.packed_simd]]
3734 who = "Henri Sivonen <hsivonen@hsivonen.fi>"
3735 criteria = "safe-to-deploy"
3736 delta = "0.3.9 -> 0.3.9@git:e588ceb568878e1a3156ea9ce551d5b63ef0cdc4"
3737 notes = "The patch on top of crates.io version 0.3.9 merely deletes code for a feature that Firefox does not use."
3739 [[audits.packed_simd_2]]
3740 who = "Mike Hommey <mh+mozilla@glandium.org>"
3741 criteria = "safe-to-deploy"
3742 delta = "0.3.7 -> 0.3.8"
3744 [[audits.packed_simd_2]]
3745 who = "Bobby Holley <bobbyholley@gmail.com>"
3746 criteria = "safe-to-deploy"
3747 delta = "0.3.8 -> 0.3.8@git:412f9a0aa556611de021bde89dee8fefe6e0fbbd"
3749 [[audits.parking_lot_core]]
3750 who = "Mike Hommey <mh+mozilla@glandium.org>"
3751 criteria = "safe-to-deploy"
3752 delta = "0.8.5 -> 0.8.6"
3754 [[audits.paste]]
3755 who = "Mike Hommey <mh+mozilla@glandium.org>"
3756 criteria = "safe-to-deploy"
3757 delta = "1.0.7 -> 1.0.8"
3759 [[audits.paste]]
3760 who = "Mike Hommey <mh+mozilla@glandium.org>"
3761 criteria = "safe-to-deploy"
3762 delta = "1.0.8 -> 1.0.11"
3764 [[audits.peeking_take_while]]
3765 who = "Bobby Holley <bobbyholley@gmail.com>"
3766 criteria = "safe-to-deploy"
3767 delta = "1.0.0 -> 0.1.2"
3768 notes = "Small refactor of some simple iterator logic, no unsafe code or capabilities."
3770 [[audits.percent-encoding]]
3771 who = "Valentin Gosu <valentin.gosu@gmail.com>"
3772 criteria = "safe-to-deploy"
3773 delta = "2.2.0 -> 2.3.0"
3775 [[audits.percent-encoding]]
3776 who = "Valentin Gosu <valentin.gosu@gmail.com>"
3777 criteria = "safe-to-deploy"
3778 delta = "2.3.0 -> 2.3.1"
3780 [[audits.phf]]
3781 who = "Mike Hommey <mh+mozilla@glandium.org>"
3782 criteria = "safe-to-deploy"
3783 delta = "0.10.1 -> 0.11.2"
3785 [[audits.phf_codegen]]
3786 who = "Mike Hommey <mh+mozilla@glandium.org>"
3787 criteria = "safe-to-deploy"
3788 delta = "0.10.0 -> 0.11.2"
3790 [[audits.phf_generator]]
3791 who = "Mike Hommey <mh+mozilla@glandium.org>"
3792 criteria = "safe-to-deploy"
3793 delta = "0.10.0 -> 0.11.2"
3795 [[audits.phf_macros]]
3796 who = "Mike Hommey <mh+mozilla@glandium.org>"
3797 criteria = "safe-to-deploy"
3798 delta = "0.10.0 -> 0.11.2"
3800 [[audits.phf_shared]]
3801 who = "Mike Hommey <mh+mozilla@glandium.org>"
3802 criteria = "safe-to-deploy"
3803 delta = "0.10.0 -> 0.11.2"
3805 [[audits.pin-project]]
3806 who = "Mike Hommey <mh+mozilla@glandium.org>"
3807 criteria = "safe-to-run"
3808 delta = "1.0.10 -> 1.0.12"
3810 [[audits.pin-project]]
3811 who = "Mike Hommey <mh+mozilla@glandium.org>"
3812 criteria = "safe-to-run"
3813 delta = "1.0.12 -> 1.1.0"
3815 [[audits.pin-project-internal]]
3816 who = "Mike Hommey <mh+mozilla@glandium.org>"
3817 criteria = "safe-to-run"
3818 delta = "1.0.10 -> 1.0.12"
3820 [[audits.pin-project-internal]]
3821 who = "Mike Hommey <mh+mozilla@glandium.org>"
3822 criteria = "safe-to-run"
3823 delta = "1.0.12 -> 1.1.0"
3825 [[audits.pin-project-lite]]
3826 who = "Mike Hommey <mh+mozilla@glandium.org>"
3827 criteria = "safe-to-deploy"
3828 delta = "0.2.13 -> 0.2.14"
3830 [[audits.pkcs11-bindings]]
3831 who = "Dana Keeler <dkeeler@mozilla.com>"
3832 criteria = "safe-to-deploy"
3833 version = "0.1.0"
3834 notes = """
3835 This crate consists of declarations of types and constants that are
3836 auto-generated by running bindgen on the PKCS#11 specification headers. Other
3837 than the tests generated by bindgen, it consists of no runnable code.
3840 [[audits.pkcs11-bindings]]
3841 who = "John M. Schanck <jmschanck@gmail.com>"
3842 criteria = "safe-to-deploy"
3843 version = "0.1.1"
3845 [[audits.pkcs11-bindings]]
3846 who = "Mike Hommey <mh+mozilla@glandium.org>"
3847 criteria = "safe-to-deploy"
3848 delta = "0.1.1 -> 0.1.4"
3850 [[audits.pkcs11-bindings]]
3851 who = "Mike Hommey <mh+mozilla@glandium.org>"
3852 criteria = "safe-to-deploy"
3853 delta = "0.1.4 -> 0.1.5"
3855 [[audits.pkg-config]]
3856 who = "Mike Hommey <mh+mozilla@glandium.org>"
3857 criteria = "safe-to-deploy"
3858 delta = "0.3.25 -> 0.3.26"
3860 [[audits.plane-split]]
3861 who = "Nicolas Silva <nical@fastmail.com>"
3862 criteria = "safe-to-deploy"
3863 version = "0.18.0"
3864 notes = "Mozilla-developed package, no unsafe code, no access to file system, network or other far reaching APIs."
3866 [[audits.powerfmt]]
3867 who = "Alex Franchuk <afranchuk@mozilla.com>"
3868 criteria = "safe-to-deploy"
3869 version = "0.2.0"
3870 notes = """
3871 A tiny bit of unsafe code to implement functionality that isn't in stable rust
3872 yet, but it's all valid. Otherwise it's a pretty simple crate.
3875 [[audits.ppv-lite86]]
3876 who = "Mike Hommey <mh+mozilla@glandium.org>"
3877 criteria = "safe-to-deploy"
3878 delta = "0.2.16 -> 0.2.17"
3880 [[audits.precomputed-hash]]
3881 who = "Bobby Holley <bobbyholley@gmail.com>"
3882 criteria = "safe-to-deploy"
3883 version = "0.1.1"
3884 notes = "This is a trivial crate."
3886 [[audits.prio]]
3887 who = "Simon Friedberger <simon@mozilla.com>"
3888 criteria = "safe-to-deploy"
3889 version = "0.8.4"
3890 notes = "The crate does not use any unsafe code or ambient capabilities and thus meets the criteria for safe-to-deploy. The cryptography itself should be considered experimental at this phase and is currently undergoing a thorough audit organized by Cloudflare."
3892 [[audits.prio]]
3893 who = "Simon Friedberger <simon@mozilla.com>"
3894 criteria = "safe-to-deploy"
3895 version = "0.9.1"
3897 [[audits.proc-macro-hack]]
3898 who = "Mike Hommey <mh+mozilla@glandium.org>"
3899 criteria = "safe-to-deploy"
3900 delta = "0.5.19 -> 0.5.20+deprecated"
3902 [[audits.proc-macro2]]
3903 who = "Nika Layzell <nika@thelayzells.com>"
3904 criteria = "safe-to-deploy"
3905 version = "1.0.39"
3906 notes = """
3907 `proc-macro2` acts as either a thin(-ish) wrapper around the std-provided
3908 `proc_macro` crate, or as a fallback implementation of the crate, depending on
3909 where it is used.
3911 If using this crate on older versions of rustc (1.56 and earlier), it will
3912 temporarily replace the panic handler while initializing in order to detect if
3913 it is running within a `proc_macro`, which could lead to surprising behaviour.
3914 This should not be an issue for more recent compiler versions, which support
3915 `proc_macro::is_available()`.
3917 The `proc-macro2` crate's fallback behaviour is not identical to the complex
3918 behaviour of the rustc compiler (e.g. it does not perform unicode normalization
3919 for identifiers), however it behaves well enough for its intended use-case
3920 (tests and scripts processing rust code).
3922 `proc-macro2` does not use unsafe code, however exposes one `unsafe` API to
3923 allow bypassing checks in the fallback implementation when constructing
3924 `Literal` using `from_str_unchecked`. This was intended to only be used by the
3925 `quote!` macro, however it has been removed
3926 (https://github.com/dtolnay/quote/commit/f621fe64a8a501cae8e95ebd6848e637bbc79078),
3927 and is likely completely unused. Even when used, this API shouldn't be able to
3928 cause unsoundness.
3931 [[audits.proc-macro2]]
3932 who = "Mike Hommey <mh+mozilla@glandium.org>"
3933 criteria = "safe-to-deploy"
3934 delta = "1.0.39 -> 1.0.43"
3936 [[audits.proc-macro2]]
3937 who = "Mike Hommey <mh+mozilla@glandium.org>"
3938 criteria = "safe-to-deploy"
3939 delta = "1.0.43 -> 1.0.49"
3941 [[audits.proc-macro2]]
3942 who = "Mike Hommey <mh+mozilla@glandium.org>"
3943 criteria = "safe-to-deploy"
3944 delta = "1.0.49 -> 1.0.51"
3946 [[audits.procfs-core]]
3947 who = "Gabriele Svelto <gsvelto@mozilla.com>"
3948 criteria = "safe-to-deploy"
3949 version = "0.16.0-RC1"
3951 [[audits.procfs-core]]
3952 who = "Gabriele Svelto <gsvelto@mozilla.com>"
3953 criteria = "safe-to-deploy"
3954 delta = "0.16.0-RC1 -> 0.16.0"
3956 [[audits.profiling]]
3957 who = "Mike Hommey <mh+mozilla@glandium.org>"
3958 criteria = "safe-to-deploy"
3959 delta = "1.0.6 -> 1.0.7"
3961 [[audits.prost]]
3962 who = "Jan-Erik Rediger <jrediger@mozilla.com>"
3963 criteria = "safe-to-deploy"
3964 delta = "0.8.0 -> 0.11.9"
3965 notes = "Mostly internal refactorings. Minimal new unsafe code, but with the invariants explicitly checked in code"
3967 [[audits.prost]]
3968 who = "Drew Willcoxon <adw@mozilla.com>"
3969 criteria = "safe-to-deploy"
3970 delta = "0.11.9 -> 0.12.1"
3972 [[audits.prost-derive]]
3973 who = "Jan-Erik Rediger <jrediger@mozilla.com>"
3974 criteria = "safe-to-deploy"
3975 delta = "0.8.0 -> 0.11.9"
3976 notes = "Documentation and internal refactoring changes only"
3978 [[audits.prost-derive]]
3979 who = "Mike Hommey <mh+mozilla@glandium.org>"
3980 criteria = "safe-to-deploy"
3981 delta = "0.11.9 -> 0.11.9@git:95964e9d33df3c2a9c3f14285e262867cab6f96b"
3982 notes = "Changes against 0.11.9 are mine."
3984 [[audits.prost-derive]]
3985 who = "Drew Willcoxon <adw@mozilla.com>"
3986 criteria = "safe-to-deploy"
3987 delta = "0.11.9 -> 0.12.1"
3989 [[audits.qlog]]
3990 who = "Kershaw Chang <kershaw@mozilla.com>"
3991 criteria = "safe-to-deploy"
3992 version = "0.9.0"
3994 [[audits.qlog]]
3995 who = "Kershaw Chang <kershaw@mozilla.com>"
3996 criteria = "safe-to-deploy"
3997 delta = "0.9.0 -> 0.11.0"
3999 [[audits.qlog]]
4000 who = "Kershaw Chang <kershaw@mozilla.com>"
4001 criteria = "safe-to-deploy"
4002 delta = "0.11.0 -> 0.12.0"
4004 [[audits.qlog]]
4005 who = "Kershaw Chang <kershaw@mozilla.com>"
4006 criteria = "safe-to-deploy"
4007 delta = "0.12.0 -> 0.13.0"
4009 [[audits.quinn-udp]]
4010 who = "Kershaw Chang <kershaw@mozilla.com>"
4011 criteria = "safe-to-run"
4012 version = "0.5.0"
4014 [[audits.quinn-udp]]
4015 who = "Max Inden <mail@max-inden.de>"
4016 criteria = "safe-to-deploy"
4017 version = "0.5.4"
4018 notes = "This is a small crate, providing safe wrappers around various low-level networking specific operating system features. Given that the Rust standard library does not provide safe wrappers for these low-level features, safe wrappers need to be build in the crate itself, i.e. `quinn-udp`, thus requiring `unsafe` code."
4020 [[audits.quinn-udp]]
4021 who = "Max Inden <mail@max-inden.de>"
4022 criteria = "safe-to-deploy"
4023 delta = "0.5.4 -> 0.5.6"
4025 [[audits.quinn-udp]]
4026 who = "Max Inden <mail@max-inden.de>"
4027 criteria = "safe-to-deploy"
4028 delta = "0.5.6 -> 0.5.8"
4030 [[audits.quinn-udp]]
4031 who = "Max Inden <mail@max-inden.de>"
4032 criteria = "safe-to-deploy"
4033 delta = "0.5.8 -> 0.5.9"
4035 [[audits.quote]]
4036 who = "Nika Layzell <nika@thelayzells.com>"
4037 criteria = "safe-to-deploy"
4038 version = "1.0.18"
4039 notes = """
4040 `quote` is a utility crate used by proc-macros to generate TokenStreams
4041 conveniently from source code. The bulk of the logic is some complex
4042 interlocking `macro_rules!` macros which are used to parse and build the
4043 `TokenStream` within the proc-macro.
4045 This crate contains no unsafe code, and the internal logic, while difficult to
4046 read, is generally straightforward. I have audited the the quote macros, ident
4047 formatter, and runtime logic.
4050 [[audits.quote]]
4051 who = "Mike Hommey <mh+mozilla@glandium.org>"
4052 criteria = "safe-to-deploy"
4053 delta = "1.0.18 -> 1.0.21"
4055 [[audits.quote]]
4056 who = "Mike Hommey <mh+mozilla@glandium.org>"
4057 criteria = "safe-to-deploy"
4058 delta = "1.0.21 -> 1.0.23"
4060 [[audits.radium]]
4061 who = "Nika Layzell <nika@thelayzells.com>"
4062 criteria = "safe-to-deploy"
4063 version = "0.5.3"
4064 notes = """
4065 I am no longer the primary maintainer of `radium`, however I have audited the
4066 code to ensure it is still correct. The implementation contains no `unsafe`
4067 logic, and will not abstract away `Sync` trait bounds.
