| FazBrowse GitHub Viewer | Trending | | Home |
| Tools: [Download Repo ZIP] [Original HTTPS Page] |
We actively support the following versions with security updates:
| Version | Supported | MSRV | Status |
|---|---|---|---|
| 0.24.x | ✅ | 1.90 | Active |
| 0.23.x | ❌ | 1.90 | Deprecated |
| < 0.23 | ❌ | 1.70+ | Deprecated |
Security patches are released as patch versions (e.g., 0.24.19 → 0.24.20) for the actively supported version line.
We take security vulnerabilities seriously. If you discover a security issue in masterror, please report it responsibly.
When using masterror in production:
cargo install cargo-audit
cargo audituse masterror::{AppError, field, RedactionPolicy};
let err = AppError::internal("auth failed")
.with_field(field::str_redacted(
"user_email",
email,
RedactionPolicy::Hash
));[dependencies]
masterror = { version = "0.24", features = ["std", "axum"], default-features = false }match db.query().await {
Ok(result) => Ok(result),
Err(e) => {
// Log full error internally
tracing::error!("Database error: {:?}", e);
// Return sanitized error to client
Err(AppError::service("database unavailable"))
}
}Error source chains may contain sensitive information from third-party libraries. Always review what is exposed to end users.
Metadata fields are serialized in responses. Ensure redaction policies are correctly applied before exposing errors via HTTP/gRPC.
Backtraces can reveal internal file paths and stack frames. Disable the backtrace feature in production or implement custom filtering.
Error handling paths should not reveal timing information that could be exploited (e.g., database existence checks via different error latencies). This is application-specific and not handled by masterror.
masterror contains zero unsafe code, eliminating entire classes of memory safety vulnerabilities:
[lints.rust]
unsafe_code = "forbid"All error types implement Send + Sync, ensuring safe concurrent usage without data races.
No security vulnerabilities have been reported to date.
Future disclosures will be listed here with:
Primary contact: andrey.rozanov.vl@gmail.com
PGP key: Available on request for encrypted communication
| Back | FazBrowse Home | New Git URL |