| 1 |
# cargo-deny configuration: supply-chain gate for the MNW server. |
| 2 |
# |
| 3 |
# Run by Sando's `cargo_deny` gate as `cargo deny check` (all four checks). |
| 4 |
# This complements `cargo audit`: `bans` surfaces duplicate-version clusters |
| 5 |
# (the x509/crypto and rustls dual stacks the audits flag), and `sources` fails |
| 6 |
# the build if any dependency is pulled from a registry or git remote we did not |
| 7 |
# sanction. |
| 8 |
# |
| 9 |
# `licenses` is now part of the gate. The cleanup it was waiting on has landed: |
| 10 |
# docengine, s3-storage and tagtree carry `license = "MIT"`, per the licensing |
| 11 |
# strategy (reusable infra is MIT, products are PolyForm-Noncommercial). |
| 12 |
|
| 13 |
[advisories] |
| 14 |
version = 2 |
| 15 |
# Mirror of `.cargo/audit.toml`: every entry is a transitive advisory we cannot |
| 16 |
# resolve by bumping our own direct deps, kept in sync with the cargo-audit |
| 17 |
# posture. Directly-fixable advisories are fixed in Cargo.toml, never parked here. |
| 18 |
ignore = [ |
| 19 |
"RUSTSEC-2023-0071", # rsa Marvin timing side-channel, only via signature *verification* crates; we never decrypt with rsa. |
| 20 |
"RUSTSEC-2025-0141", # bincode unmaintained, transitive tooling, no code change available. |
| 21 |
"RUSTSEC-2020-0095", # difference unmaintained, via a dev/test dep. |
| 22 |
"RUSTSEC-2025-0134", # rustls-pemfile unmaintained, via AWS SDK TLS. |
| 23 |
# RUSTSEC-2024-0436 (paste) was dropped 2026-08-19: the dependency trim in |
| 24 |
# 2a53c900 took the last path to it and `paste` is no longer in Cargo.lock. |
| 25 |
# |
| 26 |
# RUSTSEC-2026-0173 (proc-macro-error2) is deliberately NOT mirrored here, |
| 27 |
# which is the one place this file and `.cargo/audit.toml` diverge. The crate |
| 28 |
# IS still in the graph, so the ignore stays load-bearing over there; it is |
| 29 |
# `informational = "unmaintained"`, which `[advisories] version = 2` does not |
| 30 |
# report for a transitive crate, so mirroring it only bought a permanent |
| 31 |
# `advisory-not-detected` warning on every run. |
| 32 |
# wasmtime "Stores can mix up type indices between engines" (3.8 low), via |
| 33 |
# yara-x 1.19.0, which pins the 43 line while the fixes skip it. Not |
| 34 |
# applicable: the bug needs two wasmtime Engines and production builds |
| 35 |
# exactly one (scanning/mod.rs:499). Full rationale + the condition that |
| 36 |
# would invalidate it: .cargo/audit.toml. |
| 37 |
"RUSTSEC-2026-0222", |
| 38 |
] |
| 39 |
|
| 40 |
[bans] |
| 41 |
# Duplicate versions are the supply-chain smell the audits track (x509/crypto |
| 42 |
# cluster, rustls 0.21/0.23 dual stack via the AWS SDK). Surface them as |
| 43 |
# warnings rather than failing the build: they are transitive and not yet |
| 44 |
# de-duplicable: so a *new* duplicate is visible in CI output without blocking |
| 45 |
# a deploy. Promote to "deny" with a `skip` list once the tree is de-duped. |
| 46 |
multiple-versions = "warn" |
| 47 |
wildcards = "deny" # a `*` version requirement on any dependency fails the build |
| 48 |
allow-wildcard-paths = true # ...except first-party path deps, which legitimately use path, not version |
| 49 |
highlight = "all" |
| 50 |
|
| 51 |
# The C crypto backends, banned by name. Two comments in Cargo.toml (on |
| 52 |
# webauthn-rs and on async-stripe) already said cargo-deny banned openssl-sys; |
| 53 |
# until now it did not, and nothing here could see the server sitting on |
| 54 |
# aws-lc-rs while the rest of the tree moved to ring. These are the `-sys` |
| 55 |
# crates rather than their wrappers because the wrapper is reachable as a |
| 56 |
# no-op feature, and it is the C toolchain that is the cost: it lands on the |
| 57 |
# build path for every architecture built natively (fw13, astra, mbp, |
| 58 |
# windows-x86) and it is what stops miri from ever reaching a verdict. |
| 59 |
# |
| 60 |