4069 The core logic is very simple, and acts as an abstraction trait for `Cell<T>`
4070 and `AtomicT`.
4073 [[audits.rand_core]]
4074 who = "Mike Hommey <mh+mozilla@glandium.org>"
4075 criteria = "safe-to-deploy"
4076 delta = "0.6.3 -> 0.6.4"
4078 [[audits.rand_distr]]
4079 who = "Ben Dean-Kawamura <bdk@mozilla.com>"
4080 criteria = "safe-to-deploy"
4081 version = "0.4.3"
4082 notes = """
4083 Simple crate that extends `rand`.  It has little unsafe code and uses Miri to test it.
4084 As far as I can tell, it does not have any file IO or network access.
4087 [[audits.range-alloc]]
4088 who = "Bobby Holley <bobbyholley@gmail.com>"
4089 criteria = "safe-to-deploy"
4090 version = "0.1.2"
4091 notes = "Dzmitry authored this crate while he was staff at Mozilla."
4093 [[audits.range-alloc]]
4094 who = "Mike Hommey <mh+mozilla@glandium.org>"
4095 criteria = "safe-to-deploy"
4096 delta = "0.1.2 -> 0.1.3"
4098 [[audits.range-map]]
4099 who = "Gabriele Svelto <gsvelto@mozilla.com>"
4100 criteria = "safe-to-deploy"
4101 version = "0.2.0"
4103 [[audits.raw-window-handle]]
4104 who = "Jim Blandy <jimb@red-bean.com>"
4105 criteria = "safe-to-deploy"
4106 version = "0.5.0"
4107 notes = "I looked through all the sources of the v0.5.0 crate."
4109 [[audits.raw-window-handle]]
4110 who = "Mike Hommey <mh+mozilla@glandium.org>"
4111 criteria = "safe-to-deploy"
4112 delta = "0.5.0 -> 0.5.2"
4114 [[audits.raw-window-handle]]
4115 who = "Nicolas Silva <nical@fastmail.com>"
4116 criteria = "safe-to-deploy"
4117 delta = "0.5.2 -> 0.6.0"
4119 [[audits.rayon]]
4120 who = "Josh Stone <jistone@redhat.com>"
4121 criteria = "safe-to-deploy"
4122 version = "1.5.3"
4123 notes = "All code written or reviewed by Josh Stone or Niko Matsakis."
4125 [[audits.rayon]]
4126 who = "Mike Hommey <mh+mozilla@glandium.org>"
4127 criteria = "safe-to-deploy"
4128 delta = "1.5.3 -> 1.6.1"
4130 [[audits.rayon-core]]
4131 who = "Josh Stone <jistone@redhat.com>"
4132 criteria = "safe-to-deploy"
4133 version = "1.9.3"
4134 notes = "All code written or reviewed by Josh Stone or Niko Matsakis."
4136 [[audits.rayon-core]]
4137 who = "Mike Hommey <mh+mozilla@glandium.org>"
4138 criteria = "safe-to-deploy"
4139 delta = "1.9.3 -> 1.10.1"
4141 [[audits.rayon-core]]
4142 who = "Mike Hommey <mh+mozilla@glandium.org>"
4143 criteria = "safe-to-deploy"
4144 delta = "1.10.1 -> 1.10.2"
4146 [[audits.redox_syscall]]
4147 who = "Mike Hommey <mh+mozilla@glandium.org>"
4148 criteria = "safe-to-deploy"
4149 delta = "0.2.13 -> 0.2.16"
4151 [[audits.regex]]
4152 who = "Mike Hommey <mh+mozilla@glandium.org>"
4153 criteria = "safe-to-deploy"
4154 delta = "1.5.6 -> 1.6.0"
4156 [[audits.regex]]
4157 who = "Mike Hommey <mh+mozilla@glandium.org>"
4158 criteria = "safe-to-deploy"
4159 delta = "1.6.0 -> 1.7.0"
4161 [[audits.regex]]
4162 who = "Mike Hommey <mh+mozilla@glandium.org>"
4163 criteria = "safe-to-deploy"
4164 delta = "1.7.0 -> 1.7.1"
4166 [[audits.regex-syntax]]
4167 who = "Mike Hommey <mh+mozilla@glandium.org>"
4168 criteria = "safe-to-deploy"
4169 delta = "0.6.26 -> 0.6.27"
4171 [[audits.regex-syntax]]
4172 who = "Mike Hommey <mh+mozilla@glandium.org>"
4173 criteria = "safe-to-deploy"
4174 delta = "0.6.27 -> 0.6.28"
4176 [[audits.rkv]]
4177 who = "Chris H-C <chutten@mozilla.com>"
4178 criteria = "safe-to-deploy"
4179 version = "0.18.2"
4180 notes = "Maintained by Jan-Erik and :krosylight."
4182 [[audits.rkv]]
4183 who = "Chris H-C <chutten@mozilla.com>"
4184 criteria = "safe-to-deploy"
4185 version = "0.18.4"
4187 [[audits.rmp]]
4188 who = "Ben Dean-Kawamura <bdk@mozilla.com>"
4189 criteria = "safe-to-deploy"
4190 version = "0.8.14"
4191 notes = """
4192 Very popular crate. 1 instance of unsafe code, which is used to adjust a slice to work around
4193 lifetime issues. No network or file access.
4196 [[audits.rmp-serde]]
4197 who = "Ben Dean-Kawamura <bdk@mozilla.com>"
4198 criteria = "safe-to-deploy"
4199 version = "1.3.0"
4200 notes = "Very popular crate. No unsafe code, network or file access."
4202 [[audits.ron]]
4203 who = "Mike Hommey <mh+mozilla@glandium.org>"
4204 criteria = "safe-to-deploy"
4205 delta = "0.7.0 -> 0.7.1"
4207 [[audits.ron]]
4208 who = "Jim Blandy <jimb@red-bean.com>"
4209 criteria = "safe-to-deploy"
4210 delta = "0.7.1 -> 0.8.0"
4212 [[audits.ron]]
4213 who = "Mike Hommey <mh+mozilla@glandium.org>"
4214 criteria = "safe-to-deploy"
4215 delta = "0.8.0 -> 0.8.1"
4217 [[audits.rure]]
4218 who = "Nika Layzell <nika@thelayzells.com>"
4219 criteria = "safe-to-deploy"
4220 version = "0.2.2"
4221 notes = """
4222 This is a fairly straightforward FFI wrapper crate for `regex`, maintained by
4223 the `regex` developers in the same repository.
4225 This crate is explicitly designed for FFI use, and should not be used directly
4226 by Rust code. The exported `extern \"C\"` functions are not marked as `unsafe`,
4227 meaning that it is technically incorrect to use them from within Rust code,
4228 however they are reasonable to use from C code.
4230 The unsafe code in this crate heavily depends on the C caller maintaining
4231 invariants, however these invariants are clearly documented in the `rure.h`
4232 file, bundled with the crate.
4234 I have checked the signatures of each function both in C++ and in the Rust to
4235 ensure they match.  In some places, the c `rure.h` header file is missing a
4236 `const` qualifier which could be present given the Rust code, however this will
4237 have no impact on ABI, and is fairly normal for FFI crates.
4239 Panics are handled in all Rust FFI methods, meaning that projects which do not
4240 disable unwinding will still consistently abort (using `libc::abort()`) if a
4241 panic occurs in the Rust code.
4244 [[audits.rusqlite]]
4245 who = "Mike Hommey <mh+mozilla@glandium.org>"
4246 criteria = "safe-to-deploy"
4247 delta = "0.27.0 -> 0.28.0"
4249 [[audits.rusqlite]]
4250 who = "Ben Dean-Kawamura <bdk@mozilla.com>"
4251 criteria = "safe-to-deploy"
4252 delta = "0.28.0 -> 0.29.0"
4254 [[audits.rusqlite]]
4255 who = "Mark Hammond <mhammond@mozilla.com>"
4256 criteria = "safe-to-deploy"
4257 delta = "0.29.0 -> 0.30.0"
4259 [[audits.rusqlite]]
4260 who = "Mark Hammond <mhammond@mozilla.com>"
4261 criteria = "safe-to-deploy"
4262 delta = "0.30.0 -> 0.31.0"
4263 notes = "Mostly build and dependency related changes, and bump to sqlite version"
4265 [[audits.rusqlite]]
4266 who = "Erich Gubler <erichdongubler@gmail.com>"
4267 criteria = "safe-to-deploy"
4268 delta = "0.31.0 -> 0.33.0"
4270 [[audits.rust_cascade]]
4271 who = "Mike Hommey <mh+mozilla@glandium.org>"
4272 criteria = "safe-to-deploy"
4273 delta = "1.4.0 -> 1.5.0"
4275 [[audits.rust_decimal]]
4276 who = "Mike Hommey <mh+mozilla@glandium.org>"
4277 criteria = "safe-to-deploy"
4278 delta = "1.24.0 -> 1.25.0"
4280 [[audits.rust_decimal]]
4281 who = "Mike Hommey <mh+mozilla@glandium.org>"
4282 criteria = "safe-to-deploy"
4283 delta = "1.25.0 -> 1.26.1"
4285 [[audits.rust_decimal]]
4286 who = "Mike Hommey <mh+mozilla@glandium.org>"
4287 criteria = "safe-to-deploy"
4288 delta = "1.26.1 -> 1.27.0"
4290 [[audits.rust_decimal]]
4291 who = "Mike Hommey <mh+mozilla@glandium.org>"
4292 criteria = "safe-to-deploy"
4293 delta = "1.27.0 -> 1.28.1"
4295 [[audits.rustc-hash]]
4296 who = "Bobby Holley <bobbyholley@gmail.com>"
4297 criteria = "safe-to-deploy"
4298 version = "1.1.0"
4299 notes = "Straightforward crate with no unsafe code, does what it says on the tin."
4301 [[audits.rustc_version]]
4302 who = "Nika Layzell <nika@thelayzells.com>"
4303 criteria = "safe-to-run"
4304 version = "0.4.0"
4305 notes = """
4306 Straightforward crate which runs `$RUSTC -vV` and parses the output into a
4307 machine-interpretable form for build scripts.
4310 [[audits.rustversion]]
4311 who = "Bobby Holley <bobbyholley@gmail.com>"
4312 criteria = "safe-to-deploy"
4313 version = "1.0.9"
4314 notes = """
4315 This crate has a build-time component and procedural macro logic, which I looked
4316 at enough to convince myself it wasn't going to do anything dramatically wrong.
4317 I don't think logic bugs in the version parsing etc can realistically introduce
4318 a security vulnerability.
4321 [[audits.rustversion]]
4322 who = "Mike Hommey <mh+mozilla@glandium.org>"
4323 criteria = "safe-to-run"
4324 delta = "1.0.9 -> 1.0.11"
4326 [[audits.ryu]]
4327 who = "Mike Hommey <mh+mozilla@glandium.org>"
4328 criteria = "safe-to-deploy"
4329 delta = "1.0.10 -> 1.0.11"
4331 [[audits.ryu]]
4332 who = "Mike Hommey <mh+mozilla@glandium.org>"
4333 criteria = "safe-to-deploy"
4334 delta = "1.0.11 -> 1.0.12"
4336 [[audits.safemem]]
4337 who = "Bobby Holley <bobbyholley@gmail.com>"
4338 criteria = "safe-to-run"
4339 version = "0.3.3"
4340 notes = "I didn't review the allocation code carefully but it's not malicious."
4342 [[audits.scoped-tls]]
4343 who = "Mike Hommey <mh+mozilla@glandium.org>"
4344 criteria = "safe-to-run"
4345 delta = "1.0.0 -> 1.0.1"
4347 [[audits.scroll]]
4348 who = "Jan-Erik Rediger <jrediger@mozilla.com>"
4349 criteria = "safe-to-deploy"
4350 delta = "0.10.2 -> 0.11.0"
4351 notes = "Small changes to exposed traits, that look reasonable and have additional buffer boundary checks. No unsafe code touched."
4353 [[audits.scroll_derive]]
4354 who = "Jan-Erik Rediger <jrediger@mozilla.com>"
4355 criteria = "safe-to-deploy"
4356 delta = "0.10.5 -> 0.11.0"
4357 notes = "No code changes. Tagged together with its parent crate scroll."
4359 [[audits.scroll_derive]]
4360 who = "Mike Hommey <mh+mozilla@glandium.org>"
4361 criteria = "safe-to-deploy"
4362 delta = "0.11.0 -> 0.11.1"
4364 [[audits.selectors]]
4365 who = "Emilio Cobos Álvarez <emilio@crisal.io>"
4366 criteria = "safe-to-deploy"
4367 version = "0.22.0"
4368 notes = """
4369 This crate is basically developed in-tree. Mozilla employees have either
4370 reviewed or written virtually all of the code.
4373 [[audits.selectors]]
4374 who = "Emilio Cobos Álvarez <emilio@crisal.io>"
4375 criteria = "safe-to-deploy"
4376 delta = "0.22.0 -> 0.25.0"
4377 notes = "First party Mozilla code."
4379 [[audits.selectors]]
4380 who = "Emilio Cobos Álvarez <emilio@crisal.io>"
4381 criteria = "safe-to-deploy"
4382 delta = "0.25.0 -> 0.26.0"
4383 notes = "First-party code."
