Repository navigation
Releases: agammann/rust-cve-sniffer
Release list
Rust CVE Sniffer 1.0.0
The browser and portable Windows editions have a shared stable release with separate input, coverage and report formats. The Windows archive includes its linked user guides, browser downloads include ready-to-serve WebAssembly and a dated RustSec fallback, and source builds use the caller's configured Rust toolchain.
Versioned source, browser and Windows archives identify their source revision and compiled components. Release checks exercise advisory controls, malformed inputs, cancellation, exported reports and delivered source builds before publication.
Invalid CLI options now return error exit code 1; help and version still return 0. Exit code 2 stays reserved for a completed scan with known vulnerability findings.
The public advisory service continues to update separately from website code. Its live combined RustSec/OSV coverage and the bundled RustSec fallback are labeled separately.
Download the Windows x64 ZIP, extract the complete archive into a writable folder and open Start Scanner.bat. Rust and Cargo are not required for the portable edition. The browser ZIP includes ready-to-serve assets; serve it over localhost HTTP. Advisory updates need a network connection and stale data is labeled or rejected as documented. The matching source ZIP includes build instructions and release manifests. Compare SHA256SUMS before extraction.
Rust CVE Sniffer 0.5.0
Windows x64 portable release, now MIT licensed. Download the ZIP, extract the entire folder, and open Start Scanner.bat. The default scanner does not require Rust or Cargo.
New in 0.5.0
- Dependency parents and example chains in JSON, HTML and desktop finding details.
- Declared workspace member recognition with manifest provenance and member-specific direct or transitive paths.
- Bounded discovery, conservative exclusions and explicit unknowns for unsupported or ambiguous context.
- Reliable PowerShell module loading, native process output handling, deadlines and argument quoting.
- Improved finding label visibility and a maintained full validation command.
- MIT source license, included in the portable ZIP. Third party components retain their own licenses.
Verification
Local release acceptance passed: 51 Rust tests, 6 runtime regressions, 32 desktop insight checks, 22 real advisory benchmark cases with CISA evidence, portable desktop workflows, pinned bat/uv/starship scans, and the real uv workspace. The workspace check recognizes 70 included members from 71 downloaded manifests and independently tests excluded locked packages. Target files remain unchanged and target application code is not executed.
Exact release commit: 0ecdb89
Linux and Windows commit workflow
Limits
The Windows executable is unsigned. Dependency and declared-member context is not full Cargo resolution or proof of runtime exploitability. Active features, platform applicability, automatic path-dependency membership and external workspace members are not established. CISA evidence concerns the CVE, not exploitation of the scanned application.
ZIP SHA256: 961eee08b0d0536fcad00d91a5e74d336131e52f5fa0de79c7b55fd1045f51bb
Rust CVE Sniffer 0.4.0
Windows x64 portable release. Download the ZIP, extract the entire folder, and double click Start Scanner.bat. The default scanner does not require Rust or Cargo.
New in 0.4.0:
- Actionable finding details and copyable Cargo update suggestions, starting with a dry run. Commands are never executed automatically.
- CISA KEV indicators with saved catalog provenance and explicit unknown, cached and stale states.
- Saved scan comparisons with scope and database change warnings. No longer detected does not prove a fix.
- Coverage details and enriched HTML companions, preserving original JSON and CSV reports.
Fixed the stale primary source failure message after successful fallback, stale finding details after filtering, and validation of saved CISA snapshots.
Local verification passed: 14 Rust tests, 32 desktop insight regression checks, all 22 CVE benchmark cases, portable clean/vulnerable scans, search, saved reports, cancellation, and a live WebP CVE-2023-4863 CISA match. Feed failure branches use deterministic fixtures; live evidence is recorded separately.
Public workflow: https://github.com/agammann/rust-cve-sniffer/actions/runs/34734340713
Versioned benchmark evidence: https://github.com/agammann/rust-cve-sniffer/tree/v0.4.0/validation/v0.4.0
The app is unsigned. It checks known dependency advisories, not application source security or runtime exploitability. Snapshot hashes are not digital signatures. Optional cargo-deny requires Cargo and the source edition.
ZIP SHA256: beb9985ca43b11298b944c03e6f4c0146ab4fe5a9e5899fa06b515a3f3d04c71
Rust CVE Sniffer 0.3.0
A portable Windows x64 scanner for known vulnerabilities in Rust dependencies.
Download the ZIP below, extract the entire folder, and double click Start Scanner.bat. The default scan does not require Rust or Cargo.
Includes searchable findings, CVE aliases, published patch ranges, impact details, saved reports, HTML/JSON/CSV exports, and cancellation.
Verified locally: 14 Rust tests, optimized build, clean and deliberately vulnerable scans, unchanged target lockfiles, desktop search/report/cancellation flows, and execution without Cargo in PATH.
The application is unsigned. It scans known dependency advisories from Cargo.lock; it does not audit application source code. cargo-deny is available in the source edition and requires Cargo.
ZIP SHA256: e9fe18ca21af91eaac6c4fe090d1339c9f4f0316c657344463fab25ad43878c3