Dependency health Workspace

zstd-safecrates.io

Vulnerabilities, end of life and next steps

Check a specific version for known advisories, documented mitigations and evidence-backed earlier-version options. Maintenance health is separate from vulnerability status.

Review remediation options →

Came back

After 18 months without a release, zstd-safe published 8.0.0 on 2026-09-04.

Usually this is a maintainer returning. It is also what a hijacked package looks like, so it is worth a glance at what changed before you upgrade.

What the project says about itself
  • OpenSSF Scorecard4.7 / 10 on 2026-08-17. Source: OpenSSF, via deps.dev. A third party's view of security practice, not part of the health score.

Third-party facts checked today; registry facts on every crawl.

State history 1
WhenChange
2026-09-05 first verdict: active
Licence history 1
WhenChangeSeverity
2026-09-05 MIT OR Apache-2.0 → BSD-3-Clause (8.0.0) info

Badge

maintenance: active

Drop this in your README. It re-renders itself as the verdict changes.

[![maintenance](https://isitdeadyet.dev/badge/crates/zstd-safe.svg)](https://isitdeadyet.dev/crates/zstd-safe)

Watch it

Get told when zstd-safe changes state, changes licence, or is deprecated — instead of finding out during an incident.

Free for up to 25 packages. Signing in is a link sent to your email — there is no password to choose.