4385 [[audits.semver]]
4386 who = "Mike Hommey <mh+mozilla@glandium.org>"
4387 criteria = "safe-to-deploy"
4388 delta = "1.0.9 -> 1.0.10"
4390 [[audits.semver]]
4391 who = "Mike Hommey <mh+mozilla@glandium.org>"
4392 criteria = "safe-to-deploy"
4393 delta = "1.0.10 -> 1.0.13"
4395 [[audits.semver]]
4396 who = "Mike Hommey <mh+mozilla@glandium.org>"
4397 criteria = "safe-to-deploy"
4398 delta = "1.0.13 -> 1.0.16"
4400 [[audits.semver]]
4401 who = "Bobby Holley <bobbyholley@gmail.com>"
4402 criteria = "safe-to-deploy"
4403 delta = "1.0.17 -> 1.0.16"
4405 [[audits.serde]]
4406 who = "Mike Hommey <mh+mozilla@glandium.org>"
4407 criteria = "safe-to-deploy"
4408 delta = "1.0.137 -> 1.0.143"
4410 [[audits.serde]]
4411 who = "Mike Hommey <mh+mozilla@glandium.org>"
4412 criteria = "safe-to-deploy"
4413 delta = "1.0.143 -> 1.0.144"
4415 [[audits.serde]]
4416 who = "Mike Hommey <mh+mozilla@glandium.org>"
4417 criteria = "safe-to-deploy"
4418 delta = "1.0.144 -> 1.0.151"
4420 [[audits.serde]]
4421 who = "Mike Hommey <mh+mozilla@glandium.org>"
4422 criteria = "safe-to-deploy"
4423 delta = "1.0.151 -> 1.0.152"
4425 [[audits.serde]]
4426 who = "Erich Gubler <erichdongubler@gmail.com>"
4427 criteria = "safe-to-deploy"
4428 delta = "1.0.198 -> 1.0.201"
4430 [[audits.serde_bytes]]
4431 who = "Mike Hommey <mh+mozilla@glandium.org>"
4432 criteria = "safe-to-deploy"
4433 delta = "0.11.6 -> 0.11.7"
4435 [[audits.serde_bytes]]
4436 who = "Mike Hommey <mh+mozilla@glandium.org>"
4437 criteria = "safe-to-deploy"
4438 delta = "0.11.7 -> 0.11.8"
4440 [[audits.serde_bytes]]
4441 who = "Mike Hommey <mh+mozilla@glandium.org>"
4442 criteria = "safe-to-deploy"
4443 delta = "0.11.8 -> 0.11.9"
4445 [[audits.serde_cbor]]
4446 who = "R. Martinho Fernandes <bugs@rmf.io>"
4447 criteria = "safe-to-deploy"
4448 version = "0.11.1"
4450 [[audits.serde_cbor]]
4451 who = "John M. Schanck <jschanck@mozilla.com>"
4452 criteria = "safe-to-deploy"
4453 delta = "0.11.1 -> 0.11.2"
4455 [[audits.serde_derive]]
4456 who = "Mike Hommey <mh+mozilla@glandium.org>"
4457 criteria = "safe-to-deploy"
4458 delta = "1.0.137 -> 1.0.143"
4460 [[audits.serde_derive]]
4461 who = "Mike Hommey <mh+mozilla@glandium.org>"
4462 criteria = "safe-to-deploy"
4463 delta = "1.0.143 -> 1.0.144"
4465 [[audits.serde_derive]]
4466 who = "Mike Hommey <mh+mozilla@glandium.org>"
4467 criteria = "safe-to-deploy"
4468 delta = "1.0.144 -> 1.0.151"
4470 [[audits.serde_derive]]
4471 who = "Mike Hommey <mh+mozilla@glandium.org>"
4472 criteria = "safe-to-deploy"
4473 delta = "1.0.151 -> 1.0.152"
4475 [[audits.serde_derive]]
4476 who = "Erich Gubler <erichdongubler@gmail.com>"
4477 criteria = "safe-to-deploy"
4478 delta = "1.0.198 -> 1.0.201"
4480 [[audits.serde_json]]
4481 who = "Mike Hommey <mh+mozilla@glandium.org>"
4482 criteria = "safe-to-deploy"
4483 delta = "1.0.81 -> 1.0.83"
4485 [[audits.serde_json]]
4486 who = "Mike Hommey <mh+mozilla@glandium.org>"
4487 criteria = "safe-to-deploy"
4488 delta = "1.0.83 -> 1.0.85"
4490 [[audits.serde_json]]
4491 who = "Mike Hommey <mh+mozilla@glandium.org>"
4492 criteria = "safe-to-deploy"
4493 delta = "1.0.85 -> 1.0.91"
4495 [[audits.serde_json]]
4496 who = "Mike Hommey <mh+mozilla@glandium.org>"
4497 criteria = "safe-to-deploy"
4498 delta = "1.0.91 -> 1.0.93"
4500 [[audits.serde_path_to_error]]
4501 who = "Ben Dean-Kawamura <bdk@mozilla.com>"
4502 criteria = "safe-to-deploy"
4503 version = "0.1.11"
4505 [[audits.serde_repr]]
4506 who = "Mike Hommey <mh+mozilla@glandium.org>"
4507 criteria = "safe-to-run"
4508 delta = "0.1.8 -> 0.1.9"
4510 [[audits.serde_repr]]
4511 who = "Mike Hommey <mh+mozilla@glandium.org>"
4512 criteria = "safe-to-run"
4513 delta = "0.1.9 -> 0.1.10"
4515 [[audits.serde_with]]
4516 who = "Mike Hommey <mh+mozilla@glandium.org>"
4517 criteria = "safe-to-deploy"
4518 delta = "1.14.0 -> 3.0.0"
4520 [[audits.serde_with_macros]]
4521 who = "Mike Hommey <mh+mozilla@glandium.org>"
4522 criteria = "safe-to-deploy"
4523 delta = "1.5.2 -> 3.0.0"
4525 [[audits.serde_yaml]]
4526 who = "Mike Hommey <mh+mozilla@glandium.org>"
4527 criteria = "safe-to-run"
4528 delta = "0.8.24 -> 0.8.26"
4530 [[audits.servo_arc]]
4531 who = "Emilio Cobos Álvarez <emilio@crisal.io>"
4532 criteria = "safe-to-deploy"
4533 version = "0.1.1"
4534 notes = "Developed in-tree, effectively."
4536 [[audits.servo_arc]]
4537 who = "Emilio Cobos Álvarez <emilio@crisal.io>"
4538 criteria = "safe-to-deploy"
4539 delta = "0.1.1 -> 0.3.0"
4540 notes = "First-party Mozilla code."
4542 [[audits.servo_arc]]
4543 who = "Emilio Cobos Álvarez <emilio@crisal.io>"
4544 criteria = "safe-to-deploy"
4545 delta = "0.3.0 -> 0.4.0"
4546 notes = "First-party code."
4548 [[audits.sfv]]
4549 who = "Mike Hommey <mh+mozilla@glandium.org>"
4550 criteria = "safe-to-deploy"
4551 delta = "0.9.2 -> 0.9.3"
4553 [[audits.sfv]]
4554 who = "Erich Gubler <erichdongubler@gmail.com>"
4555 criteria = "safe-to-deploy"
4556 delta = "0.9.3 -> 0.9.4"
4557 notes = "Only an update of `indexmap` 1 → 2."
4559 [[audits.sha1]]
4560 who = "Dana Keeler <dkeeler@mozilla.com>"
4561 criteria = "safe-to-deploy"
4562 version = "0.10.5"
4564 [[audits.sha1]]
4565 who = "Mike Hommey <mh+mozilla@glandium.org>"
4566 criteria = "safe-to-run"
4567 delta = "0.10.0 -> 0.10.5"
4569 [[audits.sha2]]
4570 who = "Mike Hommey <mh+mozilla@glandium.org>"
4571 criteria = "safe-to-deploy"
4572 delta = "0.10.2 -> 0.10.6"
4574 [[audits.sha2]]
4575 who = "Jeff Muizelaar <jmuizelaar@mozilla.com>"
4576 criteria = "safe-to-deploy"
4577 delta = "0.10.6 -> 0.10.8"
4578 notes = """
4579 The bulk of this is https://github.com/RustCrypto/hashes/pull/490 which adds aarch64 support along with another PR adding longson.
4580 I didn't check the implementation thoroughly but there wasn't anything obviously nefarious. 0.10.8 has been out for more than a year
4581 which suggests no one else has found anything either.
4584 [[audits.sha3]]
4585 who = "Simon Friedberger <simon@mozilla.com>"
4586 criteria = "safe-to-deploy"
4587 delta = "0.10.6 -> 0.10.7"
4589 [[audits.shlex]]
4590 who = "Max Inden <mail@max-inden.de>"
4591 criteria = "safe-to-deploy"
4592 delta = "1.1.0 -> 1.3.0"
4594 [[audits.slab]]
4595 who = "Mike Hommey <mh+mozilla@glandium.org>"
4596 criteria = "safe-to-deploy"
4597 delta = "0.4.6 -> 0.4.7"
4599 [[audits.slab]]
4600 who = "Mike Hommey <mh+mozilla@glandium.org>"
4601 criteria = "safe-to-deploy"
4602 delta = "0.4.7 -> 0.4.8"
4604 [[audits.smallbitvec]]
4605 who = "Bobby Holley <bobbyholley@gmail.com>"
4606 criteria = "safe-to-deploy"
4607 version = "2.5.0"
4608 notes = "All code written or reviewed by Mozilla staff."
4610 [[audits.smallbitvec]]
4611 who = "Bobby Holley <bobbyholley@gmail.com>"
4612 criteria = "safe-to-deploy"
4613 delta = "2.5.0 -> 2.5.1"
4615 [[audits.smallvec]]
4616 who = "Mike Hommey <mh+mozilla@glandium.org>"
4617 criteria = "safe-to-deploy"
4618 delta = "1.8.0 -> 1.9.0"
4620 [[audits.smallvec]]
4621 who = "Mike Hommey <mh+mozilla@glandium.org>"
4622 criteria = "safe-to-deploy"
4623 delta = "1.9.0 -> 1.10.0"
4625 [[audits.smart-default]]
4626 who = "Gabriele Svelto <gsvelto@mozilla.com>"
4627 criteria = "safe-to-deploy"
4628 version = "0.6.0"
4630 [[audits.smart-default]]
4631 who = "Mike Hommey <mh+mozilla@glandium.org>"
4632 criteria = "safe-to-deploy"
4633 delta = "0.6.0 -> 0.7.1"
4635 [[audits.socket2]]
4636 who = "Mike Hommey <mh+mozilla@glandium.org>"
4637 criteria = "safe-to-deploy"
4638 delta = "0.4.4 -> 0.4.7"
4640 [[audits.socket2]]
4641 who = "Kershaw Chang <kershaw@mozilla.com>"
4642 criteria = "safe-to-deploy"
4643 delta = "0.5.5 -> 0.5.7"
4645 [[audits.spirv]]
4646 who = "Nicolas Silva <nical@fastmail.com>"
4647 criteria = "safe-to-deploy"
4648 delta = "0.2.0+1.5.4 -> 0.3.0+sdk-1.3.268.0"
4650 [[audits.strck]]
4651 who = "Makoto Kato <m_kato@ga2.so-net.ne.jp>"
4652 criteria = "safe-to-deploy"
4653 version = "0.1.2"
4654 notes = "This crate uses unsafe lock to keep invariant. I auditted code. Also, this doesn't have file access and network access."
4656 [[audits.strck_ident]]
4657 who = "Makoto Kato <m_kato@ga2.so-net.ne.jp>"
4658 criteria = "safe-to-deploy"
4659 version = "0.1.2"
4660 notes = "This crate doesn't use unsafe block, network access and filesystem access."
4662 [[audits.strsim]]
4663 who = "Ben Dean-Kawamura <bdk@mozilla.com>"
4664 criteria = "safe-to-deploy"
4665 delta = "0.10.0 -> 0.11.1"
4667 [[audits.strum]]
4668 who = "Teodor Tanasoaia <ttanasoaia@mozilla.com>"
4669 criteria = "safe-to-deploy"
4670 delta = "0.25.0 -> 0.26.3"
4672 [[audits.strum_macros]]
4673 who = "Teodor Tanasoaia <ttanasoaia@mozilla.com>"
4674 criteria = "safe-to-deploy"
4675 delta = "0.25.3 -> 0.26.4"
4677 [[audits.subtle]]
4678 who = "Simon Friedberger <simon@mozilla.com>"
4679 criteria = "safe-to-deploy"
4680 version = "2.5.0"
4681 notes = "The goal is to provide some constant-time correctness for cryptographic implementations. The approach is reasonable, it is known to be insufficient but this is pointed out in the documentation."
4683 [[audits.svg_fmt]]
4684 who = "Bobby Holley <bobbyholley@gmail.com>"
4685 criteria = "safe-to-deploy"
4686 version = "0.4.1"
4687 notes = "Simple string processing with no unsafe code or ambient capability usage."
4689 [[audits.syn]]
4690 who = "Mike Hommey <mh+mozilla@glandium.org>"
4691 criteria = "safe-to-deploy"
4692 delta = "1.0.96 -> 1.0.99"
4694 [[audits.syn]]
4695 who = "Mike Hommey <mh+mozilla@glandium.org>"
4696 criteria = "safe-to-deploy"
4697 delta = "1.0.99 -> 1.0.107"
4699 [[audits.synstructure]]
4700 who = "Nika Layzell <nika@thelayzells.com>"
4701 criteria = "safe-to-deploy"
4702 version = "0.12.6"
4703 notes = """
4704 I am the primary author of the `synstructure` crate, and its current
4705 maintainer. The one use of `unsafe` is unnecessary, but documented and
4706 harmless. It will be removed in the next version.
4709 [[audits.synstructure]]
4710 who = "Mike Hommey <mh+mozilla@glandium.org>"
4711 criteria = "safe-to-deploy"
4712 delta = "0.12.6 -> 0.13.0"
4714 [[audits.synstructure]]
4715 who = "Mike Hommey <mh+mozilla@glandium.org>"
4716 criteria = "safe-to-deploy"
4717 delta = "0.13.0 -> 0.13.1"
4719 [[audits.sys-locale]]
4720 who = "Alex Franchuk <afranchuk@mozilla.com>"
4721 criteria = "safe-to-deploy"
4722 version = "0.3.1"
4723 notes = "Succinct and easily-verified unsafe code."
4725 [[audits.tempfile]]
4726 who = "Mike Hommey <mh+mozilla@glandium.org>"
4727 criteria = "safe-to-deploy"
4728 delta = "3.6.0 -> 3.8.0"
4730 [[audits.tempfile]]
4731 who = "Mike Hommey <mh+mozilla@glandium.org>"
4732 criteria = "safe-to-deploy"
4733 delta = "3.8.0 -> 3.9.0"
4735 [[audits.tempfile]]
4736 who = "Mike Hommey <mh+mozilla@glandium.org>"
4737 criteria = "safe-to-deploy"
4738 delta = "3.9.0 -> 3.10.1"
4740 [[audits.termcolor]]
4741 who = "Mike Hommey <mh+mozilla@glandium.org>"
4742 criteria = "safe-to-deploy"
4743 delta = "1.1.3 -> 1.2.0"
4745 [[audits.textwrap]]
4746 who = "Mike Hommey <mh+mozilla@glandium.org>"
4747 criteria = "safe-to-deploy"
4748 delta = "0.15.0 -> 0.15.2"
4750 [[audits.textwrap]]
4751 who = "Mike Hommey <mh+mozilla@glandium.org>"
4752 criteria = "safe-to-deploy"
4753 delta = "0.15.2 -> 0.16.0"
4755 [[audits.textwrap]]
4756 who = "Jan-Erik Rediger <jrediger@mozilla.com>"
4757 criteria = "safe-to-deploy"
4758 delta = "0.16.0 -> 0.16.1"
4760 [[audits.thin-vec]]
4761 who = "Aria Beingessner <a.beingessner@gmail.com>"
4762 criteria = "safe-to-deploy"
4763 version = "0.2.5"
4764 notes = "I own this crate, and most of its versions were codeveloped and reviewed by Nika Layzell. This version was not explicitly reviewed by her, but it was specifically a release that made the code pass miri and was reviewed by me. Firefox uses it in the gecko-ffi configuration which is less thoroughly tested and more dangerous but we're reasonably confident in it. The real danger is from C++ code failing to use it correctly in FFI but that's just how FFI is."
