Source: rust-cargo-audit Section: rust Build-Depends: debhelper-compat (= 13), dh-sequence-cargo Build-Depends-Arch: cargo:native, rustc:native (>= 1.81.0), libstd-rust-dev, librust-abscissa-core-0.9+default-dev, librust-cargo-lock-11+default-dev, librust-clap-4+default-dev, librust-display-error-chain-0.2+default-dev, librust-home-0.5+default-dev, librust-rustsec-0.30+binary-scanning-dev, librust-rustsec-0.30+default-dev, librust-rustsec-0.30+dependency-tree-dev, librust-serde-1+default-dev, librust-serde-1+serde-derive-dev, librust-serde-json-1+default-dev, librust-thiserror-1+default-dev Maintainer: Debian Rust Maintainers Uploaders: Alexander Kjäll Standards-Version: 4.7.3 Vcs-Git: https://salsa.debian.org/rust-team/debcargo-conf.git [src/cargo-audit] Vcs-Browser: https://salsa.debian.org/rust-team/debcargo-conf/tree/master/src/cargo-audit Homepage: https://rustsec.org X-Cargo-Crate: cargo-audit X-Cargo-Crate-Version: 0.21.2 Package: librust-cargo-audit-dev Architecture: any Multi-Arch: same Depends: ${misc:Depends}, librust-abscissa-core-0.9+default-dev, librust-cargo-lock-11+default-dev, librust-clap-4+default-dev, librust-display-error-chain-0.2+default-dev, librust-home-0.5+default-dev, librust-rustsec-0.30+binary-scanning-dev, librust-rustsec-0.30+default-dev, librust-rustsec-0.30+dependency-tree-dev, librust-serde-1+default-dev, librust-serde-1+serde-derive-dev, librust-serde-json-1+default-dev, librust-thiserror-1+default-dev Provides: librust-cargo-audit+binary-scanning-dev (= ${binary:Version}), librust-cargo-audit+default-dev (= ${binary:Version}), librust-cargo-audit+fix-dev (= ${binary:Version}), librust-cargo-audit-0-dev (= ${binary:Version}), librust-cargo-audit-0+binary-scanning-dev (= ${binary:Version}), librust-cargo-audit-0+default-dev (= ${binary:Version}), librust-cargo-audit-0+fix-dev (= ${binary:Version}), librust-cargo-audit-0.21-dev (= ${binary:Version}), librust-cargo-audit-0.21+binary-scanning-dev (= ${binary:Version}), librust-cargo-audit-0.21+default-dev (= ${binary:Version}), librust-cargo-audit-0.21+fix-dev (= ${binary:Version}), librust-cargo-audit-0.21.2-dev (= ${binary:Version}), librust-cargo-audit-0.21.2+binary-scanning-dev (= ${binary:Version}), librust-cargo-audit-0.21.2+default-dev (= ${binary:Version}), librust-cargo-audit-0.21.2+fix-dev (= ${binary:Version}) Description: Audit Cargo.lock for crates with security vulnerabilities - Rust source code Audit your dependencies for crates with security vulnerabilities reported to the RustSec Advisory Database. . You can also audit binaries, run cargo audit bin followed by the paths to your binaries to audit them. . If your programs have been compiled with cargo auditable, the audit is fully accurate because all the necessary information is embedded in the compiled binary. . For binaries that were not compiled with cargo auditable it will recover a part of the dependency list by parsing panic messages. This will miss any embedded C code (e.g. OpenSSL) as well as roughly half of the Rust dependencies because the Rust compiler is very good at removing unnecessary panics, but that's better than having no vulnerability information whatsoever. Source code for Debianized Rust crate "cargo-audit" Package: cargo-audit Architecture: any Section: rust Depends: ${misc:Depends}, ${shlibs:Depends}, ${cargo:Depends}, cargo Recommends: ${cargo:Recommends} Suggests: ${cargo:Suggests} Provides: ${cargo:Provides} Built-Using: ${cargo:Built-Using} Static-Built-Using: ${cargo:Static-Built-Using} Description: Audit Cargo.lock for crates with security vulnerabilities Audit your dependencies for crates with security vulnerabilities reported to the RustSec Advisory Database. . You can also audit binaries, run cargo audit bin followed by the paths to your binaries to audit them. . If your programs have been compiled with cargo auditable, the audit is fully accurate because all the necessary information is embedded in the compiled binary. . For binaries that were not compiled with cargo auditable it will recover a part of the dependency list by parsing panic messages. This will miss any embedded C code (e.g. OpenSSL) as well as roughly half of the Rust dependencies because the Rust compiler is very good at removing unnecessary panics, but that's better than having no vulnerability information whatsoever. This package contains the following binaries built from the Rust crate "cargo-audit": - cargo-audit