A Rust implementation of an async TAR file reader and writer. This library does not currently handle compression, but it is abstract over all I/O readers and writers. Additionally, great lengths are taken to ensure that the entire contents are never required to be entirely resident in memory all at once.
[email protected] has vulnerabilities — update to latest
Update to >= 0.5.6 to fix known vulnerabilities
| Severity | ID | Summary | Fixed in |
|---|---|---|---|
| high | CVE-2025-62518 | astral-tokio-tar Vulnerable to PAX Header Desynchronization | 0.5.6 |
| unknown | CVE-2025-62518 | `tokio-tar` parses PAX extended headers incorrectly, allows file smuggling | — |
Get this data programmatically — free, no authentication.
curl https://depscope.dev/api/check/cargo/tokio-tarFirst published · 2020-01-09T17:53:46.412863Z
Last updated · 2023-07-14T21:02:27.805709Z