# The standing choice is the most-Rust backend available: rust_crypto > ring > |
| 61 |
# aws-lc-rs. If a transitive dep drags one of these back in, that is a real |
| 62 |
# finding and the fix is a feature selection, not an entry in this list. |
| 63 |
deny = [ |
| 64 |
{ name = "openssl-sys" }, |
| 65 |
{ name = "aws-lc-sys" }, |
| 66 |
] |
| 67 |
|
| 68 |
[sources] |
| 69 |
unknown-registry = "deny" # no crate may come from a registry other than the allow-list below |
| 70 |
unknown-git = "deny" # no crate may come from an unsanctioned git remote |
| 71 |
allow-registry = ["https://github.com/rust-lang/crates.io-index"] |
| 72 |
# Our own forge. docengine is consumed as a git dep on purpose (Cargo.toml:122) |
| 73 |
# so a container build can take it without the repo checked out beside this one; |
| 74 |
# multithreaded and GoingsOn keep path deps to the same crate. |
| 75 |
# |
| 76 |
# This is invisible on a dev box: ~/Code/.cargo/config.toml patches this URL (and |
| 77 |
# three more makenot.work git deps) to local checkouts, so `cargo deny` run from |
| 78 |
# ~/Code sees a path dependency and reports sources ok. The Sando worktree lives |
| 79 |
# under /srv/sando and inherits no such patch, which is why the gate is the thing |
| 80 |
# that sees the real dependency graph. When these disagree, the gate is right. |
| 81 |
allow-git = [ |
| 82 |
"https://makenot.work/git/max/docengine.git", |
| 83 |
# The description layer. Four crates out of one repo (quasi-router, |
| 84 |
# quasi-http, quasi-axum, quasi-webview), taken as git deps for the same |
| 85 |
# reason docengine is. Public on our forge since 2026-08-08. |
| 86 |
# |
| 87 |
# Missing here since the G1 spike added the deps, and invisible until now |
| 88 |
# for exactly the reason the paragraph above gives: no Sando build had run |
| 89 |
# in between, and a dev box's `cargo deny` sees the patched path deps. The |
| 90 |
# gate caught it on the first build that carried them, which is the gate |
| 91 |
# working. |
| 92 |
"https://makenot.work/git/max/quasi.git", |
| 93 |
# The house font pipeline, rev-pinned (Cargo.toml:261). Caught on |
| 94 |
# 2026-08-19 by the same mechanism and for the same reason as the quasi |
| 95 |
# entry above: the dep was added, no Sando build ran while it was there, |
| 96 |
# and every dev box read it as a path dep through the ~/Code patch. |
| 97 |
"https://makenot.work/git/max/quasi-type.git", |
| 98 |
] |
| 99 |
|
| 100 |
[licenses] |
| 101 |
version = 2 |
| 102 |
# Every license family present in the tree today. All permissive/weak-copyleft; |
| 103 |
# `r-efi`'s LGPL-2.1-or-later is satisfied by its MIT/Apache OR-clause. |
| 104 |
allow = [ |
| 105 |
"MIT", |
| 106 |
"MIT-0", |
| 107 |
"Apache-2.0", |
| 108 |
"BSD-1-Clause", |
| 109 |
"BSD-2-Clause", |
| 110 |
"BSD-3-Clause", |
| 111 |
"0BSD", |
| 112 |
"ISC", |
| 113 |
"BSL-1.0", |
| 114 |
"Zlib", |
| 115 |
"MPL-2.0", |
| 116 |
"CC0-1.0", |
| 117 |
"Unlicense", |
| 118 |
"Unicode-3.0", |
| 119 |
"CDLA-Permissive-2.0", |
| 120 |
"BlueOak-1.0.0", |
| 121 |
"bzip2-1.0.6", |
| 122 |
# cranelift, via yara-x. Apache-2.0 with the LLVM linking exception: |
| 123 |
# more permissive than bare Apache-2.0, no copyleft obligation. |
| 124 |
"Apache-2.0 WITH LLVM-exception", |
| 125 |
] |
| 126 |
confidence-threshold = 0.9 |
| 127 |
# First-party product crates carry the product license; allow it for exactly |
| 128 |
# these, not tree-wide. |
| 129 |
# The identifier must carry the `LicenseRef-` prefix, because PolyForm is not on |
| 130 |
# the SPDX list and `license = "PolyForm-Noncommercial-1.0.0"` is not a valid |
| 131 |
# expression. These exceptions were written without it and so matched nothing — |
| 132 |
# cargo-deny reported both as `license-exception-not-encountered` while |
| 133 |
# simultaneously rejecting the crates they were meant to cover. |
| 134 |
exceptions = [ |
| 135 |
{ name = "makenotwork", allow = ["LicenseRef-PolyForm-Noncommercial-1.0.0"] }, |
| 136 |
] |
| 137 |
|