4766 [[audits.thin-vec]]
4767 who = "Mike Hommey <mh+mozilla@glandium.org>"
4768 criteria = "safe-to-deploy"
4769 delta = "0.2.5 -> 0.2.7"
4771 [[audits.thin-vec]]
4772 who = "Mike Hommey <mh+mozilla@glandium.org>"
4773 criteria = "safe-to-deploy"
4774 delta = "0.2.7 -> 0.2.12"
4776 [[audits.thiserror]]
4777 who = "Mike Hommey <mh+mozilla@glandium.org>"
4778 criteria = "safe-to-deploy"
4779 delta = "1.0.31 -> 1.0.32"
4781 [[audits.thiserror]]
4782 who = "Mike Hommey <mh+mozilla@glandium.org>"
4783 criteria = "safe-to-deploy"
4784 delta = "1.0.32 -> 1.0.38"
4786 [[audits.thiserror-impl]]
4787 who = "Mike Hommey <mh+mozilla@glandium.org>"
4788 criteria = "safe-to-deploy"
4789 delta = "1.0.31 -> 1.0.32"
4791 [[audits.thiserror-impl]]
4792 who = "Mike Hommey <mh+mozilla@glandium.org>"
4793 criteria = "safe-to-deploy"
4794 delta = "1.0.32 -> 1.0.38"
4796 [[audits.threadbound]]
4797 who = "Mike Hommey <mh+mozilla@glandium.org>"
4798 criteria = "safe-to-deploy"
4799 delta = "0.1.3 -> 0.1.4"
4801 [[audits.threadbound]]
4802 who = "Mike Hommey <mh+mozilla@glandium.org>"
4803 criteria = "safe-to-deploy"
4804 delta = "0.1.4 -> 0.1.5"
4806 [[audits.time]]
4807 who = "Mike Hommey <mh+mozilla@glandium.org>"
4808 criteria = "safe-to-deploy"
4809 delta = "0.1.44 -> 0.1.45"
4811 [[audits.time]]
4812 who = "Kershaw Chang <kershaw@mozilla.com>"
4813 criteria = "safe-to-deploy"
4814 delta = "0.1.45 -> 0.3.17"
4816 [[audits.time]]
4817 who = "Mike Hommey <mh+mozilla@glandium.org>"
4818 criteria = "safe-to-run"
4819 delta = "0.3.9 -> 0.3.17"
4821 [[audits.time]]
4822 who = "Kershaw Chang <kershaw@mozilla.com>"
4823 criteria = "safe-to-deploy"
4824 delta = "0.3.17 -> 0.3.23"
4826 [[audits.time]]
4827 who = "Alex Franchuk <afranchuk@mozilla.com>"
4828 criteria = "safe-to-deploy"
4829 delta = "0.3.23 -> 0.3.36"
4830 notes = """
4831 There's a bit of new unsafe code that is self-imposed because they now assert
4832 that ordinals are non-zero. All unsafe code was checked to ensure that the
4833 invariants claimed were true.
4836 [[audits.time-core]]
4837 who = "Kershaw Chang <kershaw@mozilla.com>"
4838 criteria = "safe-to-deploy"
4839 version = "0.1.0"
4841 [[audits.time-core]]
4842 who = "Mike Hommey <mh+mozilla@glandium.org>"
4843 criteria = "safe-to-run"
4844 version = "0.1.0"
4846 [[audits.time-core]]
4847 who = "Kershaw Chang <kershaw@mozilla.com>"
4848 criteria = "safe-to-deploy"
4849 delta = "0.1.0 -> 0.1.1"
4851 [[audits.time-core]]
4852 who = "Alex Franchuk <afranchuk@mozilla.com>"
4853 criteria = "safe-to-deploy"
4854 delta = "0.1.1 -> 0.1.2"
4856 [[audits.time-macros]]
4857 who = "Kershaw Chang <kershaw@mozilla.com>"
4858 criteria = "safe-to-deploy"
4859 version = "0.2.6"
4861 [[audits.time-macros]]
4862 who = "Mike Hommey <mh+mozilla@glandium.org>"
4863 criteria = "safe-to-run"
4864 delta = "0.2.4 -> 0.2.6"
4866 [[audits.time-macros]]
4867 who = "Kershaw Chang <kershaw@mozilla.com>"
4868 criteria = "safe-to-deploy"
4869 delta = "0.2.6 -> 0.2.10"
4871 [[audits.time-macros]]
4872 who = "Alex Franchuk <afranchuk@mozilla.com>"
4873 criteria = "safe-to-deploy"
4874 delta = "0.2.10 -> 0.2.18"
4876 [[audits.tinystr]]
4877 who = "Zibi Braniecki <zibi@unicode.org>"
4878 criteria = "safe-to-deploy"
4879 version = "0.3.4"
4881 [[audits.tinystr]]
4882 who = "Zibi Braniecki <zibi@unicode.org>"
4883 criteria = "safe-to-deploy"
4884 version = "0.6.0"
4886 [[audits.tinystr]]
4887 who = "Makoto Kato <m_kato@ga2.so-net.ne.jp>"
4888 criteria = "safe-to-deploy"
4889 version = "0.7.0"
4890 notes = "One of original auther was Zibi Braniecki who worked at Mozilla and maintained by ICU4X developers (Google and Mozilla). I've vetted the one instance of unsafe code."
4892 [[audits.tinystr]]
4893 who = "Mike Hommey <mh+mozilla@glandium.org>"
4894 criteria = "safe-to-deploy"
4895 delta = "0.7.0 -> 0.7.1"
4897 [[audits.tinystr]]
4898 who = "Makoto Kato <m_kato@ga2.so-net.ne.jp>"
4899 criteria = "safe-to-deploy"
4900 delta = "0.7.1 -> 0.7.4"
4902 [[audits.tinystr]]
4903 who = "Makoto Kato <m_kato@ga2.so-net.ne.jp>"
4904 criteria = "safe-to-deploy"
4905 delta = "0.7.4 -> 0.7.6"
4907 [[audits.to_shmem]]
4908 who = "Emilio Cobos Álvarez <emilio@crisal.io>"
4909 criteria = "safe-to-deploy"
4910 version = "0.1.0"
4911 notes = "First-party mozilla code."
4913 [[audits.to_shmem_derive]]
4914 who = "Emilio Cobos Álvarez <emilio@crisal.io>"
4915 criteria = "safe-to-deploy"
4916 version = "0.1.0"
4917 notes = "It's all first-party Mozilla code recently published to crates.io"
4919 [[audits.tokio-macros]]
4920 who = "Mike Hommey <mh+mozilla@glandium.org>"
4921 criteria = "safe-to-run"
4922 delta = "1.8.0 -> 1.8.2"
4924 [[audits.tokio-stream]]
4925 who = "Mike Hommey <mh+mozilla@glandium.org>"
4926 criteria = "safe-to-run"
4927 delta = "0.1.9 -> 0.1.11"
4929 [[audits.tokio-stream]]
4930 who = "Mike Hommey <mh+mozilla@glandium.org>"
4931 criteria = "safe-to-run"
4932 delta = "0.1.11 -> 0.1.12"
4934 [[audits.toml]]
4935 who = "Bobby Holley <bobbyholley@gmail.com>"
4936 criteria = "safe-to-deploy"
4937 delta = "0.5.7 -> 0.5.9"
4939 [[audits.toml]]
4940 who = "Mike Hommey <mh+mozilla@glandium.org>"
4941 criteria = "safe-to-deploy"
4942 delta = "0.5.9 -> 0.5.10"
4944 [[audits.toml]]
4945 who = "Mike Hommey <mh+mozilla@glandium.org>"
4946 criteria = "safe-to-deploy"
4947 delta = "0.5.10 -> 0.5.11"
4949 [[audits.topological-sort]]
4950 who = "Bobby Holley <bobbyholley@gmail.com>"
4951 criteria = "safe-to-deploy"
4952 version = "0.1.0"
4953 notes = "Simple algorithm crate with no unsafe code or capability usage."
4955 [[audits.tower-service]]
4956 who = "Mike Hommey <mh+mozilla@glandium.org>"
4957 criteria = "safe-to-run"
4958 delta = "0.3.1 -> 0.3.2"
4960 [[audits.tracing]]
4961 who = "Alex Franchuk <afranchuk@mozilla.com>"
4962 criteria = "safe-to-deploy"
4963 version = "0.1.37"
4964 notes = """
4965 There's only one unsafe impl, and its purpose is to ensure correct behavior by
4966 creating a non-Send marker type (it has nothing to do with soundness). All
4967 dependencies make sense, and no side-effectful std functions are used.
4970 [[audits.tracing]]
4971 who = "Mike Hommey <mh+mozilla@glandium.org>"
4972 criteria = "safe-to-run"
4973 delta = "0.1.35 -> 0.1.36"
4975 [[audits.tracing]]
4976 who = "Mike Hommey <mh+mozilla@glandium.org>"
4977 criteria = "safe-to-run"
4978 delta = "0.1.36 -> 0.1.37"
4980 [[audits.tracing-attributes]]
4981 who = "Alex Franchuk <afranchuk@mozilla.com>"
4982 criteria = "safe-to-deploy"
4983 version = "0.1.24"
4984 notes = "No unsafe code, macros extensively tested and produce reasonable code."
4986 [[audits.tracing-attributes]]
4987 who = "Mike Hommey <mh+mozilla@glandium.org>"
4988 criteria = "safe-to-run"
4989 delta = "0.1.21 -> 0.1.22"
4991 [[audits.tracing-attributes]]
4992 who = "Mike Hommey <mh+mozilla@glandium.org>"
4993 criteria = "safe-to-run"
4994 delta = "0.1.22 -> 0.1.23"
4996 [[audits.tracing-attributes]]
4997 who = "Mike Hommey <mh+mozilla@glandium.org>"
4998 criteria = "safe-to-run"
4999 delta = "0.1.23 -> 0.1.24"
5001 [[audits.tracing-core]]
5002 who = "Alex Franchuk <afranchuk@mozilla.com>"
5003 criteria = "safe-to-deploy"
5004 version = "0.1.30"
5005 notes = """
5006 Most unsafe code is in implementing non-std sync primitives. Unsafe impls are
5007 logically correct and justified in comments, and unsafe code is sound and
5008 justified in comments.
5011 [[audits.tracing-core]]
5012 who = "Mike Hommey <mh+mozilla@glandium.org>"
5013 criteria = "safe-to-run"
5014 delta = "0.1.27 -> 0.1.29"
5016 [[audits.tracing-core]]
5017 who = "Mike Hommey <mh+mozilla@glandium.org>"
5018 criteria = "safe-to-run"
5019 delta = "0.1.29 -> 0.1.30"
5021 [[audits.tracy-rs]]
5022 who = "Glenn Watson <git@intuitionlibrary.com>"
5023 criteria = "safe-to-deploy"
5024 version = "0.1.2"
5026 [[audits.try-lock]]
5027 who = "Mike Hommey <mh+mozilla@glandium.org>"
5028 criteria = "safe-to-run"
5029 delta = "0.2.3 -> 0.2.4"
5031 [[audits.typed-arena-nomut]]
5032 who = "Lee Salzman <lsalzman@gmail.com>"
5033 criteria = "safe-to-deploy"
5034 version = "0.1.0"
5036 [[audits.typenum]]
5037 who = "Mike Hommey <mh+mozilla@glandium.org>"
5038 criteria = "safe-to-deploy"
5039 delta = "1.15.0 -> 1.16.0"
5041 [[audits.uluru]]
5042 who = "Emilio Cobos Álvarez <emilio@crisal.io>"
5043 criteria = "safe-to-deploy"
5044 version = "3.0.0"
5045 notes = """
5046 I've reviewed multiple patches in this crate, including the initial
5047 implementation back in the day. It has no unsafe code at all nowadays.
5050 [[audits.unic-langid]]
5051 who = "Zibi Braniecki <zibi@unicode.org>"
5052 criteria = "safe-to-deploy"
5053 version = "0.9.0"
5055 [[audits.unic-langid]]
5056 who = "Mike Hommey <mh+mozilla@glandium.org>"
5057 criteria = "safe-to-deploy"
5058 delta = "0.9.0 -> 0.9.1"
5060 [[audits.unic-langid]]
5061 who = "Eemeli Aro <eemeli@mozilla.com>"
5062 criteria = "safe-to-deploy"
5063 delta = "0.9.1 -> 0.9.5"
5065 [[audits.unic-langid-impl]]
5066 who = "Zibi Braniecki <zibi@unicode.org>"
5067 criteria = "safe-to-deploy"
5068 version = "0.9.0"
5070 [[audits.unic-langid-impl]]
5071 who = "Makoto Kato <m_kato@ga2.so-net.ne.jp>"
5072 criteria = "safe-to-deploy"
5073 delta = "0.9.0 -> 0.9.1"
5075 [[audits.unic-langid-impl]]
5076 who = "Eemeli Aro <eemeli@mozilla.com>"
5077 criteria = "safe-to-deploy"
5078 delta = "0.9.1 -> 0.9.5"
5080 [[audits.unic-langid-macros]]
5081 who = "Zibi Braniecki <zibi@unicode.org>"
5082 criteria = "safe-to-deploy"
5083 version = "0.9.0"
5085 [[audits.unic-langid-macros]]
5086 who = "Makoto Kato <m_kato@ga2.so-net.ne.jp>"
5087 criteria = "safe-to-deploy"
5088 delta = "0.9.0 -> 0.9.1"
5090 [[audits.unic-langid-macros-impl]]
5091 who = "Zibi Braniecki <zibi@unicode.org>"
5092 criteria = "safe-to-deploy"
5093 version = "0.9.0"
5095 [[audits.unic-langid-macros-impl]]
5096 who = "Mike Hommey <mh+mozilla@glandium.org>"
5097 criteria = "safe-to-deploy"
5098 delta = "0.9.0 -> 0.9.1"
5100 [[audits.unicode-bidi]]
5101 who = "Makoto Kato <m_kato@ga2.so-net.ne.jp>"
5102 criteria = "safe-to-deploy"
5103 delta = "0.3.8 -> 0.3.13"
5105 [[audits.unicode-bidi]]
5106 who = "Jonathan Kew <jkew@mozilla.com>"
5107 criteria = "safe-to-deploy"
5108 delta = "0.3.13 -> 0.3.14"
5109 notes = "I am the author of the bulk of the upstream changes in this version, and also checked the remaining post-0.3.13 changes."
