{"package":"rand_core","ecosystem":"cargo","latest_version":"0.1.1","description":"Core random number generator traits and tools for implementation.\n","license":"MIT/Apache-2.0","license_risk":"permissive","commercial_use_notes":"Permissive: commercial closed-source use OK; preserve the copyright notice.","homepage":"https://crates.io/crates/rand_core","repository":"https://github.com/rust-lang-nursery/rand","downloads_weekly":440566830,"health":{"score":40,"risk":"high","breakdown":{"maintenance":25,"popularity":20,"security":15,"maturity":12,"community":0,"popularity_floor":0},"deprecated":false,"max_score":100},"vulnerabilities":{"count":1,"critical":1,"high":0,"medium":0,"low":0,"details":[{"vuln_id":"CVE-2020-25576","severity":"critical","summary":"Unaligned memory access in rand_core","affected_versions":">=0.4.0,<0.4.2|<0.3.1","fixed_version":"0.3.1","source":"osv","published_at":"2021-08-25T20:56:50Z"}]},"versions":{"latest":"0.1.1","total_count":42,"recent":["0.1.1","0.2.3","0.3.2","0.4.3","0.10.1","0.10.0","0.10.0-rc-6","0.10.0-rc-5","0.10.0-rc-4","0.9.5","0.9.4","0.10.0-rc-3","0.10.0-rc-2","0.10.0-rc-1","0.9.3","0.9.2","0.9.1","0.9.0","0.9.0-beta.1","0.9.0-beta.0"]},"metadata":{"deprecated":false,"deprecated_message":null,"maintainers_count":0,"first_published":"2017-09-14T12:02:18.709038Z","last_published":"2026-09-02T08:19:33.285884Z","dependencies_count":0,"dependencies":[]},"github_stats":null,"bundle":null,"typescript":null,"known_issues":{"bugs_count":4,"bugs_severity":{"medium":2,"critical":2},"status_breakdown":{"fixed":4},"link":"/api/bugs/cargo/rand_core","scope":"all","details":[{"title":"Incorrect check on buffer length when seeding RNGs","severity":"medium","status":"fixed","affected_version":"0.6.0","fixed_version":"0.6.2","url":"https://crates.io/crates/rand_core"},{"title":"Unaligned memory access","severity":"medium","status":"fixed","affected_version":"0.4.0-0","fixed_version":"0.4.2","url":"https://crates.io/crates/rand_core"},{"title":"Incorrect check on buffer length in rand_core","severity":"critical","status":"fixed","affected_version":"0.6.0","fixed_version":"0.6.2","url":"https://nvd.nist.gov/vuln/detail/CVE-2021-27378"},{"title":"Unaligned memory access in rand_core","severity":"critical","status":"fixed","affected_version":"0.4.0","fixed_version":"0.4.2","url":"https://github.com/rust-random/rand/security/advisories/GHSA-mmc9-pwm7-qj5w"}]},"historical_compromise":null,"recommendation":{"action":"do_not_use","issues":["Moderate health score (40/100) — verify manually","1 critical vulnerabilities"],"use_version":"0.1.1","version_hint":"Update to >= 0.3.1 to fix known vulnerabilities","summary":"rand_core has critical vulnerabilities — do not use","alternatives":[{"name":"rand","reason":"Full rand crate re-exports rand_core","builtin":false}]},"version_scoped":null,"_meta":{"endpoint":"check","tier":"full","philosophy":"DepScope is free. Use the cheapest endpoint that answers your real question.","cheaper_alternatives":[{"endpoint":"/api/exists/cargo/rand_core","tokens_estimated":12,"use_when":"you only need to know if the package exists (hallucination guard)"},{"endpoint":"/api/health/cargo/rand_core","tokens_estimated":80,"use_when":"you only need a 0-100 score for go/no-go (>=70 = safe)"},{"endpoint":"/api/prompt/cargo/rand_core","tokens_estimated":280,"use_when":"you want a plain-text LLM-friendly brief instead of JSON"},{"endpoint":"POST /api/check_bulk","tokens_estimated":60,"use_when":"you have 5+ packages to check; sends one round-trip instead of N"}],"docs":"https://depscope.dev/integrate"},"_cache":"hit","_response_ms":0}