cargo / bit-set

bit-set

cargo

A set of bits

Audits

PE Patrick Elsen 2026-05-27

bit-set@0.8.0 · 3 findings

bit-set 0.8.0 is a #![no_std] integer-set data structure built on top of bit-vec. Two unsafe blocks (storage_mut+index, set_len after truncating zero blocks); CI runs Miri with strict provenance. Three low-severity quality findings: missing SAFETY comments, stale RELEASES.md, and no property/fuzz tests.

datastructure-impl-boundsdatastructure-impl-correctdatastructure-impl-safedatastructure-impl-testedhas-binarieshas-build-exechas-fuzz-testshas-install-exechas-integration-testshas-property-testshas-unit-testsimpl-algorithmimpl-concurrencyimpl-cryptoimpl-datastructureimpl-interpreterimpl-jitimpl-parserimpl-protocolis-benignunsafe-documentedunsafe-minimalunsafe-safeunsafe-testeduses-concurrencyuses-cryptouses-environmentuses-execuses-filesystemuses-interpreteruses-jituses-networkuses-unsafe
PE Patrick Elsen 2026-05-27

bit-set@0.5.3 · 4 findings

no_std set built on bit-vec; two unsafe call sites to storage_mut/set_len preserve the bit-length-vs-storage-length invariant. Four low-severity quality findings: VCS SHA does not exist upstream, unsafe blocks lack SAFETY comments, no randomized testing, stale README badges and maintenance-mode notice.

datastructure-impl-boundsdatastructure-impl-correctdatastructure-impl-safedatastructure-impl-testedhas-binarieshas-build-exechas-fuzz-testshas-install-exechas-integration-testshas-property-testshas-unit-testsimpl-algorithmimpl-concurrencyimpl-cryptoimpl-datastructureimpl-interpreterimpl-jitimpl-parserimpl-protocolis-benignunsafe-documentedunsafe-minimalunsafe-safeunsafe-testeduses-concurrencyuses-cryptouses-environmentuses-execuses-filesystemuses-interpreteruses-jituses-networkuses-unsafe