# rustc-1.98.1 1.98.1

Empowering everyone to build reliable and efficient software.

Snapshot of gominimal/pkgs commit `901d8f160f8206e06c5066da5f443ca281a31164` (pushed 2026-10-10T00:25:31.000Z).

## Install

```sh
min add rustc-1.98.1
```

## Direct advisories

None at this commit.

## Transitive advisories

14 advisories inherited through runtime dependencies:

- CVE-2026-35189 (MEDIUM) via openssl
- CVE-2026-35191 (LOW) via openssl
- CVE-2026-42772 (MEDIUM) via openssl
- CVE-2026-54872 (LOW) via openssl
- CVE-2026-54873 (HIGH) via openssl
- CVE-2026-54875 (LOW) via openssl
- CVE-2026-72897 (HIGH) via openssl
- CVE-2026-75804 (MEDIUM) via openssl
- CVE-2026-75805 (MEDIUM) via openssl
- CVE-2026-75806 (MEDIUM) via openssl
- CVE-2026-77696 (LOW) via openssl
- CVE-2026-84782 (HIGH) via openssl
- CVE-2026-84784 (HIGH) via openssl
- CVE-2026-50813 (MEDIUM) via sqlite

## Dependencies

- Build (8): rustc-1.97.1, base, cmake, curl, libssh2, pkgconf, python, toolchain
- Runtime (5): libffi, llvm, openssl, sqlite, gcc

## OpenSSF Scorecard

Aggregate score: 7.1 / 10. Scored by OpenSSF Scorecard. Repository scored: rust-lang/rust. Scanned 2026-10-05.

Result on OpenSSF's viewer: https://scorecard.dev/viewer/?uri=github.com/rust-lang/rust

Checks, scored 0-10 as the Scorecard tool reports them (N/A: not applicable or inconclusive):

| Check | Score | Reason |
| --- | --- | --- |
| [Binary-Artifacts](https://minimal.dev/docs/reference/scorecard#check-binary-artifacts) | 9 | Binaries present in source code |
| [Branch-Protection](https://minimal.dev/docs/reference/scorecard#check-branch-protection) | 5 | Branch protection is not maximal on development and all release branches |
| [CII-Best-Practices](https://minimal.dev/docs/reference/scorecard#check-cii-best-practices) | 0 | No effort to earn an OpenSSF best practices badge detected |
| [Code-Review](https://minimal.dev/docs/reference/scorecard#check-code-review) | 10 | All changesets reviewed |
| [Dangerous-Workflow](https://minimal.dev/docs/reference/scorecard#check-dangerous-workflow) | 10 | No dangerous workflow patterns detected |
| [Fuzzing](https://minimal.dev/docs/reference/scorecard#check-fuzzing) | 10 | Project is fuzzed |
| [License](https://minimal.dev/docs/reference/scorecard#check-license) | 10 | License file detected |
| [Maintained](https://minimal.dev/docs/reference/scorecard#check-maintained) | 10 | 30 commit(s) and 18 issue activity found in the last 90 days -- score normalized to 10 |
| [Packaging](https://minimal.dev/docs/reference/scorecard#check-packaging) | N/A | Packaging workflow not detected |
| [Pinned-Dependencies](https://minimal.dev/docs/reference/scorecard#check-pinned-dependencies) | N/A | Could not be evaluated |
| [SAST](https://minimal.dev/docs/reference/scorecard#check-sast) | 0 | SAST tool is not run on all commits -- score normalized to 0 |
| [Security-Policy](https://minimal.dev/docs/reference/scorecard#check-security-policy) | 10 | Security policy file detected |
| [Signed-Releases](https://minimal.dev/docs/reference/scorecard#check-signed-releases) | N/A | No releases found |
| [Token-Permissions](https://minimal.dev/docs/reference/scorecard#check-token-permissions) | 0 | Detected GitHub workflow tokens with excessive permissions |

## Links

- Homepage: https://www.rust-lang.org
- Package page (HTML): https://minimal.dev/pkgs/rustc-1.98.1
- JSON API (floats latest): https://minimal.dev/api/pkgs/rustc-1.98.1.json
- SBOM (CycloneDX 1.5): https://minimal.dev/api/pkgs/rustc-1.98.1/sbom.json
- Build attestations (JSON): https://minimal.dev/api/pkgs/rustc-1.98.1/attestation.json
