Repository navigation
Expand file tree
/
Copy pathdeny.toml
More file actions
114 lines (98 loc) · 6 KB
/
Copy pathdeny.toml
File metadata and controls
114 lines (98 loc) · 6 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
# cargo-deny configuration for cachekit security policy
# Enforces license compliance, vulnerability scanning, and dependency policy
# See: https://embarkstudios.github.io/cargo-deny/
# ═══════════════════════════════════════════════════════════════
# GRAPH - Dependency Graph Configuration
# ═══════════════════════════════════════════════════════════════
[graph]
# Target platforms for cachekit (cross-platform library)
targets = [
"x86_64-unknown-linux-gnu",
"aarch64-unknown-linux-gnu",
"x86_64-apple-darwin",
"aarch64-apple-darwin",
"x86_64-pc-windows-msvc",
]
# Use all features for comprehensive analysis
all-features = true
# ═══════════════════════════════════════════════════════════════
# ADVISORIES - Vulnerability Scanning (RustSec Database)
# ═══════════════════════════════════════════════════════════════
[advisories]
# Check all workspace crates for unmaintained dependencies
unmaintained = "workspace"
# Exemptions require a reason and are re-checked whenever the parent dep updates.
# quick-xml 0.26 is pinned by pprof 0.15 -> inferno 0.11 (dev-only profiling/flamegraph
# stack, never shipped in the wheel). No patched quick-xml exists on the 0.26 line and
# pprof 0.15 (latest) cannot take inferno 0.12. Remove when pprof releases with inferno >= 0.12.
# Keep in sync with the audit-check ignore list in .github/workflows/security-fast.yml.
ignore = [
{ id = "RUSTSEC-2026-0194", reason = "quick-xml DoS (quadratic attr check); dev-only via pprof->inferno, no upgrade path yet" },
{ id = "RUSTSEC-2026-0195", reason = "quick-xml DoS (unbounded ns alloc); dev-only via pprof->inferno, no upgrade path yet" },
]
# ═══════════════════════════════════════════════════════════════
# LICENSES - License Policy Enforcement
# ═══════════════════════════════════════════════════════════════
[licenses]
# High confidence threshold for license detection
confidence-threshold = 0.8
# Allowed licenses (MIT/Apache-2.0/BSD-3-Clause compatible with cachekit MIT license)
allow = [
"MIT",
"Apache-2.0",
"Apache-2.0 WITH LLVM-exception", # LLVM runtime exception
"BSD-2-Clause",
"BSD-3-Clause",
"ISC",
"Unicode-3.0", # Unicode License v3 (OSI approved, permissive)
"CC0-1.0", # Public domain
"0BSD", # BSD Zero Clause (very permissive)
"BSL-1.0", # Boost Software License (very permissive, simpler than MIT)
"MPL-2.0", # Mozilla Public License 2.0 (file-level copyleft, OSI approved)
]
# License exceptions for specific crates (use sparingly)
# Format: { allow = ["LICENSE"], crate = "crate-name" }
exceptions = []
# ═══════════════════════════════════════════════════════════════
# BANS - Dependency Policy Enforcement
# ═══════════════════════════════════════════════════════════════
[bans]
# Deny multiple versions of the same crate (reduces binary size, prevents subtle bugs)
multiple-versions = "deny"
# Deny wildcard dependencies (e.g., "serde = *")
wildcards = "deny"
# Highlight all duplicate versions for review
highlight = "all"
# Ban specific crates (use-instead provides alternative)
# Format: { crate = "name", reason = "explanation", use-instead = "alternative" }
deny = []
# Skip specific dependencies from multiple-version checks
# Format: { crate = "name@version", reason = "explanation" }
skip = [
# getrandom 0.2.x (ring) vs 0.3.x (newer ecosystem) - common split
# Safe: stateless RNG interface, both maintained
{ crate = "getrandom@0.2.17", reason = "ring uses 0.2.x, newer deps use 0.3.x" },
]
# Skip crate trees entirely (e.g., frequently-updated foundational crates)
# Format: { crate = "name", reason = "explanation" }
skip-tree = [
# Windows FFI shim family (windows-sys -> windows-targets -> windows_x86_64_*) churns
# across majors (0.59/0.60/0.61) as transitive deps migrate. It is never compiled on the
# Linux CI target and only one variant is ever linked per platform, so duplicate versions
# are benign. skip-tree covers the whole subtree so a windows bump pulled in by a transitive
# build dep (e.g. cachekit-core's RNG path) does not re-trip the duplicate ban. (#175)
{ crate = "windows-sys", reason = "Windows FFI shim; benign cross-major churn, not built on Linux" },
{ crate = "windows-targets", reason = "windows-sys subtree; may also appear under other parents" },
]
# ═══════════════════════════════════════════════════════════════
# SOURCES - Source Registry Policy
# ═══════════════════════════════════════════════════════════════
[sources]
# Deny unknown registry sources (prevent supply chain attacks)
unknown-registry = "deny"
# Deny unknown git sources (prevent malicious repos)
unknown-git = "deny"
# Only allow crates.io as the source registry
allow-registry = ["https://github.com/rust-lang/crates.io-index"]
# No git dependencies allowed (use crates.io releases for stability)
allow-git = []