V OpenVet
Packages Docs Blog Sign in
cargo / allocator-api2

allocator-api2

cargo

Mirror of Rust's allocator API

1 audit github.com/zakarumych/allocator-api2

Audits

PE Patrick Elsen 2026-05-27

allocator-api2@0.2.21 · 3 findings

Stable-Rust polyfill for unstable allocator_api: near-verbatim ports of std's Box/Vec/RawVec parameterised over Allocator. Three quality findings: medium (no active tests in the published crate despite extensive unsafe and a documented past Box::into_inner double-free fix), and two lows (empty CHANGELOG placeholder, published archive uses CRLF/CR while upstream uses LF — content byte-identical after normalisation).

datastructure-impl-boundsdatastructure-impl-correctdatastructure-impl-safedatastructure-impl-testedhas-binarieshas-build-exechas-fuzz-testshas-install-exechas-integration-testshas-property-testshas-unit-testsimpl-algorithmimpl-concurrencyimpl-cryptoimpl-datastructureimpl-interpreterimpl-jitimpl-parserimpl-protocolis-benignunsafe-documentedunsafe-minimalunsafe-safeunsafe-testeduses-concurrencyuses-cryptouses-environmentuses-execuses-filesystemuses-interpreteruses-jituses-networkuses-unsafe

Package facts

Registry
cargo
Repository
github.com/zakarumych/allocator-api2
Homepage
github.com/zakarumych/allocator-api2
V openvet · supply-chain audits · open source
CLI Source