5111 [[audits.unicode-bidi]]
5112 who = "Jonathan Kew <jfkthame@gmail.com>"
5113 criteria = "safe-to-deploy"
5114 delta = "0.3.14 -> 0.3.15"
5116 [[audits.unicode-bidi]]
5117 who = "Jonathan Kew <jfkthame@gmail.com>"
5118 criteria = "safe-to-deploy"
5119 delta = "0.3.15 -> 0.3.15@git:ca612daf1c08c53abe07327cb3e6ef6e0a760f0c"
5120 importable = false
5122 [[audits.unicode-ident]]
5123 who = "Mike Hommey <mh+mozilla@glandium.org>"
5124 criteria = "safe-to-deploy"
5125 delta = "1.0.0 -> 1.0.1"
5127 [[audits.unicode-ident]]
5128 who = "Mike Hommey <mh+mozilla@glandium.org>"
5129 criteria = "safe-to-deploy"
5130 delta = "1.0.1 -> 1.0.3"
5132 [[audits.unicode-ident]]
5133 who = "Mike Hommey <mh+mozilla@glandium.org>"
5134 criteria = "safe-to-deploy"
5135 delta = "1.0.3 -> 1.0.6"
5137 [[audits.unicode-normalization]]
5138 who = "Mike Hommey <mh+mozilla@glandium.org>"
5139 criteria = "safe-to-deploy"
5140 delta = "0.1.19 -> 0.1.20"
5141 notes = "I am the author of most of these changes upstream, and prepared the release myself, at which point I looked at the other changes since 0.1.19."
5143 [[audits.unicode-normalization]]
5144 who = "Mike Hommey <mh+mozilla@glandium.org>"
5145 criteria = "safe-to-deploy"
5146 delta = "0.1.20 -> 0.1.21"
5148 [[audits.unicode-normalization]]
5149 who = "Mike Hommey <mh+mozilla@glandium.org>"
5150 criteria = "safe-to-deploy"
5151 delta = "0.1.21 -> 0.1.22"
5153 [[audits.unicode-segmentation]]
5154 who = "Mike Hommey <mh+mozilla@glandium.org>"
5155 criteria = "safe-to-deploy"
5156 delta = "1.9.0 -> 1.10.0"
5158 [[audits.unicode-width]]
5159 who = "Mike Hommey <mh+mozilla@glandium.org>"
5160 criteria = "safe-to-deploy"
5161 delta = "0.1.9 -> 0.1.10"
5163 [[audits.unicode-xid]]
5164 who = "Mike Hommey <mh+mozilla@glandium.org>"
5165 criteria = "safe-to-deploy"
5166 delta = "0.2.3 -> 0.2.4"
5168 [[audits.unicode-xid]]
5169 who = "Teodor Tanasoaia <ttanasoaia@mozilla.com>"
5170 criteria = "safe-to-deploy"
5171 delta = "0.2.4 -> 0.2.5"
5173 [[audits.unicode-xid]]
5174 who = "Jim Blandy <jimb@red-bean.com>"
5175 criteria = "safe-to-deploy"
5176 delta = "0.2.5 -> 0.2.6"
5178 [[audits.uniffi]]
5179 who = "Travis Long <tlong@mozilla.com>"
5180 criteria = "safe-to-deploy"
5181 version = "0.19.3"
5182 notes = "Maintained by the Glean and Application Services teams"
5184 [[audits.uniffi]]
5185 who = "Jan-Erik Rediger <jrediger@mozilla.com>"
5186 criteria = "safe-to-deploy"
5187 delta = "0.19.3 -> 0.19.6"
5188 notes = "Maintained by the Glean and Application Services team."
5190 [[audits.uniffi]]
5191 who = "Perry McManis <pmcmanis@mozilla.com>"
5192 criteria = "safe-to-deploy"
5193 delta = "0.19.6 -> 0.20.0"
5195 [[audits.uniffi]]
5196 who = "Jan-Erik Rediger <jrediger@mozilla.com>"
5197 criteria = "safe-to-deploy"
5198 delta = "0.20.0 -> 0.21.0"
5199 notes = "Maintained by the Glean and Application Services team."
5201 [[audits.uniffi]]
5202 who = "Mike Hommey <mh+mozilla@glandium.org>"
5203 criteria = "safe-to-deploy"
5204 delta = "0.21.0 -> 0.21.1"
5205 notes = "No changes."
5207 [[audits.uniffi]]
5208 who = "Jan-Erik Rediger <jrediger@mozilla.com>"
5209 criteria = "safe-to-deploy"
5210 delta = "0.21.1 -> 0.23.0"
5211 notes = "Maintained by the Glean and Application Services team."
5213 [[audits.uniffi_bindgen]]
5214 who = "Travis Long <tlong@mozilla.com>"
5215 criteria = "safe-to-deploy"
5216 version = "0.19.3"
5217 notes = "Maintained by the Glean and Application Services teams."
5219 [[audits.uniffi_bindgen]]
5220 who = "Jan-Erik Rediger <jrediger@mozilla.com>"
5221 criteria = "safe-to-deploy"
5222 delta = "0.19.3 -> 0.19.6"
5223 notes = "Maintained by the Glean and Application Services team."
5225 [[audits.uniffi_bindgen]]
5226 who = "Perry McManis <pmcmanis@mozilla.com>"
5227 criteria = "safe-to-deploy"
5228 delta = "0.19.6 -> 0.20.0"
5230 [[audits.uniffi_bindgen]]
5231 who = "Jan-Erik Rediger <jrediger@mozilla.com>"
5232 criteria = "safe-to-deploy"
5233 delta = "0.20.0 -> 0.21.0"
5234 notes = "Maintained by the Glean and Application Services team."
5236 [[audits.uniffi_bindgen]]
5237 who = "Mike Hommey <mh+mozilla@glandium.org>"
5238 criteria = "safe-to-deploy"
5239 delta = "0.21.0 -> 0.21.1"
5240 notes = "I authored the changes in this version."
5242 [[audits.uniffi_bindgen]]
5243 who = "Jan-Erik Rediger <jrediger@mozilla.com>"
5244 criteria = "safe-to-deploy"
5245 delta = "0.21.1 -> 0.23.0"
5246 notes = "Maintained by the Glean and Application Services team."
5248 [[audits.uniffi_build]]
5249 who = "Travis Long <tlong@mozilla.com>"
5250 criteria = "safe-to-deploy"
5251 version = "0.19.3"
5252 notes = "Maintained by the Glean and Application Services teams."
5254 [[audits.uniffi_build]]
5255 who = "Jan-Erik Rediger <jrediger@mozilla.com>"
5256 criteria = "safe-to-deploy"
5257 delta = "0.19.3 -> 0.19.6"
5258 notes = "Maintained by the Glean and Application Services team."
5260 [[audits.uniffi_build]]
5261 who = "Perry McManis <pmcmanis@mozilla.com>"
5262 criteria = "safe-to-deploy"
5263 delta = "0.19.6 -> 0.20.0"
5265 [[audits.uniffi_build]]
5266 who = "Jan-Erik Rediger <jrediger@mozilla.com>"
5267 criteria = "safe-to-deploy"
5268 delta = "0.20.0 -> 0.21.0"
5269 notes = "Maintained by the Glean and Application Services team."
5271 [[audits.uniffi_build]]
5272 who = "Mike Hommey <mh+mozilla@glandium.org>"
5273 criteria = "safe-to-deploy"
5274 delta = "0.21.0 -> 0.21.1"
5275 notes = "No changes."
5277 [[audits.uniffi_build]]
5278 who = "Jan-Erik Rediger <jrediger@mozilla.com>"
5279 criteria = "safe-to-deploy"
5280 delta = "0.21.1 -> 0.23.0"
5281 notes = "Maintained by the Glean and Application Services team."
5283 [[audits.uniffi_checksum_derive]]
5284 who = "Mike Hommey <mh+mozilla@glandium.org>"
5285 criteria = "safe-to-deploy"
5286 version = "0.21.1"
5287 notes = "I authored this crate."
5289 [[audits.uniffi_checksum_derive]]
5290 who = "Jan-Erik Rediger <jrediger@mozilla.com>"
5291 criteria = "safe-to-deploy"
5292 delta = "0.21.1 -> 0.23.0"
5293 notes = "Maintained by the Glean and Application Services team."
5295 [[audits.uniffi_core]]
5296 who = "Jan-Erik Rediger <jrediger@mozilla.com>"
5297 criteria = "safe-to-deploy"
5298 version = "0.23.0"
5299 notes = "Maintained by the Glean and Application Services teams."
5301 [[audits.uniffi_macros]]
5302 who = "Travis Long <tlong@mozilla.com>"
5303 criteria = "safe-to-deploy"
5304 version = "0.19.3"
5305 notes = "Maintained by the Glean and Application Services teams."
5307 [[audits.uniffi_macros]]
5308 who = "Jan-Erik Rediger <jrediger@mozilla.com>"
5309 criteria = "safe-to-deploy"
5310 delta = "0.19.3 -> 0.19.6"
5311 notes = "Maintained by the Glean and Application Services team."
5313 [[audits.uniffi_macros]]
5314 who = "Perry McManis <pmcmanis@mozilla.com>"
5315 criteria = "safe-to-deploy"
5316 delta = "0.19.6 -> 0.20.0"
5318 [[audits.uniffi_macros]]
5319 who = "Jan-Erik Rediger <jrediger@mozilla.com>"
5320 criteria = "safe-to-deploy"
5321 delta = "0.20.0 -> 0.21.0"
5322 notes = "Maintained by the Glean and Application Services team."
5324 [[audits.uniffi_macros]]
5325 who = "Mike Hommey <mh+mozilla@glandium.org>"
5326 criteria = "safe-to-deploy"
5327 delta = "0.21.0 -> 0.21.1"
5328 notes = "No changes."
5330 [[audits.uniffi_macros]]
5331 who = "Jan-Erik Rediger <jrediger@mozilla.com>"
5332 criteria = "safe-to-deploy"
5333 delta = "0.21.1 -> 0.23.0"
5334 notes = "Maintained by the Glean and Application Services team."
5336 [[audits.uniffi_meta]]
5337 who = "Jan-Erik Rediger <jrediger@mozilla.com>"
5338 criteria = "safe-to-deploy"
5339 version = "0.19.6"
5340 notes = "Maintained by the Glean and Application Services team."
5342 [[audits.uniffi_meta]]
5343 who = "Perry McManis <pmcmanis@mozilla.com>"
5344 criteria = "safe-to-deploy"
5345 delta = "0.19.6 -> 0.20.0"
5347 [[audits.uniffi_meta]]
5348 who = "Jan-Erik Rediger <jrediger@mozilla.com>"
5349 criteria = "safe-to-deploy"
5350 delta = "0.20.0 -> 0.21.0"
5351 notes = "Maintained by the Glean and Application Services team."
5353 [[audits.uniffi_meta]]
5354 who = "Mike Hommey <mh+mozilla@glandium.org>"
5355 criteria = "safe-to-deploy"
5356 delta = "0.21.0 -> 0.21.1"
5357 notes = "I authored the changes in this version."
5359 [[audits.uniffi_meta]]
5360 who = "Jan-Erik Rediger <jrediger@mozilla.com>"
5361 criteria = "safe-to-deploy"
5362 delta = "0.21.1 -> 0.23.0"
5363 notes = "Maintained by the Glean and Application Services team."
5365 [[audits.uniffi_testing]]
5366 who = "Jan-Erik Rediger <jrediger@mozilla.com>"
5367 criteria = "safe-to-deploy"
5368 version = "0.23.0"
5369 notes = "Maintained by the Glean and Application Services team."
5371 [[audits.url]]
5372 who = "Valentin Gosu <valentin.gosu@gmail.com>"
5373 criteria = "safe-to-deploy"
5374 version = "2.4.0"
5376 [[audits.url]]
5377 who = "Valentin Gosu <valentin.gosu@gmail.com>"
5378 criteria = "safe-to-deploy"
5379 delta = "2.4.0 -> 2.4.1"
5381 [[audits.url]]
5382 who = "Valentin Gosu <valentin.gosu@gmail.com>"
5383 criteria = "safe-to-deploy"
5384 delta = "2.4.1 -> 2.5.0"
5386 [[audits.url]]
5387 who = "Henri Sivonen <hsivonen@hsivonen.fi>"
5388 criteria = "safe-to-deploy"
5389 delta = "2.5.0 -> 2.5.1"
5391 [[audits.url]]
5392 who = "Valentin Gosu <valentin.gosu@gmail.com>"
5393 criteria = "safe-to-deploy"
5394 delta = "2.5.1 -> 2.5.4"
5396 [[audits.utf16_iter]]
5397 who = "Henri Sivonen <hsivonen@hsivonen.fi>"
5398 criteria = "safe-to-deploy"
5399 version = "1.0.5"
5400 notes = "I, Henri Sivonen, wrote this crate."
5402 [[audits.uuid]]
5403 who = "Gabriele Svelto <gsvelto@mozilla.com>"
5404 criteria = "safe-to-deploy"
5405 delta = "0.8.2 -> 1.2.2"
5407 [[audits.uuid]]
5408 who = "Mike Hommey <mh+mozilla@glandium.org>"
5409 criteria = "safe-to-deploy"
5410 delta = "1.2.2 -> 1.3.0"
5412 [[audits.void]]
5413 who = "Bobby Holley <bobbyholley@gmail.com>"
5414 criteria = "safe-to-deploy"
5415 version = "1.0.2"
5416 notes = "Very small crate, just hosts the Void type for easier cross-crate interfacing."
5418 [[audits.warp]]
5419 who = "Mike Hommey <mh+mozilla@glandium.org>"
5420 criteria = "safe-to-run"
5421 delta = "0.3.2 -> 0.3.3"
5423 [[audits.wasm-encoder]]
5424 who = "Ryan Hunt <rhunt@eqrion.net>"
5425 criteria = "safe-to-deploy"
5426 version = "0.7.0"
5427 notes = "Maintained by the Bytecode Alliance, with contributions from Mozilla. This has no unsafe code and uses no ambient capabilities."
5429 [[audits.wasm-encoder]]
5430 who = "Ryan Hunt <rhunt@eqrion.net>"
5431 criteria = "safe-to-deploy"
5432 delta = "0.7.0 -> 0.14.0"
5433 notes = "wasm-encoder has no unsafe code and uses no ambient capabilities."
5435 [[audits.wasm-encoder]]
5436 who = "Yury Delendik <ydelendik@mozilla.com>"
5437 criteria = "safe-to-deploy"
5438 delta = "0.14.0 -> 0.15.0"
5440 [[audits.wasm-encoder]]
5441 who = "Yury Delendik <ydelendik@mozilla.com>"
5442 criteria = "safe-to-deploy"
5443 delta = "0.16.0 -> 0.17.0"
5445 [[audits.wasm-encoder]]
5446 who = "Ryan Hunt <rhunt@eqrion.net>"
5447 criteria = "safe-to-deploy"
5448 delta = "0.19.0 -> 0.19.1"
5450 [[audits.wasm-smith]]
5451 who = "Ryan Hunt <rhunt@eqrion.net>"
5452 criteria = "safe-to-deploy"
5453 version = "0.11.2"
5454 notes = "Maintained by the Bytecode Alliance, with contributions from Mozilla. I've vetted the one instance of unsafe code."
