Check Rust dependencies for known security advisories. Start in your browser with one Cargo.lock, or use the Windows desktop app and CLI for local workspace scans.
Open the public scanner | Download the Windows app | Documentation
The stable 1.0.0 release provides separate Windows x64, ready-to-serve browser and source ZIPs. Use the Windows archive to open Start Scanner.bat, the browser archive for a local HTTP preview, and the source archive to change or build the tools. Each contains a matching RELEASE.json; the release includes SHA256 checksums.
- Open the public scanner.
- Choose your project's
Cargo.lock, up to 1 MiB. - Select Scan dependencies.
- Review each advisory's What to do next panel, affected versions, source evidence and recorded dependency paths.
- Use Copy issue summary for the filtered view, or export complete JSON or HTML reports.
The repository includes a small deliberately vulnerable example lockfile for trying the interface. It is scan data; the scanner does not install or execute it. Its time 0.1.43 advisory is RUSTSEC-2020-0071. Set the version to 0.2.23 in a disposable copy to try the corresponding patched control.
See the browser quick start and troubleshooting for a walkthrough and help with incomplete scans.
Scanning runs on your device with WebAssembly. The browser downloads public advisory data; your lockfile and dependency names are not uploaded. No account, repository access or target code execution is needed.
A Rust source file or Cargo.toml alone does not establish exact dependency versions. Use Cargo.lock. This is known dependency advisory matching, not a source code audit or proof of exploitability.
Download the latest portable ZIP, extract the entire archive into a writable folder, then open Start Scanner.bat. The current desktop release is v1.0.0. It bundles the scanner and cargo-audit, so Rust and Cargo are not required for the portable edition. Windows PowerShell 5.1 and Windows Forms are required; the application is unsigned.
See the desktop and CLI guide for setup, build commands, workspace context, reports and limitations.
The CLI scans a local project and can write reports for scripts or CI. Follow the CLI setup and examples. The portable Windows package includes its tools; building from source requires a Rust toolchain. Use --skip-deny for an audit-only scan and read the documented exit codes rather than treating every nonzero exit as a crash.
| Capability | Public browser scanner | Windows desktop | CLI |
|---|---|---|---|
| Input | One Cargo.lock | Local workspace or Cargo.lock | Directory, Cargo.toml or Cargo.lock |
| Advisory sources | RustSec plus supported GitHub-reviewed crates.io advisories via OSV | cargo-audit / RustSec; optional cargo-deny in source edition | cargo-audit; optional cargo-deny |
| Processing | On your device in a browser worker | Local processes | Local processes |
| Dependency context | Bounded recorded lockfile relationships | Lockfile relationships and supported manifest/workspace declarations | Same core context in JSON and HTML |
| Search and filters | Yes | Yes | Read exported reports |
| Exports | Grouped JSON and HTML | JSON, HTML, CSV and desktop enrichment companions | JSON, HTML and CSV |
| Scan comparison | Previous successful scan in this tab | Saved report comparison | No built-in comparison UI |
| CISA KEV indicators | Not implemented | Available with explicit freshness and unknown states | Not enriched by the CLI |
| Automatic dependency changes | Never | Copyable suggestions only | Never |
The separate Docker web preview is a local development implementation, not the public site's architecture. It sends a lockfile to a local Node server and Docker worker. Do not assume the browser site's privacy or deployment model applies to it.
For the public browser scanner, one linked advisory appears once. All affected packages and installed versions stay inside that result.
- Reported IDs and transitive aliases link RustSec, CVE and GHSA records. Titles are not used to guess equivalence.
- Repeated source records do not add vulnerabilities. Duplicate identity/package/version entries are merged.
- One vulnerability affecting two installed versions counts as one vulnerability group and two affected package versions, not two vulnerabilities.
- Advisory warnings are separate from vulnerability totals. Conflicting source evidence requires review and does not carry combined patch advice.
- Version pagination and shortened copied summaries do not change counts. Full JSON and HTML exports retain every result and affected version.
Browser JSON uses schema_version: 3 and format: "grouped-advisories". Results are in top-level findings and warnings; affected versions are nested in affected_packages. The CLI's per-tool schema and desktop report formats are separate. See browser counting and export details.
Identity linkage depends on upstream identifiers. Missing aliases can prevent a match; the scanner does not hide potentially distinct vulnerabilities based on similar wording. No findings does not mean a project is secure.
The browser combines RustSec with supported GitHub-reviewed crates.io records from OSV. Withdrawn, unreviewed and unsupported supplementary records are excluded and counted. Coverage metadata and source disagreements remain visible.
The public advisory service refreshes every six hours without redeploying the website. The scanner verifies snapshot hashes, labels live/cached/bundled data, and refuses data not verified within 14 days. Missing supplementary data is labeled RustSec-only, not full combined coverage.
Git, path and other registry packages are outside the browser's crates.io advisory matching scope and are counted as skipped. Lockfile relationships do not establish active features, targets, workspace ownership, runtime reachability or exploitability. See browser scope and service operations.
Read the October 7 release checks for the paired source/browser/Windows packages, actual worker scans, data failure and recovery, real downloads, portable desktop/CLI checks and extracted source builds. The October 2 verification retains the earlier public Chrome/Edge, Windows v0.5.0 and Docker preview results.
Read the dated browser quality audit for the 2026-09-16 checks: generated overlap cases, vulnerable/patched advisory controls, pinned public-project lockfiles and large-result tests. It records the measurement conditions and limitations rather than making a universal accuracy or performance claim.
The permanent browser quality suite checks 400 generated overlap cases, patch-range ordering, pagination and complete exports with a synthetic 5,000-version result. Additional result and action guidance tests cover alias linkage, warning counts, conflicting patch evidence, filtering and escaped output. Rust integration tests exercise lockfile formats, malformed inputs, exact resource limits and bounded graph traversal. GitHub Actions also checks browser dependency tracing, advisory refreshes, Rust builds and tests, and the Windows package. Use the workflow links above for current status.
Older benchmark and validation documents are retained as historical evidence, not current health indicators. The documentation index separates current guides from dated evidence.
- Build the browser scanner.
- Build and run the CLI or Windows desktop.
- Contribute and run focused checks.
- Report a scanner security problem.
- Open a regular bug report.
For coordinated packaging, follow the release build guide. Keep older downloaded packages and private reports while testing an upgrade; extract a new Windows release into a new writable folder.
Do not attach private lockfiles, credentials or sensitive scan reports to public issues. Deliberately vulnerable test fixtures are scanner inputs, not dependencies of this application.
MIT licensed. See LICENSE and third-party notices. Advisory data and bundled components retain their upstream licenses and attribution.