-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathdeny.toml
More file actions
66 lines (62 loc) · 2.91 KB
/
Copy pathdeny.toml
File metadata and controls
66 lines (62 loc) · 2.91 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
# What this crate is allowed to depend on, and under what terms.
#
# `cargo deny` answers three questions no rule in `policy/principles.toml` can:
# whether a dependency carries a published advisory, whether its license is one
# this repository may ship under, and whether the tree has quietly acquired two
# copies of the same crate or a source nobody named. Those are facts about the
# dependency graph rather than about this tree's files, which is exactly the
# boundary between a rule here and an external provider.
#
# It is NOT wired into a hook. The advisory half reaches the network, and this
# repository already decided where that belongs: `no-stale-hook-pins` runs at
# pre-push and manual and not at every commit, because a check that adds a
# network round trip to a commit is one somebody switches off. Run it here or in
# a scheduled job:
#
# cargo deny check
#
# What a claim in `policy/upheld.toml` could name once it IS wired is the hook
# id, not the individual advisory -- the same limit `ROADMAP.md` records for
# every third-party hook: this tool takes the claim's word for what that id
# enforces, because it cannot look inside the tool.
[advisories]
# The default is to deny anything the RustSec database reports. Nothing is
# ignored here, and an ignore that appears later should carry the reason and the
# date somebody expects to remove it.
yanked = "deny"
[licenses]
# Permissive licences only, named one at a time rather than by a category, so
# that adding one is a decision in a diff. This crate ships under Apache-2.0 and
# is installed as a binary by consumers who did not choose its dependency tree.
#
# The list holds what the tree actually carries and nothing else. `cargo deny`
# reports an allowance that matched nothing, and an entry that describes no
# dependency is the same shape as a stale baseline or a waiver naming a rule
# that is gone: it reads as a decision while doing nothing, and it will keep
# reading that way after the dependency it was for has left.
allow = [
"Apache-2.0",
"Apache-2.0 WITH LLVM-exception",
"BSD-2-Clause",
"BSD-3-Clause",
"MIT",
"Unicode-3.0",
"Unicode-DFS-2016",
"Unlicense",
]
# A dual-licensed crate is taken under the first of its licences this list
# admits, which is how `MIT OR Apache-2.0` resolves without a note per crate.
confidence-threshold = 0.9
[bans]
# Two versions of one crate in a binary is not automatically wrong -- a
# transitive dependency can hold an older one -- so this reports rather than
# refuses. What it catches is the version that is duplicated because nobody
# looked, which is the same shape as a pin nobody watches.
multiple-versions = "warn"
wildcards = "deny"
[sources]
# Everything comes from crates.io. A git dependency is not forbidden by
# argument, it is forbidden by default: it would be a pin no manifest resolver
# updates, which is what the `unmanaged-pins` rule set is about.
unknown-registry = "deny"
unknown-git = "deny"