5456 [[audits.wasm-smith]]
5457 who = "Yury Delendik <ydelendik@mozilla.com>"
5458 criteria = "safe-to-run"
5459 delta = "0.11.2 -> 0.11.3"
5461 [[audits.wasm-smith]]
5462 who = "Yury Delendik <ydelendik@mozilla.com>"
5463 criteria = "safe-to-run"
5464 delta = "0.11.4 -> 0.11.5"
5466 [[audits.wasm-smith]]
5467 who = "Ryan Hunt <rhunt@eqrion.net>"
5468 criteria = "safe-to-run"
5469 delta = "0.11.7 -> 0.11.8"
5471 [[audits.wasmparser]]
5472 who = "Ryan Hunt <rhunt@eqrion.net>"
5473 criteria = "safe-to-deploy"
5474 version = "0.87.0"
5475 notes = "Maintained by the Bytecode Alliance, with contributions from Mozilla. I've vetted the one instance of unsafe code."
5477 [[audits.wasmparser]]
5478 who = "Yury Delendik <ydelendik@mozilla.com>"
5479 criteria = "safe-to-deploy"
5480 delta = "0.87.0 -> 0.88.0"
5482 [[audits.wasmparser]]
5483 who = "Yury Delendik <ydelendik@mozilla.com>"
5484 criteria = "safe-to-deploy"
5485 delta = "0.89.1 -> 0.91.0"
5487 [[audits.wasmparser]]
5488 who = "Ryan Hunt <rhunt@eqrion.net>"
5489 criteria = "safe-to-deploy"
5490 delta = "0.93.0 -> 0.94.0"
5492 [[audits.wast]]
5493 who = "Ryan Hunt <rhunt@eqrion.net>"
5494 criteria = "safe-to-deploy"
5495 version = "44.0.0"
5497 [[audits.wast]]
5498 who = "Ryan Hunt <rhunt@eqrion.net>"
5499 criteria = "safe-to-deploy"
5500 version = "44.0.0"
5501 notes = "Maintained by the Bytecode Alliance, with contributions from Mozilla. wast has no unsafe code and the only ambient capability it uses is to read the full contents of a file that is given to it."
5503 [[audits.wast]]
5504 who = "Yury Delendik <ydelendik@mozilla.com>"
5505 criteria = "safe-to-deploy"
5506 delta = "44.0.0 -> 45.0.0"
5508 [[audits.wast]]
5509 who = "Yury Delendik <ydelendik@mozilla.com>"
5510 criteria = "safe-to-deploy"
5511 delta = "46.0.0 -> 47.0.0"
5513 [[audits.wast]]
5514 who = "Ryan Hunt <rhunt@eqrion.net>"
5515 criteria = "safe-to-deploy"
5516 delta = "48.0.0 -> 49.0.0"
5518 [[audits.wast]]
5519 who = "Ben Visness <bvisness@mozilla.com>"
5520 criteria = "safe-to-deploy"
5521 delta = "55.0.0 -> 56.0.0"
5523 [[audits.webrtc-sdp]]
5524 who = "Byron Campen <docfaraday@gmail.com>"
5525 criteria = "safe-to-deploy"
5526 delta = "0.3.9 -> 0.3.10"
5528 [[audits.webrtc-sdp]]
5529 who = "Nicolas Grunbaum <ngrunbaum@mozilla.com>"
5530 criteria = "safe-to-deploy"
5531 delta = "0.3.10 -> 0.3.11"
5533 [[audits.webrtc-sdp]]
5534 who = "na-g <na-g@nostrum.com>"
5535 criteria = "safe-to-deploy"
5536 delta = "0.3.11 -> 0.3.13"
5538 [[audits.weedle2]]
5539 who = "Travis Long <tlong@mozilla.com>"
5540 criteria = "safe-to-deploy"
5541 version = "3.0.0"
5542 notes = "Maintained by the Glean and Application Services teams."
5544 [[audits.weedle2]]
5545 who = "Jan-Erik Rediger <jrediger@mozilla.com>"
5546 criteria = "safe-to-deploy"
5547 delta = "3.0.0 -> 4.0.0"
5548 notes = "Maintained by the Glean and Application Services team."
5550 [[audits.wgpu-core]]
5551 who = "Dzmitry Malyshau <kvark@fastmail.com>"
5552 criteria = "safe-to-deploy"
5553 version = "0.12.0"
5554 notes = """
5555 This crate, up through the indicated version, was written or reviewed
5556 by Dzmitry Malyshau while he was a Mozilla employee. Dzmitry left
5557 Mozilla at the beginning of February 2022. This audit statement was
5558 collected by Jim Blandy, a Mozilla employee, over email in July 2022:
5559 Dzmitry was shown, and agreed to, the 'safe-to-deploy' text.
5562 [[audits.wgpu-core]]
5563 who = "Jim Blandy <jimb@mozilla.com>"
5564 criteria = "safe-to-deploy"
5565 delta = "0.12.0 -> 0.13.0"
5567 [[audits.wgpu-core]]
5568 who = "Jim Blandy <jimb@red-bean.com>"
5569 criteria = "safe-to-deploy"
5570 delta = "0.13.0 -> 0.14.0"
5571 notes = "Audit by Erich Gubler, Jim Blandy, Nicolas Silva, and Teodor Tanasoaia."
5573 [[audits.wgpu-core]]
5574 who = "Nicolas Silva <nical@fastmail.com>"
5575 criteria = "safe-to-deploy"
5576 delta = "0.14.0 -> 0.15.0"
5578 [[audits.wgpu-core]]
5579 who = "Nicolas Silva <nical@fastmail.com>"
5580 criteria = "safe-to-deploy"
5581 delta = "0.15.0 -> 0.16.0"
5583 [[audits.wgpu-core]]
5584 who = "Nicolas Silva <nical@fastmail.com>"
5585 criteria = "safe-to-deploy"
5586 delta = "0.16.0 -> 0.17.0"
5588 [[audits.wgpu-core]]
5589 who = "Nicolas Silva <nical@fastmail.com>"
5590 criteria = "safe-to-deploy"
5591 delta = "0.17.0 -> 0.18.0"
5593 [[audits.wgpu-core]]
5594 who = "Erich Gubler <erichdongubler@gmail.com>"
5595 criteria = "safe-to-deploy"
5596 delta = "0.18.0 -> 0.19.3"
5598 [[audits.wgpu-core]]
5599 who = [
5600     "Jim Blandy <jimb@red-bean.com>",
5601     "Nicolas Silva <nical@fastmail.com>",
5602     "Erich Gubler <erichdongubler@gmail.com>",
5603     "Teodor Tanasoaia <ttanasoaia@mozilla.com>",
5605 criteria = "safe-to-deploy"
5606 delta = "0.19.3 -> 0.20.0"
5608 [[audits.wgpu-core]]
5609 who = "Jim Blandy <jimb@red-bean.com>"
5610 criteria = "safe-to-deploy"
5611 delta = "0.20.0 -> 22.0.0"
5613 [[audits.wgpu-core]]
5614 who = "Erich Gubler <erichdongubler@gmail.com>"
5615 criteria = "safe-to-deploy"
5616 delta = "22.0.0 -> 23.0.0"
5618 [[audits.wgpu-core]]
5619 who = "Erich Gubler <erichdongubler@gmail.com>"
5620 criteria = "safe-to-deploy"
5621 delta = "23.0.0 -> 23.0.1"
5623 [[audits.wgpu-core]]
5624 who = [
5625     "Jim Blandy <jimb@red-bean.com>",
5626     "Erich Gubler <erichdongubler@gmail.com>",
5627     "Teodor Tanasoaia <ttanasoaia@mozilla.com>",
5629 criteria = "safe-to-deploy"
5630 delta = "23.0.1 -> 23.0.1@git:aa7bec65b90028e4db6ec8def8589b52097d92f9"
5631 importable = false
5633 [[audits.wgpu-core]]
5634 who = "Erich Gubler <erichdongubler@gmail.com>"
5635 criteria = "safe-to-deploy"
5636 delta = "23.0.1 -> 24.0.0"
5638 [[audits.wgpu-hal]]
5639 who = "Dzmitry Malyshau <kvark@fastmail.com>"
5640 criteria = "safe-to-deploy"
5641 version = "0.12.0"
5642 notes = """
5643 This crate, up through the indicated version, was written or reviewed
5644 by Dzmitry Malyshau while he was a Mozilla employee. Dzmitry left
5645 Mozilla at the beginning of February 2022. This audit statement was
5646 collected by Jim Blandy, a Mozilla employee, over email in July 2022:
5647 Dzmitry was shown, and agreed to, the 'safe-to-deploy' text.
5650 [[audits.wgpu-hal]]
5651 who = "Jim Blandy <jimb@mozilla.com>"
5652 criteria = "safe-to-deploy"
5653 delta = "0.12.0 -> 0.13.0"
5655 [[audits.wgpu-hal]]
5656 who = "Jim Blandy <jimb@red-bean.com>"
5657 criteria = "safe-to-deploy"
5658 delta = "0.13.0 -> 0.14.0"
5659 notes = "Audit by Erich Gubler, Jim Blandy, Nicolas Silva, and Teodor Tanasoaia."
5661 [[audits.wgpu-hal]]
5662 who = "Nicolas Silva <nical@fastmail.com>"
5663 criteria = "safe-to-deploy"
5664 delta = "0.14.0 -> 0.15.0"
5666 [[audits.wgpu-hal]]
5667 who = "Nicolas Silva <nical@fastmail.com>"
5668 criteria = "safe-to-deploy"
5669 delta = "0.15.0 -> 0.16.0"
5671 [[audits.wgpu-hal]]
5672 who = "Nicolas Silva <nical@fastmail.com>"
5673 criteria = "safe-to-deploy"
5674 delta = "0.16.0 -> 0.17.0"
5676 [[audits.wgpu-hal]]
5677 who = "Nicolas Silva <nical@fastmail.com>"
5678 criteria = "safe-to-deploy"
5679 delta = "0.17.0 -> 0.18.0"
5681 [[audits.wgpu-hal]]
5682 who = "Erich Gubler <erichdongubler@gmail.com>"
5683 criteria = "safe-to-deploy"
5684 delta = "0.18.0 -> 0.19.3"
5686 [[audits.wgpu-hal]]
5687 who = [
5688     "Jim Blandy <jimb@red-bean.com>",
5689     "Nicolas Silva <nical@fastmail.com>",
5690     "Erich Gubler <erichdongubler@gmail.com>",
5691     "Teodor Tanasoaia <ttanasoaia@mozilla.com>",
5693 criteria = "safe-to-deploy"
5694 delta = "0.19.3 -> 0.20.0"
5696 [[audits.wgpu-hal]]
5697 who = "Jim Blandy <jimb@red-bean.com>"
5698 criteria = "safe-to-deploy"
5699 delta = "0.20.0 -> 22.0.0"
5701 [[audits.wgpu-hal]]
5702 who = "Erich Gubler <erichdongubler@gmail.com>"
5703 criteria = "safe-to-deploy"
5704 delta = "22.0.0 -> 23.0.0"
5706 [[audits.wgpu-hal]]
5707 who = "Erich Gubler <erichdongubler@gmail.com>"
5708 criteria = "safe-to-deploy"
5709 delta = "23.0.0 -> 23.0.1"
5711 [[audits.wgpu-hal]]
5712 who = [
5713     "Jim Blandy <jimb@red-bean.com>",
5714     "Erich Gubler <erichdongubler@gmail.com>",
5715     "Teodor Tanasoaia <ttanasoaia@mozilla.com>",
5717 criteria = "safe-to-deploy"
5718 delta = "23.0.1 -> 23.0.1@git:aa7bec65b90028e4db6ec8def8589b52097d92f9"
5719 importable = false
5721 [[audits.wgpu-hal]]
5722 who = "Erich Gubler <erichdongubler@gmail.com>"
5723 criteria = "safe-to-deploy"
5724 delta = "23.0.1 -> 24.0.0"
5726 [[audits.wgpu-types]]
5727 who = "Dzmitry Malyshau <kvark@fastmail.com>"
5728 criteria = "safe-to-deploy"
5729 version = "0.12.0"
5730 notes = """
5731 This crate, up through the indicated version, was written or reviewed
5732 by Dzmitry Malyshau while he was a Mozilla employee. Dzmitry left
5733 Mozilla at the beginning of February 2022. This audit statement was
5734 collected by Jim Blandy, a Mozilla employee, over email in July 2022:
5735 Dzmitry was shown, and agreed to, the 'safe-to-deploy' text.
5738 [[audits.wgpu-types]]
5739 who = "Jim Blandy <jimb@mozilla.com>"
5740 criteria = "safe-to-deploy"
5741 delta = "0.12.0 -> 0.13.0"
5743 [[audits.wgpu-types]]
5744 who = "Jim Blandy <jimb@red-bean.com>"
5745 criteria = "safe-to-deploy"
5746 delta = "0.13.0 -> 0.14.0"
5747 notes = "Audit by Erich Gubler, Jim Blandy, Nicolas Silva, and Teodor Tanasoaia."
5749 [[audits.wgpu-types]]
5750 who = "Nicolas Silva <nical@fastmail.com>"
5751 criteria = "safe-to-deploy"
5752 delta = "0.14.0 -> 0.15.0"
5754 [[audits.wgpu-types]]
5755 who = "Nicolas Silva <nical@fastmail.com>"
5756 criteria = "safe-to-deploy"
5757 delta = "0.15.0 -> 0.16.0"
5759 [[audits.wgpu-types]]
5760 who = "Nicolas Silva <nical@fastmail.com>"
5761 criteria = "safe-to-deploy"
5762 delta = "0.16.0 -> 0.17.0"
5764 [[audits.wgpu-types]]
5765 who = "Nicolas Silva <nical@fastmail.com>"
5766 criteria = "safe-to-deploy"
5767 delta = "0.17.0 -> 0.18.0"
5769 [[audits.wgpu-types]]
5770 who = "Erich Gubler <erichdongubler@gmail.com>"
5771 criteria = "safe-to-deploy"
5772 delta = "0.18.0 -> 0.19.2"
5774 [[audits.wgpu-types]]
5775 who = [
5776     "Jim Blandy <jimb@red-bean.com>",
5777     "Nicolas Silva <nical@fastmail.com>",
5778     "Erich Gubler <erichdongubler@gmail.com>",
5779     "Teodor Tanasoaia <ttanasoaia@mozilla.com>",
5781 criteria = "safe-to-deploy"
5782 delta = "0.19.2 -> 0.20.0"
5784 [[audits.wgpu-types]]
5785 who = "Jim Blandy <jimb@red-bean.com>"
5786 criteria = "safe-to-deploy"
5787 delta = "0.20.0 -> 22.0.0"
5789 [[audits.wgpu-types]]
5790 who = "Erich Gubler <erichdongubler@gmail.com>"
5791 criteria = "safe-to-deploy"
5792 delta = "22.0.0 -> 23.0.0"
5794 [[audits.wgpu-types]]
5795 who = [
5796     "Jim Blandy <jimb@red-bean.com>",
5797     "Erich Gubler <erichdongubler@gmail.com>",
5798     "Teodor Tanasoaia <ttanasoaia@mozilla.com>",
5800 criteria = "safe-to-deploy"
5801 delta = "23.0.0 -> 23.0.0@git:aa7bec65b90028e4db6ec8def8589b52097d92f9"
5802 importable = false
5804 [[audits.wgpu-types]]
5805 who = "Erich Gubler <erichdongubler@gmail.com>"
5806 criteria = "safe-to-deploy"
5807 delta = "23.0.0 -> 24.0.0"
5809 [[audits.whatsys]]
5810 who = "Bobby Holley <bobbyholley@gmail.com>"
5811 criteria = "safe-to-deploy"
5812 version = "0.1.2"
5813 notes = """
5814 Contains platform-specific FFI code for apple, mac, and windows. The windows code
5815 also contains a small C file compiled at build-time. I audited all of it and it
5816 looks correct.
