-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathCargo.toml
More file actions
219 lines (203 loc) · 9.05 KB
/
Copy pathCargo.toml
File metadata and controls
219 lines (203 loc) · 9.05 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
[package]
name = "uphold"
version = "1.23.0"
edition = "2024"
# 1.90, and the floor is set by what the tree embeds rather than by taste: the
# ripgrep stack -- globset 0.4.20 and ignore 0.4.33 in Cargo.lock -- refuses
# anything older than 1.88, and tree-sitter 0.27 with tree-sitter-language 0.1.8
# refuses anything older than 1.90. Nothing builds the crate on this version:
# rust-toolchain.toml puts every build on `stable`, and what this number does is
# drive cargo's MSRV-aware dependency resolution, so a bump that needs a newer
# compiler is refused at resolve time rather than found by a reader on the
# older one. Raising it means raising toolchain.toml's rustc `want` in the same
# commit -- tests/test_toolchain.py refuses the tree where only one moved.
rust-version = "1.90"
description = "One binary for the engineering principles catalog and the rules that enforce it"
license = "Apache-2.0"
repository = "https://github.com/HackingGate/uphold"
readme = "README.md"
keywords = ["lint", "policy", "git-hooks", "pre-commit", "governance"]
categories = ["command-line-utilities", "development-tools"]
[[bin]]
name = "uphold"
path = "src/main.rs"
[dependencies]
# ripgrep's own search stack. The point of embedding these rather than shelling
# out to `rg` is that a pattern written for the old hook has to keep meaning what
# it meant: same regex engine, same multiline handling, same glob semantics.
grep-matcher = "0.1"
grep-regex = "0.1"
grep-searcher = "0.1"
globset = "0.4"
ignore = "0.4"
regex = "1"
serde = { version = "1", features = ["derive"] }
toml = "1"
# Already in the tree under tree-sitter, so this is a name for something the
# build already compiles rather than a new dependency. It is here because
# `rules --set --json` has to emit the WHOLE of a rule -- a set ships compiled
# in, and a regex that changed between two versions with no diff in any
# consuming tree is the risk that output exists to close. A hand-rolled writer
# naming the fields it knows about is a list that drifts from the struct, which
# is the failure the schema collapse in this file was about.
serde_json = "1"
# The Unicode Script property, which the Python engine could not read and
# approximated by matching tokens in character names.
unicode-script = "0.5"
# The character NAME, which is the only part of this report a reader can act on.
# A homoglyph finding shows a letter that looks exactly like the Latin one it
# replaced, so printing the character is no help at all and "CYRILLIC SMALL
# LETTER EN" is the whole answer.
unicode_names2 = "4.0"
# The WHATWG encoding registry, which is what an `encoding` rule's label
# resolves through: "Shift_JIS" here means what it means to every browser, and
# a hand-enumerated subset of the registry would be the failure
# `parameterize-do-not-enumerate` names.
encoding_rs = "0.8"
# The YAML reader, for hook configurations and the YAML arm of the anchor
# check. serde_yaml was archived in 2024 and every fork of it carries the same
# libyaml port; this is the maintained parser with a stable major. It has no
# value type of its own, so a document with no fixed shape is read into
# `serde_json::Value`, which is already the model the anchor check reads every
# format into. A `<<` merge key expands, as it does under the YAML readers
# pre-commit and lefthook use, and a duplicate key is refused rather than
# silently resolved to whichever copy came last.
serde-saphyr = "1.3"
# A parser, for the one question a regex over file contents cannot answer:
# whether the text it matched is a comment. `grep-regex` reads bytes, so
# `let s = "// TODO";` is a hit and a rule about comments is a rule about
# anything that spells one. These give the comment its own node kind -- and
# `///` a different kind from `//`, which is the distinction a line-prefix test
# gets wrong by construction: `///` starts with `//`.
tree-sitter = "0.27"
tree-sitter-rust = "0.24"
tree-sitter-python = "0.25"
# The grammar the doc-command resolver needs, and the one language whose
# dispatch this was measured against. Its star count reads marginal and
# mismeasures it: nobody stars a grammar, and it carries 11.2M downloads with
# 4.7M in the last ninety days. It is read by the comment checks too, and that
# is the argument for adding a language rather than a second reason to have one:
# Go joined `comment_regexp`, `trivial_comments` and `prose_regexp` at the cost
# of three lines, because the dependency was already here.
tree-sitter-go = "0.25"
# The word splitter for an alias's expansion. git splits `alias.cm = commit -m
# "a b"` the way a shell would, quotes and backslashes included, so a reader
# that splits on whitespace hands the push scan `"a` and `b"` and shifts every
# positional word after them. Where this reader and git's `split_cmdline`
# disagree, `expand_alias` says which case and how it is closed.
shell-words = "1"
# `strip` is deliberately absent: stripping is a packaging step, and a stripped
# binary with no build-id cannot be symbolicated from a core. `debug = 1` keeps
# the line tables so a crash names the line it happened on.
[profile.release]
lto = "fat"
codegen-units = 1
panic = "abort"
debug = 1
# Read by `cargo kani` and by nothing else. One harness replaces
# `config::load` with a loader that always fails, and replacing a function is
# still an unstable Kani feature; declared here so the bare `cargo kani` that
# CONTRIBUTING, the manual hook and CI run is the same command.
[package.metadata.kani.unstable]
stubbing = true
# The profile `dist` builds the release artifacts with. It adds nothing to
# `release`: the shipped binary is the one `cargo build --release` produces.
[profile.dist]
inherits = "release"
# The same lint profile the sibling crates run under. A repository whose
# whole job is enforcing engineering rules should not hold its own Rust to a
# looser standard than the projects it gates.
[lints.rust]
warnings = "deny"
# `cfg(kani)` is set by the model checker and by nothing else, so an ordinary
# build has to be told the name exists before it will accept a module gated on
# it. Declared here rather than allowed at the module, which would switch the
# lint off for every other misspelling in the same file.
unexpected_cfgs = { level = "deny", check-cfg = ['cfg(kani)'] }
# Safety
unsafe_code = "deny"
# Logic & Idioms (Hardened)
missing_debug_implementations = "deny"
missing_copy_implementations = "deny"
unused_qualifications = "deny"
unused_lifetimes = "deny"
unused_import_braces = "deny"
trivial_casts = "deny"
trivial_numeric_casts = "deny"
noop_method_call = "deny"
single_use_lifetimes = "deny"
variant_size_differences = "deny"
absolute_paths_not_starting_with_crate = "deny"
elided_lifetimes_in_paths = "deny"
explicit_outlives_requirements = "deny"
meta_variable_misuse = "deny"
unreachable_pub = "deny"
missing_abi = "deny"
macro_use_extern_crate = "deny"
[lints.clippy]
# 1. The Basics
pedantic = { level = "deny", priority = -1 }
nursery = { level = "deny", priority = -1 }
cargo = { level = "deny", priority = -1 }
# 2. Ban Panics
unwrap_used = "deny"
expect_used = "deny"
indexing_slicing = "deny"
panic = "deny"
todo = "deny"
unimplemented = "deny"
panic_in_result_fn = "deny"
# 3. Numeric Rigor
cast_possible_truncation = "deny"
cast_precision_loss = "deny"
cast_sign_loss = "deny"
float_arithmetic = "deny"
lossy_float_literal = "deny"
# 4. Code Hygiene
# `allow_attributes` is what makes the rest of this list self-maintaining:
# `#[expect]` fails the build once the lint it suppresses stops firing, so a
# suppression that has outlived its cause is reported rather than audited.
allow_attributes = "deny"
shadow_unrelated = "deny"
wildcard_imports = "deny"
let_underscore_must_use = "deny"
ptr_as_ptr = "deny"
borrow_as_ptr = "deny"
case_sensitive_file_extension_comparisons = "deny"
# 5. Performance & Explicit Allocations
str_to_string = "deny"
string_add = "deny"
format_push_string = "deny"
inefficient_to_string = "deny"
# 6. Documentation & Attributes
allow_attributes_without_reason = "deny"
dbg_macro = "deny"
empty_structs_with_brackets = "deny"
empty_drop = "deny"
get_unwrap = "deny"
rc_buffer = "deny"
rc_mutex = "deny"
rest_pat_in_fully_bound_structs = "deny"
same_name_method = "deny"
tests_outside_test_module = "deny"
undocumented_unsafe_blocks = "allow"
unnecessary_self_imports = "deny"
unneeded_field_pattern = "deny"
verbose_file_reads = "deny"
struct_excessive_bools = "deny"
too_many_lines = "deny"
doc_markdown = "deny"
collapsible_if = "deny"
redundant_closure_for_method_calls = "deny"
# 7. Exceptions
module_name_repetitions = "allow" # guard::guard, scan::scan read fine here
missing_errors_doc = "allow" # binary crate, not a published API
multiple_crate_versions = "allow" # ripgrep stack pulls duplicate transitives
missing_panics_doc = "allow" # no panics allowed anyway
bool_assert_comparison = "allow" # tests
# Every guard and every shim collector is reached through ONE signature, from a
# match on the built-in's name or on `collect`. An arm that cannot fail today
# still returns `Result`, because dropping the wrapper makes the table
# inconsistent and turns the next "this can fail now" into a much bigger diff
# than the change deserves.
unnecessary_wraps = "allow"