Cryptographically verifiable, distributed dependency reviews
reviewer: kornelski
$ cargo crev repo fetch url https://github.com/kornelski/crev-proofs
$ cargo crev id trust X98FCpyv5I7z-xv4u-xMWLsFgb_Y0cG7p5xNFHSjbLA
repo: https://github.com/kornelski/crev-proofs
Please, use mobile in landscape.
Data race in unsafe code
Dead
A lot of unsafe code
it's fine, but c2rust does it better
unmaintained
Clever
Contains unsafe transmutes that seem unnecessary
big macros + transmute
May mangle UNC paths
It works fine, but the project is totally unmaintained.
Completely unfinished, doesn't do anything
Full of transmute. This is playing with fire
For AV1 only, but who'd want any other codec, right?
lots of raw pointer manipulation and use of mem::uninitialized()
Fallible feature is unsound. The rest looks ok.
It's coupled with a really awful HTTP client for no reason. I'd expect it to bundle the data, or at least just do the file parsing, and delegate networking to a separate crate.
Fixed soundness of as_bytes
Fixed soundness of ComponentBytes
The algorithm is very fast at finding things. It's not as fast at not finding matches.
© bestia.dev 2023, MIT License, Version: 2023.608.1636
Open source repository for this web app: https://github.com/bestia-dev/cargo_crev_web/