{"$schema":"https://docs.oasis-open.org/csaf/csaf/v2.1/schema/csaf.json","document":{"category":"csaf_base","csaf_version":"2.1","distribution":{"tlp":{"label":"CLEAR"}},"lang":"en","notes":[{"category":"summary","text":"Dependency-currency bump of time from 0.3.54 to 0.3.55 in ndaal nvulnlookup 1.2.72. Informational: no security defect is fixed or introduced, and the advisory is scored CVSS v3.1 0.0 (NONE) and CVSS v4.0 0.0 (NONE)."},{"category":"description","text":"time moved 0.3.54 -> 0.3.55 within the existing semantic-versioning requirement in the workspace manifest — no manifest requirement changed, only the locked version. The bump arrived via `cargo update`, which relocked 142 packages to their latest semver-compatible releases. This advisory records the time move specifically so the CSAF feed carries a per-crate history rather than only a bulk entry."},{"category":"details","text":"Verified before publication: `cargo check --workspace --all-features` exits 0 against the relocked tree. time is a DIRECT workspace dependency, which is why it is documented individually; the 117 transitive moves in the same relock are recorded together in the companion bulk advisory."},{"category":"general","text":"Recommended action: none required for security. Operators building from source will pick up 0.3.55 automatically from the committed Cargo.lock."},{"category":"other","text":"CVSS applicability: a dependency-currency bump with no security impact, scored CVSS v3.1 0.0 (NONE) and CVSS v4.0 0.0 (NONE) with every impact metric NONE. The score is intentionally zero to signal 'informational, no vulnerability' while still carrying a machine-readable metric. Status: final."},{"category":"legal_disclaimer","text":"THIS DOCUMENT IS PROVIDED ON AN 'AS IS' BASIS AND DOES NOT IMPLY ANY KIND OF GUARANTEE OR WARRANTY. ndaal Gesellschaft fuer Sicherheit in der Informationstechnik mbH & Co KG DISCLAIMS ALL WARRANTIES WITH REGARD TO THIS INFORMATION INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS."}],"publisher":{"category":"vendor","contact_details":"security@ndaal.eu","issuing_authority":"ndaal Gesellschaft für Sicherheit in der Informationstechnik mbH & Co KG Security Team","name":"ndaal Gesellschaft für Sicherheit in der Informationstechnik mbH & Co KG","namespace":"https://ndaal.eu/csaf"},"references":[{"category":"self","summary":"This advisory in CSAF 2.1 format","url":"https://gitlab.com/vPierre/ndaal_public_csaf_information/-/raw/main/csaf/2026/624/ndaal-sa-2026-624.json"},{"category":"external","summary":"CHANGELOG 1.2.72","url":"https://gitlab.com/vPierre/ndaal_public_nvulnlookup/-/raw/main/vulnerability-lookup-rs/CHANGELOG.md"},{"category":"external","summary":"nvulnlookup release repository","url":"https://gitlab.com/vPierre/ndaal_public_nvulnlookup_release2/-/tree/main/release"}],"title":"ndaal Informational Advisory: time 0.3.54 -> 0.3.55 dependency-currency bump (nvulnlookup 1.2.72)","tracking":{"current_release_date":"2026-09-16T00:00:00.000Z","generator":{"engine":{"name":"ndaal CSAF Generator","version":"1.0.0"}},"id":"ndaal-sa-2026-624","initial_release_date":"2026-09-16T00:00:00.000Z","revision_history":[{"date":"2026-09-16T00:00:00.000Z","number":"1.0.0","summary":"Initial advisory. Informational, no security impact, CVSS v3.1 0.0 / v4.0 0.0 (NONE). Status: final."}],"status":"final","version":"1.0.0"},"x_extensions":[{"$schema":"https://ndaal.eu/.well-known/csaf/extensions/dashboard-branding_1.0.0.json","category":"informational","content":{"dashboard_short_name":"ndaal","publisher_brand":"ndaal Advisories Database"},"critical":false}]},"product_tree":{"branches":[{"branches":[{"branches":[{"category":"product_version","name":"0.3.55","product":{"name":"time 0.3.55 — dependency-currency bump in nvulnlookup 1.2.72, no security impact.","product_id":"CSAFPID-0001","product_identification_helper":{"purls":["pkg:cargo/time@0.3.55"]}}}],"category":"product_name","name":"time"}],"category":"vendor","name":"ndaal Gesellschaft für Sicherheit in der Informationstechnik mbH & Co KG"}]},"vulnerabilities":[{"flags":[{"label":"vulnerable_code_not_present","product_ids":["CSAFPID-0001"]}],"ids":[{"system_name":"ndaal Advisory ID","text":"ndaal-sa-2026-624"}],"metrics":[{"content":{"cvss_v3":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":0.0,"baseSeverity":"NONE","confidentialityImpact":"NONE","integrityImpact":"NONE","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N","version":"3.1"},"cvss_v4":{"attackComplexity":"LOW","attackRequirements":"NONE","attackVector":"NETWORK","baseScore":0.0,"baseSeverity":"NONE","privilegesRequired":"NONE","subAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","userInteraction":"NONE","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N","version":"4.0","vulnAvailabilityImpact":"NONE","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"NONE"}},"products":["CSAFPID-0001"]}],"notes":[{"category":"description","text":"time moved 0.3.54 -> 0.3.55 within the existing semantic-versioning requirement in the workspace manifest — no manifest requirement changed, only the locked version. The bump arrived via `cargo update`, which relocked 142 packages to their latest semver-compatible releases. This advisory records the time move specifically so the CSAF feed carries a per-crate history rather than only a bulk entry."}],"product_status":{"known_not_affected":["CSAFPID-0001"]},"threats":[{"category":"impact","details":"None. Dependency-currency bump with no security impact (CVSS v3.1 0.0 / v4.0 0.0, NONE).","product_ids":["CSAFPID-0001"]}],"title":"ndaal Informational Advisory: time 0.3.54 -> 0.3.55 dependency-currency bump (nvulnlookup 1.2.72)"}]}