5819 [[audits.whatsys]]
5820 who = "Jan-Erik Rediger <jrediger@mozilla.com>"
5821 criteria = "safe-to-deploy"
5822 delta = "0.1.2 -> 0.3.1"
5823 notes = "Maintained by me. I have written or reviewed all of the code."
5825 [[audits.winreg]]
5826 who = "Ray Kraesig <rkraesig@mozilla.com>"
5827 criteria = "safe-to-run"
5828 version = "0.10.1"
5829 notes = """
5830 This crate uses a lot of `unsafe`; not all of it is necessary, and not all of it
5831 is correct. (In particular, the alignment of data buffers does not seem to be
5832 correctly ensured at type-conversion time.) However, the code is not deceptive,
5833 and any more subtle issues do not appear to be exploitable -- certainly not from
5834 a test environment.
5837 [[audits.wpf-gpu-raster]]
5838 who = "Lee Salzman <lsalzman@mozilla.com>"
5839 criteria = "safe-to-deploy"
5840 version = "0.1.0"
5841 notes = "Written and maintained by Gfx team at Mozilla."
5843 [[audits.write16]]
5844 who = "Henri Sivonen <hsivonen@hsivonen.fi>"
5845 criteria = "safe-to-deploy"
5846 version = "1.0.0"
5847 notes = "I, Henri Sivonen, wrote this (safe-code-only) crate."
5849 [[audits.writeable]]
5850 who = "Makoto Kato <m_kato@ga2.so-net.ne.jp>"
5851 criteria = "safe-to-deploy"
5852 version = "0.5.2"
5853 notes = "writeable is a variation of fmt::Write with sink version. This uses `unsafe` block to handle potentially-invalid UTF-8 character. I've vetted the one instance of unsafe code."
5855 [[audits.writeable]]
5856 who = "Makoto Kato <m_kato@ga2.so-net.ne.jp>"
5857 criteria = "safe-to-deploy"
5858 delta = "0.5.2 -> 0.5.4"
5860 [[audits.writeable]]
5861 who = "Makoto Kato <m_kato@ga2.so-net.ne.jp>"
5862 criteria = "safe-to-deploy"
5863 delta = "0.5.4 -> 0.5.5"
5865 [[audits.xmldecl]]
5866 who = "Henri Sivonen <hsivonen@hsivonen.fi>"
5867 criteria = "safe-to-deploy"
5868 version = "0.2.0"
5869 notes = "I, Henri Sivonen, wrote this crate myself for Gecko even though it's published on crates.io."
5871 [[audits.yoke]]
5872 who = "Makoto Kato <m_kato@ga2.so-net.ne.jp>"
5873 criteria = "safe-to-deploy"
5874 version = "0.7.1"
5875 notes = "This crate is for zero-copy serialization for ICU4X data structure, and maintained by ICU4X team. Since this uses unsafe block for serialization, I audited code."
5877 [[audits.yoke]]
5878 who = "Makoto Kato <m_kato@ga2.so-net.ne.jp>"
5879 criteria = "safe-to-deploy"
5880 delta = "0.7.1 -> 0.7.3"
5882 [[audits.yoke]]
5883 who = "Makoto Kato <m_kato@ga2.so-net.ne.jp>"
5884 criteria = "safe-to-deploy"
5885 delta = "0.7.3 -> 0.7.4"
5887 [[audits.yoke-derive]]
5888 who = "Makoto Kato <m_kato@ga2.so-net.ne.jp>"
5889 criteria = "safe-to-deploy"
5890 version = "0.7.1@git:14e9a3a9857be74582abe2dfa7ab799c5eaac873"
5891 notes = "This crate is a helper for yoke crate that is ICU4X data structure, and maintained by ICU4X team. Since this uses unsafe block for serialization, all has the comment why this uses unsafe and I audited code."
5893 [[audits.yoke-derive]]
5894 who = "Makoto Kato <m_kato@ga2.so-net.ne.jp>"
5895 criteria = "safe-to-deploy"
5896 version = "0.7.3"
5898 [[audits.yoke-derive]]
5899 who = "Makoto Kato <m_kato@ga2.so-net.ne.jp>"
5900 criteria = "safe-to-deploy"
5901 delta = "0.7.3 -> 0.7.4"
5903 [[audits.zerocopy]]
5904 who = "Alex Franchuk <afranchuk@mozilla.com>"
5905 criteria = "safe-to-deploy"
5906 version = "0.7.32"
5907 notes = """
5908 This crate is `no_std` so doesn't use any side-effectful std functions. It
5909 contains quite a lot of `unsafe` code, however. I verified portions of this. It
5910 also has a large, thorough test suite. The project claims to run tests with
5911 Miri to have stronger soundness checks, and also claims to use formal
5912 verification tools to prove correctness.
5915 [[audits.zerocopy-derive]]
5916 who = "Alex Franchuk <afranchuk@mozilla.com>"
5917 criteria = "safe-to-deploy"
5918 version = "0.7.32"
5919 notes = "Clean, safe macros for zerocopy."
5921 [[audits.zerofrom]]
5922 who = "Makoto Kato <m_kato@ga2.so-net.ne.jp>"
5923 criteria = "safe-to-deploy"
5924 version = "0.1.2"
5925 notes = "This crate is zero-copy version of \"From\". This has no unsafe code and uses no ambient capabilities."
5927 [[audits.zerofrom]]
5928 who = "Makoto Kato <m_kato@ga2.so-net.ne.jp>"
5929 criteria = "safe-to-deploy"
5930 delta = "0.1.2 -> 0.1.4"
5932 [[audits.zerofrom-derive]]
5933 who = "Makoto Kato <m_kato@ga2.so-net.ne.jp>"
5934 criteria = "safe-to-deploy"
5935 version = "0.1.2@git:14e9a3a9857be74582abe2dfa7ab799c5eaac873"
5936 notes = "This is custom derives for `ZeroFrom` that is from zerofrom crate. This has no unsafe code and uses no ambient capabilities."
5938 [[audits.zerofrom-derive]]
5939 who = "Makoto Kato <m_kato@ga2.so-net.ne.jp>"
5940 criteria = "safe-to-deploy"
5941 version = "0.1.3"
5943 [[audits.zeroize]]
5944 who = "Benjamin Beurdouche <beurdouche@mozilla.com>"
5945 criteria = "safe-to-deploy"
5946 version = "1.8.1"
5947 notes = """
5948 This code DOES contain unsafe code required to internally call volatiles
5949 for deleting data. This is expected and documented behavior.
5952 [[audits.zeroize_derive]]
5953 who = "Benjamin Beurdouche <beurdouche@mozilla.com>"
5954 criteria = "safe-to-deploy"
5955 version = "1.4.2"
5957 [[audits.zerovec]]
5958 who = "Makoto Kato <m_kato@ga2.so-net.ne.jp>"
5959 criteria = "safe-to-deploy"
5960 version = "0.9.4"
5961 notes = "This crate is zero-copy data structure implmentation. Although this uses unsafe block in several code, it requires for zero-copy. And this has a comment in code why this uses unsafe and I audited code."
5963 [[audits.zerovec]]
5964 who = "Makoto Kato <m_kato@ga2.so-net.ne.jp>"
5965 criteria = "safe-to-deploy"
5966 delta = "0.9.4 -> 0.10.1"
5968 [[audits.zerovec]]
5969 who = "Makoto Kato <m_kato@ga2.so-net.ne.jp>"
5970 criteria = "safe-to-deploy"
5971 delta = "0.10.1 -> 0.10.2"
5973 [[audits.zerovec]]
5974 who = "Mike Hommey <mh+mozilla@glandium.org>"
5975 criteria = "safe-to-deploy"
5976 delta = "0.10.2 -> 0.10.4"
5978 [[audits.zerovec-derive]]
5979 who = "Makoto Kato <m_kato@ga2.so-net.ne.jp>"
5980 criteria = "safe-to-deploy"
5981 version = "0.9.4@git:14e9a3a9857be74582abe2dfa7ab799c5eaac873"
5982 notes = "This is custom derives for `ZeroVec` that is from zerovec crate. Although this uses unsafe block for zero-copy, this has a comment in code why this uses unsafe and I audited code."
5984 [[audits.zerovec-derive]]
5985 who = "Makoto Kato <m_kato@ga2.so-net.ne.jp>"
5986 criteria = "safe-to-deploy"
5987 version = "0.10.1"
5989 [[audits.zerovec-derive]]
5990 who = "Makoto Kato <m_kato@ga2.so-net.ne.jp>"
5991 criteria = "safe-to-deploy"
5992 delta = "0.10.1 -> 0.10.2"
5994 [[audits.zerovec-derive]]
5995 who = "Max Inden <mail@max-inden.de>"
5996 criteria = "safe-to-deploy"
5997 delta = "0.10.2 -> 0.10.3"
5999 [[audits.zip]]
6000 who = "Alex Franchuk <afranchuk@mozilla.com>"
6001 criteria = "safe-to-deploy"
6002 version = "0.6.4"
6003 notes = """
6004 No unsafe code nor unwarranted dependencies. Side-effectful std usage is only
6005 present where expected (zip archive reading/writing and unpacking)
6008 [[audits.zip]]
6009 who = "Mike Hommey <mh+mozilla@glandium.org>"
6010 criteria = "safe-to-run"
6011 delta = "0.6.2 -> 0.6.3"
6013 [[audits.zip]]
6014 who = "Mike Hommey <mh+mozilla@glandium.org>"
6015 criteria = "safe-to-run"
6016 delta = "0.6.3 -> 0.6.4"
6018 [[audits.zip]]
6019 who = "Alex Franchuk <afranchuk@mozilla.com>"
6020 criteria = "safe-to-deploy"
6021 delta = "0.6.4 -> 2.1.3"
6022 notes = """
6023 There's a lot of new code and features, however it's almost entirely very
6024 straightforward and safe. All new dependencies are appropriate.
6025 `FixedSizeBlock::interpret` could be unsound if implemented on a
6026 non-1-byte-aligned type, however right now that is not the case
6027 (submitted https://github.com/zip-rs/zip2/issues/198).
