An open index of dependabot pull requests across open source projects.

diesel

Ecosystem:
cargo
Package URL:
pkg:cargo/diesel
Total PRs:
234 Dependabot PRs
Latest PR:
5 days ago
Unique Repositories:
105 repositories
Unique Repos (30 days):
6 repositories
Security Advisories
Diesel: Command injection in Diesel's implementation of `COPY FROM`/`COPY TO`
GHSA-m9p2-fxp5-v3fp MODERATE published 24 days ago • updated 3 days ago
Diesel allows users to configure various options for PostgreSQL's `COPY FROM` and `COPY TO` statements. These configurations are partially provided...
Diesel: Possible unaligned data access for implementations of `SqliteAggregate`
GHSA-q8x8-jrhj-fh9p MODERATE published 24 days ago • updated 3 days ago
Diesel allows to register custom aggregate SQL functions for SQLite via the `SqliteAggregate` interface. To store an instance of the custom aggreg...
Diesel vulnerable to Binary Protocol Misinterpretation caused by Truncating or Overflowing Casts
GHSA-wq9x-qwcq-mmgf HIGH published almost 2 years ago • updated about 1 month ago
The following presentation at this year's DEF CON was brought to our attention on the Diesel Gitter Channel: > SQL Injection isn't Dead: Smuggling...
Diesel's SQLite backend has possible UTF-8 corruption
GHSA-h5x4-m2qf-r4f2 HIGH published about 1 month ago • updated 4 days ago
Diesel uses the `sqlite3_value_text` function to receive strings from SQLite while deserializing query results. We misinterpreted the corresponding...
Fix a use-after-free bug in diesels Sqlite backend
GHSA-j8q9-5rp9-4mv9 CVE-2021-28305 CRITICAL published about 4 years ago • updated 3 days ago
An issue was discovered in the diesel crate before 1.4.6 for Rust. There is a use-after-free in the SQLite backend because the semantics of sqlite3...
Recent PRs
Bump the minor group with 21 updates

hut8/soar #1273

2.3.7 → 2.3.8 Patch PR
Closed about 2 months ago 1 comment
hut8
Package Details
Name: diesel
Ecosystem: cargo
PURL Type: cargo
Package URL: pkg:cargo/diesel
JSON API: View JSON
Security Advisories

5

Active advisories
CRITICAL 1
HIGH 2
MODERATE 2
View All cargo Advisories
Package Information
Description:

A safe, extensible ORM and Query Builder for PostgreSQL, SQLite, and MySQL

Repository: https://github.com/diesel-rs/diesel
Homepage: https://diesel.rs
Latest Release: 2.2.10
about 1 year ago
Dependent Repos: 3,691
Dependent Packages: 416
Downloads: 15,753,144
Ranking: Top 0.6417% by dependent repos Top 0.723% by downloads Top 0.2029% by dependent pkgs
PR Status
Open 84 (35.9%)
Merged 44 (18.8%)
Closed 102 (43.6%)
PR Types
Major 26 (11.1%)
Minor 31 (13.2%)
Patch 173 (73.9%)