Only report a vulnerability for the latest version (according to their branch) of supported crates:
| Name | Directory | Branch | Supported |
|---|---|---|---|
data-encoding |
lib |
main |
Yes |
data-encoding-bin |
bin |
main |
Yes |
data-encoding-macro |
lib/macro |
main |
Yes |
data-encoding-macro-internal |
lib/macro/internal |
main |
No |
data-encoding-v3 |
lib/v3 |
main |
No |
Notes for unsupported crates:
data-encoding-macro-internalis an implementation detail ofdata-encoding-macro. A bug only reachable by using it directly is not a vulnerability, whereas a bug reachable throughdata-encoding-macrois.data-encoding-v3is a development crate fordata-encoding. A bug only reachable indata-encoding-v3is not a vulnerability, whereas the same bug reachable indata-encodingis.
Click Report a vulnerability from the Security Advisories page. You can expect an acknowledgment within 24 hours and triage assessment within 7 days. If the vulnerability is accepted, we will work with you for a patch release.
Do not report security vulnerabilities through public GitHub issues or pull requests.