6030 [[audits.zlib-rs]]
6031 who = "Mike Hommey <mh+mozilla@glandium.org>"
6032 criteria = "safe-to-deploy"
6033 delta = "0.2.1 -> 0.2.1@git:4aa430ccb77537d0d60dab8db993ca51bb1194c5"
6034 importable = false
6036 [[trusted.aho-corasick]]
6037 criteria = "safe-to-deploy"
6038 user-id = 189 # Andrew Gallant (BurntSushi)
6039 start = "2019-03-28"
6040 end = "2024-05-03"
6042 [[trusted.anstyle]]
6043 criteria = "safe-to-deploy"
6044 user-id = 6743 # Ed Page (epage)
6045 start = "2022-05-18"
6046 end = "2024-09-28"
6048 [[trusted.async-trait]]
6049 criteria = "safe-to-deploy"
6050 user-id = 3618 # David Tolnay (dtolnay)
6051 start = "2019-07-23"
6052 end = "2024-04-25"
6054 [[trusted.atomic]]
6055 criteria = "safe-to-deploy"
6056 user-id = 2915 # Amanieu d'Antras (Amanieu)
6057 start = "2019-02-22"
6058 end = "2024-05-05"
6060 [[trusted.byteorder]]
6061 criteria = "safe-to-deploy"
6062 user-id = 189 # Andrew Gallant (BurntSushi)
6063 start = "2019-06-09"
6064 end = "2024-05-03"
6066 [[trusted.bytes]]
6067 criteria = "safe-to-deploy"
6068 user-id = 6741 # Alice Ryhl (Darksonn)
6069 start = "2021-01-11"
6070 end = "2024-05-05"
6072 [[trusted.cc]]
6073 criteria = "safe-to-deploy"
6074 user-id = 2915 # Amanieu d'Antras (Amanieu)
6075 start = "2024-02-20"
6076 end = "2025-02-26"
6078 [[trusted.clap]]
6079 criteria = "safe-to-deploy"
6080 user-id = 6743 # Ed Page (epage)
6081 start = "2021-12-08"
6082 end = "2025-08-21"
6084 [[trusted.clap_builder]]
6085 criteria = "safe-to-deploy"
6086 user-id = 6743 # Ed Page (epage)
6087 start = "2023-03-28"
6088 end = "2024-06-02"
6090 [[trusted.clap_derive]]
6091 criteria = "safe-to-deploy"
6092 user-id = 6743 # Ed Page (epage)
6093 start = "2021-12-08"
6094 end = "2025-08-21"
6096 [[trusted.clap_lex]]
6097 criteria = "safe-to-deploy"
6098 user-id = 6743 # Ed Page (epage)
6099 start = "2022-04-15"
6100 end = "2025-08-21"
6102 [[trusted.dtoa]]
6103 criteria = "safe-to-deploy"
6104 user-id = 3618 # David Tolnay (dtolnay)
6105 start = "2019-05-02"
6106 end = "2024-04-25"
6108 [[trusted.equivalent]]
6109 criteria = "safe-to-deploy"
6110 user-id = 539 # Josh Stone (cuviper)
6111 start = "2023-02-05"
6112 end = "2024-07-17"
6114 [[trusted.errno]]
6115 criteria = "safe-to-deploy"
6116 user-id = 6825 # Dan Gohman (sunfishcode)
6117 start = "2023-08-29"
6118 end = "2025-01-11"
6120 [[trusted.flate2]]
6121 criteria = "safe-to-deploy"
6122 user-id = 4333 # Josh Triplett (joshtriplett)
6123 start = "2020-09-30"
6124 end = "2024-05-05"
6126 [[trusted.h2]]
6127 criteria = "safe-to-deploy"
6128 user-id = 359 # Sean McArthur (seanmonstar)
6129 start = "2019-03-13"
6130 end = "2024-12-05"
6132 [[trusted.hashbrown]]
6133 criteria = "safe-to-deploy"
6134 user-id = 2915 # Amanieu d'Antras (Amanieu)
6135 start = "2019-04-02"
6136 end = "2024-07-17"
6138 [[trusted.headers]]
6139 criteria = "safe-to-deploy"
6140 user-id = 359 # Sean McArthur (seanmonstar)
6141 start = "2019-09-09"
6142 end = "2024-04-25"
6144 [[trusted.httparse]]
6145 criteria = "safe-to-deploy"
6146 user-id = 359 # Sean McArthur (seanmonstar)
6147 start = "2019-07-03"
6148 end = "2024-04-25"
6150 [[trusted.indexmap]]
6151 criteria = "safe-to-deploy"
6152 user-id = 539 # Josh Stone (cuviper)
6153 start = "2020-01-15"
6154 end = "2024-05-05"
6156 [[trusted.inherent]]
6157 criteria = "safe-to-deploy"
6158 user-id = 3618 # David Tolnay (dtolnay)
6159 start = "2019-07-14"
6160 end = "2024-04-25"
6162 [[trusted.iovec]]
6163 criteria = "safe-to-deploy"
6164 user-id = 10 # Carl Lerche (carllerche)
6165 start = "2019-10-09"
6166 end = "2024-05-05"
6168 [[trusted.itoa]]
6169 criteria = "safe-to-deploy"
6170 user-id = 3618 # David Tolnay (dtolnay)
6171 start = "2019-05-02"
6172 end = "2024-04-25"
6174 [[trusted.jobserver]]
6175 criteria = "safe-to-deploy"
6176 user-id = 1 # Alex Crichton (alexcrichton)
6177 start = "2019-03-15"
6178 end = "2024-05-05"
6180 [[trusted.libc]]
6181 criteria = "safe-to-deploy"
6182 user-id = 2915 # Amanieu d'Antras (Amanieu)
6183 start = "2021-01-27"
6184 end = "2024-05-05"
6186 [[trusted.libc]]
6187 criteria = "safe-to-deploy"
6188 user-id = 51017 # Yuki Okushi (JohnTitor)
6189 start = "2020-03-17"
6190 end = "2024-10-25"
6192 [[trusted.libz-rs-sys]]
6193 criteria = "safe-to-deploy"
6194 user-id = 1303 # Ruben Nijveld (rnijveld)
6195 start = "2024-02-23"
6196 end = "2024-09-01"
6198 [[trusted.linux-raw-sys]]
6199 criteria = "safe-to-deploy"
6200 user-id = 6825 # Dan Gohman (sunfishcode)
6201 start = "2021-06-12"
6202 end = "2024-09-08"
6204 [[trusted.lock_api]]
6205 criteria = "safe-to-deploy"
6206 user-id = 2915 # Amanieu d'Antras (Amanieu)
6207 start = "2019-05-04"
6208 end = "2024-05-05"
6210 [[trusted.memchr]]
6211 criteria = "safe-to-deploy"
6212 user-id = 189 # Andrew Gallant (BurntSushi)
6213 start = "2019-07-07"
6214 end = "2025-06-20"
6216 [[trusted.mime]]
6217 criteria = "safe-to-deploy"
6218 user-id = 359 # Sean McArthur (seanmonstar)
6219 start = "2019-09-09"
6220 end = "2024-04-25"
6222 [[trusted.mio]]
6223 criteria = "safe-to-deploy"
6224 user-id = 10 # Carl Lerche (carllerche)
6225 start = "2019-05-15"
6226 end = "2024-05-06"
6228 [[trusted.num_cpus]]
6229 criteria = "safe-to-deploy"
6230 user-id = 359 # Sean McArthur (seanmonstar)
6231 start = "2019-06-10"
6232 end = "2024-04-25"
6234 [[trusted.ordered-float]]
6235 criteria = "safe-to-deploy"
6236 user-id = 2017 # Matt Brubeck (mbrubeck)
6237 start = "2019-03-13"
6238 end = "2024-05-06"
6240 [[trusted.parking_lot]]
6241 criteria = "safe-to-deploy"
6242 user-id = 2915 # Amanieu d'Antras (Amanieu)
6243 start = "2019-05-04"
6244 end = "2024-05-05"
6246 [[trusted.parking_lot_core]]
6247 criteria = "safe-to-deploy"
6248 user-id = 2915 # Amanieu d'Antras (Amanieu)
6249 start = "2019-05-04"
6250 end = "2024-05-05"
6252 [[trusted.paste]]
6253 criteria = "safe-to-deploy"
6254 user-id = 3618 # David Tolnay (dtolnay)
6255 start = "2019-03-19"
6256 end = "2024-04-25"
6258 [[trusted.phf]]
6259 criteria = "safe-to-deploy"
6260 user-id = 51017 # Yuki Okushi (JohnTitor)
6261 start = "2021-06-17"
6262 end = "2026-01-03"
6264 [[trusted.phf_codegen]]
6265 criteria = "safe-to-deploy"
6266 user-id = 51017 # Yuki Okushi (JohnTitor)
6267 start = "2021-06-17"
6268 end = "2026-01-03"
6270 [[trusted.phf_generator]]
6271 criteria = "safe-to-deploy"
6272 user-id = 51017 # Yuki Okushi (JohnTitor)
6273 start = "2021-06-17"
6274 end = "2026-01-03"
6276 [[trusted.phf_macros]]
6277 criteria = "safe-to-deploy"
6278 user-id = 51017 # Yuki Okushi (JohnTitor)
6279 start = "2021-06-17"
6280 end = "2026-01-03"
6282 [[trusted.phf_shared]]
6283 criteria = "safe-to-deploy"
6284 user-id = 51017 # Yuki Okushi (JohnTitor)
6285 start = "2021-06-17"
6286 end = "2026-01-03"
6288 [[trusted.proc-macro-hack]]
6289 criteria = "safe-to-deploy"
6290 user-id = 3618 # David Tolnay (dtolnay)
6291 start = "2019-04-16"
6292 end = "2024-04-25"
6294 [[trusted.proc-macro2]]
6295 criteria = "safe-to-deploy"
6296 user-id = 3618 # David Tolnay (dtolnay)
6297 start = "2019-04-23"
6298 end = "2024-05-30"
6300 [[trusted.quote]]
6301 criteria = "safe-to-deploy"
6302 user-id = 3618 # David Tolnay (dtolnay)
6303 start = "2019-04-09"
6304 end = "2024-05-30"
6306 [[trusted.regex]]
6307 criteria = "safe-to-deploy"
6308 user-id = 189 # Andrew Gallant (BurntSushi)
6309 start = "2019-02-27"
6310 end = "2024-05-03"
6312 [[trusted.regex-automata]]
6313 criteria = "safe-to-deploy"
6314 user-id = 189 # Andrew Gallant (BurntSushi)
6315 start = "2019-02-25"
6316 end = "2024-09-20"
6318 [[trusted.regex-syntax]]
6319 criteria = "safe-to-deploy"
6320 user-id = 189 # Andrew Gallant (BurntSushi)
6321 start = "2019-03-30"
6322 end = "2024-05-03"
6324 [[trusted.rustix]]
6325 criteria = "safe-to-deploy"
6326 user-id = 6825 # Dan Gohman (sunfishcode)
6327 start = "2021-10-29"
6328 end = "2024-09-08"
6330 [[trusted.ryu]]
6331 criteria = "safe-to-deploy"
6332 user-id = 3618 # David Tolnay (dtolnay)
6333 start = "2019-05-02"
6334 end = "2024-04-25"
6336 [[trusted.same-file]]
6337 criteria = "safe-to-deploy"
6338 user-id = 189 # Andrew Gallant (BurntSushi)
6339 start = "2019-07-16"
6340 end = "2024-05-03"
6342 [[trusted.scopeguard]]
6343 criteria = "safe-to-deploy"
6344 user-id = 2915 # Amanieu d'Antras (Amanieu)
6345 start = "2020-02-16"
6346 end = "2024-05-05"
6348 [[trusted.serde]]
6349 criteria = "safe-to-deploy"
6350 user-id = 3618 # David Tolnay (dtolnay)
6351 start = "2019-03-01"
6352 end = "2025-05-31"
6354 [[trusted.serde_bytes]]
6355 criteria = "safe-to-deploy"
6356 user-id = 3618 # David Tolnay (dtolnay)
6357 start = "2019-02-25"
6358 end = "2024-04-25"
6360 [[trusted.serde_derive]]
6361 criteria = "safe-to-deploy"
6362 user-id = 3618 # David Tolnay (dtolnay)
6363 start = "2019-03-01"
6364 end = "2025-05-31"
6366 [[trusted.serde_json]]
6367 criteria = "safe-to-deploy"
6368 user-id = 3618 # David Tolnay (dtolnay)
6369 start = "2019-02-28"
6370 end = "2024-04-25"
6372 [[trusted.serde_repr]]
6373 criteria = "safe-to-deploy"
6374 user-id = 3618 # David Tolnay (dtolnay)
6375 start = "2019-04-26"
6376 end = "2024-04-25"
6378 [[trusted.serde_yaml]]
6379 criteria = "safe-to-deploy"
6380 user-id = 3618 # David Tolnay (dtolnay)
6381 start = "2019-05-02"
6382 end = "2024-04-25"
6384 [[trusted.smallvec]]
6385 criteria = "safe-to-deploy"
6386 user-id = 2017 # Matt Brubeck (mbrubeck)
6387 start = "2019-10-28"
6388 end = "2024-05-06"
6390 [[trusted.syn]]
6391 criteria = "safe-to-deploy"
6392 user-id = 3618 # David Tolnay (dtolnay)
6393 start = "2019-03-01"
6394 end = "2025-07-04"
6396 [[trusted.termcolor]]
6397 criteria = "safe-to-deploy"
6398 user-id = 189 # Andrew Gallant (BurntSushi)
6399 start = "2019-06-04"
6400 end = "2024-05-03"
6402 [[trusted.thiserror]]
6403 criteria = "safe-to-deploy"
6404 user-id = 3618 # David Tolnay (dtolnay)
6405 start = "2019-10-09"
6406 end = "2025-05-31"
6408 [[trusted.thiserror-impl]]
6409 criteria = "safe-to-deploy"
6410 user-id = 3618 # David Tolnay (dtolnay)
6411 start = "2019-10-09"
6412 end = "2025-05-31"
6414 [[trusted.threadbound]]
6415 criteria = "safe-to-deploy"
6416 user-id = 3618 # David Tolnay (dtolnay)
6417 start = "2020-06-16"
6418 end = "2024-04-25"
6420 [[trusted.tokio]]
6421 criteria = "safe-to-run"
6422 user-id = 6741 # Alice Ryhl (Darksonn)
6423 start = "2020-12-25"
6424 end = "2025-07-30"
6426 [[trusted.tokio-macros]]
6427 criteria = "safe-to-deploy"
6428 user-id = 6741 # Alice Ryhl (Darksonn)
6429 start = "2020-10-26"
6430 end = "2025-07-30"
6432 [[trusted.tokio-util]]
6433 criteria = "safe-to-deploy"
6434 user-id = 6741 # Alice Ryhl (Darksonn)
6435 start = "2021-01-12"
6436 end = "2024-05-05"
6438 [[trusted.toml]]
6439 criteria = "safe-to-deploy"
6440 user-id = 1 # Alex Crichton (alexcrichton)
6441 start = "2019-05-16"
6442 end = "2024-05-06"
6444 [[trusted.unicode-ident]]
6445 criteria = "safe-to-deploy"
6446 user-id = 3618 # David Tolnay (dtolnay)
6447 start = "2021-10-02"
6448 end = "2024-04-25"
6450 [[trusted.walkdir]]
6451 criteria = "safe-to-deploy"
6452 user-id = 189 # Andrew Gallant (BurntSushi)
6453 start = "2019-06-09"
6454 end = "2024-05-03"
6456 [[trusted.warp]]
6457 criteria = "safe-to-deploy"
6458 user-id = 359 # Sean McArthur (seanmonstar)
6459 start = "2019-03-20"
6460 end = "2024-05-08"
6462 [[trusted.wasi]]
6463 criteria = "safe-to-deploy"
6464 user-id = 1 # Alex Crichton (alexcrichton)
6465 start = "2020-06-03"
6466 end = "2024-05-05"
6468 [[trusted.wasm-encoder]]
6469 criteria = "safe-to-deploy"
6470 user-id = 73222 # wasmtime-publish
6471 start = "2024-02-15"
6472 end = "2025-03-11"
6474 [[trusted.wasm-smith]]
6475 criteria = "safe-to-deploy"
6476 user-id = 73222 # wasmtime-publish
6477 start = "2024-02-15"
6478 end = "2025-03-11"
6480 [[trusted.wast]]
6481 criteria = "safe-to-deploy"
6482 user-id = 73222 # wasmtime-publish
6483 start = "2024-02-15"
6484 end = "2025-03-11"
6486 [[trusted.winapi-util]]
6487 criteria = "safe-to-deploy"
6488 user-id = 189 # Andrew Gallant (BurntSushi)
6489 start = "2020-01-11"
6490 end = "2024-05-03"
6492 [[trusted.windows]]
6493 criteria = "safe-to-deploy"
6494 user-id = 64539 # Kenny Kerr (kennykerr)
6495 start = "2021-01-15"
6496 end = "2025-01-30"
6498 [[trusted.windows-core]]
6499 criteria = "safe-to-deploy"
6500 user-id = 64539 # Kenny Kerr (kennykerr)
6501 start = "2021-11-15"
6502 end = "2024-09-20"
6504 [[trusted.windows-implement]]
6505 criteria = "safe-to-deploy"
6506 user-id = 64539 # Kenny Kerr (kennykerr)
6507 start = "2022-01-27"
6508 end = "2025-07-29"
6510 [[trusted.windows-interface]]
6511 criteria = "safe-to-deploy"
6512 user-id = 64539 # Kenny Kerr (kennykerr)
6513 start = "2022-02-18"
6514 end = "2025-07-29"
6516 [[trusted.windows-result]]
6517 criteria = "safe-to-deploy"
6518 user-id = 64539 # Kenny Kerr (kennykerr)
6519 start = "2024-02-02"
6520 end = "2025-07-29"
6522 [[trusted.windows-strings]]
6523 criteria = "safe-to-deploy"
6524 user-id = 64539 # Kenny Kerr (kennykerr)
6525 start = "2024-02-02"
6526 end = "2025-07-29"
6528 [[trusted.windows-sys]]
6529 criteria = "safe-to-deploy"
6530 user-id = 64539 # Kenny Kerr (kennykerr)
6531 start = "2021-11-15"
6532 end = "2024-09-12"
6534 [[trusted.zlib-rs]]
6535 criteria = "safe-to-deploy"
6536 user-id = 1303 # Ruben Nijveld (rnijveld)
6537 start = "2024-02-23"
6538 end = "2024-09-01"