Know whatships with you.
Check your Cargo.lock for known
vulnerabilities. Know what needs attention.
Cargo.lockLOCAL FILE / 01Your lockfile stays on this device. Scanning runs in your browser with RustSec WebAssembly. No project code is executed.
Advisory freshness is checked before every scan. Service status
Choose a file to begin. No account needed.
Know what this scan can tell you.
Known dependency advisories. Not a source code audit or proof of exploitability.
Coverage & privacy, plainly explained
Only the selected lockfile is checked. Manifest and workspace membership, active features, target platforms, CISA exploitation data, and yanked crate checks are not evaluated in this web version. Advisory warnings are shown separately from vulnerabilities.
When available, reviewed GitHub advisories from OSV supplement RustSec. Aliases link overlapping reports; source disagreements are labeled and combined patch advice is withheld. Only supported crates.io version ranges are used. GitHub advisory data is adapted under CC BY 4.0; see source license and attribution. CISA KEV and EPSS are not included.
Each scan requests automatically checked RustSec and supplementary OSV data from this project's public GitHub feed. Its hash and metadata are verified before matching. If the feed is unavailable, a previously verified public snapshot or the bundled snapshot may be used and is clearly labeled. Data not verified within 14 days is rejected. Reports identify the upstream revision and verification time; coverage is never guaranteed.
Your lockfile and dependency list are not uploaded. The browser downloads scanner assets from this site and public advisory data from GitHub. Only public advisory data may be cached on this device, never your lockfile or report. Results stay in this tab unless you download them. This app adds no analytics or scan history; normal hosting access logs may still record page requests. Closing or reloading clears results.
Limits: 1 MiB, 5,000 locked packages, 25,000 dependency edges. Dependency tracing shows up to 20 immediate dependents and 3 example chains, at most 12 edges each. These are recorded lockfile relationships, not runtime call paths. Use the desktop app for richer context.
ResultsRUST DEPENDENCY ADVISORIES
The evidence starts here.
Run a scan to see dependency advisories and patch ranges.- Locked packages
- Unique vulnerability groups
- Distinct advisory warnings
- Scanned at
Turn findings into next steps.
Each linked advisory appears once, with affected versions inside it. Filter the current scan and review advisories by package. Published patch ranges are not a compatibility guarantee.
Copies the filtered view, up to 100 unique advisory results. JSON and HTML exports always include the full report. Nothing is posted automatically.
Issue summary text
Snapshot, input fingerprint & scan coverage
Compared with your previous scan
This compares advisory and package identities across selected files. They may be different projects. No longer detected does not prove a fix. A changed advisory snapshot can change results.