GHSA-f8h5-x737-x4xr: `finch-rust` was removed from crates.io for malicious code
It depended on the sha-rust crate, which appeared to be attempting to steal credentials from local files.
References
Code Behaviors & Features
Detect and mitigate GHSA-f8h5-x737-x4xr with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →