Files
advisory-db/crates/cargo-download/RUSTSEC-2021-0133.md
2021-12-25 19:20:22 +01:00

525 B

[advisory]
id = "RUSTSEC-2021-0133"
package = "cargo-download"
date = "2021-12-25"
url = "https://github.com/Xion/cargo-download"
informational = "unmaintained"
[versions]
patched = []

cargo-download is unmaintained

The cargo download subcommand (via cargo-download crate) is broken and maintainer has disappeared from GitHub and hasn't had any commits for a year.

Using this downloader will result to corrupted crates.

Maintainer has not responded to maintenance takeover.

Just use wget / curl directly.