8.6.0 — diff review from 8.5.0 only (older version)
From zcash/rust-ecosystem copy of zcash/wallet. By Jack Grigg.
These reviews are from cargo-vet. To add your review, set up cargo-vet
and submit your URL to its registry.
The current version of rust-embed-impl is 8.7.0.
8.6.0 — diff review from 8.5.0 only (older version)
From zcash/rust-ecosystem copy of zcash/wallet. By Jack Grigg.
8.3.0 (older version)
From kornelski/crev-proofs copy of git.savannah.gnu.org.
Packaged for Guix (crates-io)
cargo-vet does not verify reviewers' identity. You have to fully trust the source the audits are from.
This crate will not introduce a serious security vulnerability to production software exposed to untrusted input. More…
This crate can be compiled, run, and tested on a local workstation or in controlled automation without surprising consequences. More…
May have been packaged automatically without a review
Lib.rs has been able to verify that all files in the crate's tarball, except Cargo.lock
,
are in the crate's repository. Please note that this check is still in beta, and absence of this confirmation does not mean that the files don't match.
Crates in the crates.io registry are tarball snapshots uploaded by crates' publishers. The registry is not using crates' git repositories, so there is a possibility that published crates have a misleading repository URL, or contain different code from the code in the repository.
To review the actual code of the crate, it's best to use cargo crev open rust-embed-impl
. Alternatively, you can download the tarball of rust-embed-impl v8.7.0 or view the source online.
If the folder path does not exist post-canonicalization, the non-canonicalized path is used instead to generate the
#ident::get
implementation. The path is checked as a prefix on requested paths to avoid escapes; not having this be a known-canonical path could be a problem in some scenarios. This is a limitation of howPath::canonicalize
relies on filesystem resolution, and cannot canonicalize a path that does not exist.This change was made as part of adding a default-disabled
allow_missing
attribute, and the generator is gated on a check that the non-canonicalized path exists (if the new attribute is off), so there should not be any changes to existing usage.