Skip to main content

max / makenotwork

6.8 KB · 137 lines History Blame Raw
1 # cargo-deny configuration: supply-chain gate for the MNW server.
2 #
3 # Run by Sando's `cargo_deny` gate as `cargo deny check` (all four checks).
4 # This complements `cargo audit`: `bans` surfaces duplicate-version clusters
5 # (the x509/crypto and rustls dual stacks the audits flag), and `sources` fails
6 # the build if any dependency is pulled from a registry or git remote we did not
7 # sanction.
8 #
9 # `licenses` is now part of the gate. The cleanup it was waiting on has landed:
10 # docengine, s3-storage and tagtree carry `license = "MIT"`, per the licensing
11 # strategy (reusable infra is MIT, products are PolyForm-Noncommercial).
12
13 [advisories]
14 version = 2
15 # Mirror of `.cargo/audit.toml`: every entry is a transitive advisory we cannot
16 # resolve by bumping our own direct deps, kept in sync with the cargo-audit
17 # posture. Directly-fixable advisories are fixed in Cargo.toml, never parked here.
18 ignore = [
19 "RUSTSEC-2023-0071", # rsa Marvin timing side-channel, only via signature *verification* crates; we never decrypt with rsa.
20 "RUSTSEC-2025-0141", # bincode unmaintained, transitive tooling, no code change available.
21 "RUSTSEC-2020-0095", # difference unmaintained, via a dev/test dep.
22 "RUSTSEC-2025-0134", # rustls-pemfile unmaintained, via AWS SDK TLS.
23 # RUSTSEC-2024-0436 (paste) was dropped 2026-08-19: the dependency trim in
24 # 2a53c900 took the last path to it and `paste` is no longer in Cargo.lock.
25 #
26 # RUSTSEC-2026-0173 (proc-macro-error2) is deliberately NOT mirrored here,
27 # which is the one place this file and `.cargo/audit.toml` diverge. The crate
28 # IS still in the graph, so the ignore stays load-bearing over there; it is
29 # `informational = "unmaintained"`, which `[advisories] version = 2` does not
30 # report for a transitive crate, so mirroring it only bought a permanent
31 # `advisory-not-detected` warning on every run.
32 # wasmtime "Stores can mix up type indices between engines" (3.8 low), via
33 # yara-x 1.19.0, which pins the 43 line while the fixes skip it. Not
34 # applicable: the bug needs two wasmtime Engines and production builds
35 # exactly one (scanning/mod.rs:499). Full rationale + the condition that
36 # would invalidate it: .cargo/audit.toml.
37 "RUSTSEC-2026-0222",
38 ]
39
40 [bans]
41 # Duplicate versions are the supply-chain smell the audits track (x509/crypto
42 # cluster, rustls 0.21/0.23 dual stack via the AWS SDK). Surface them as
43 # warnings rather than failing the build: they are transitive and not yet
44 # de-duplicable: so a *new* duplicate is visible in CI output without blocking
45 # a deploy. Promote to "deny" with a `skip` list once the tree is de-duped.
46 multiple-versions = "warn"
47 wildcards = "deny" # a `*` version requirement on any dependency fails the build
48 allow-wildcard-paths = true # ...except first-party path deps, which legitimately use path, not version
49 highlight = "all"
50
51 # The C crypto backends, banned by name. Two comments in Cargo.toml (on
52 # webauthn-rs and on async-stripe) already said cargo-deny banned openssl-sys;
53 # until now it did not, and nothing here could see the server sitting on
54 # aws-lc-rs while the rest of the tree moved to ring. These are the `-sys`
55 # crates rather than their wrappers because the wrapper is reachable as a
56 # no-op feature, and it is the C toolchain that is the cost: it lands on the
57 # build path for every architecture built natively (fw13, astra, mbp,
58 # windows-x86) and it is what stops miri from ever reaching a verdict.
59 #
60 # The standing choice is the most-Rust backend available: rust_crypto > ring >
61 # aws-lc-rs. If a transitive dep drags one of these back in, that is a real
62 # finding and the fix is a feature selection, not an entry in this list.
63 deny = [
64 { name = "openssl-sys" },
65 { name = "aws-lc-sys" },
66 ]
67
68 [sources]
69 unknown-registry = "deny" # no crate may come from a registry other than the allow-list below
70 unknown-git = "deny" # no crate may come from an unsanctioned git remote
71 allow-registry = ["https://github.com/rust-lang/crates.io-index"]
72 # Our own forge. docengine is consumed as a git dep on purpose (Cargo.toml:122)
73 # so a container build can take it without the repo checked out beside this one;
74 # multithreaded and GoingsOn keep path deps to the same crate.
75 #
76 # This is invisible on a dev box: ~/Code/.cargo/config.toml patches this URL (and
77 # three more makenot.work git deps) to local checkouts, so `cargo deny` run from
78 # ~/Code sees a path dependency and reports sources ok. The Sando worktree lives
79 # under /srv/sando and inherits no such patch, which is why the gate is the thing
80 # that sees the real dependency graph. When these disagree, the gate is right.
81 allow-git = [
82 "https://makenot.work/git/max/docengine.git",
83 # The description layer. Four crates out of one repo (quasi-router,
84 # quasi-http, quasi-axum, quasi-webview), taken as git deps for the same
85 # reason docengine is. Public on our forge since 2026-08-08.
86 #
87 # Missing here since the G1 spike added the deps, and invisible until now
88 # for exactly the reason the paragraph above gives: no Sando build had run
89 # in between, and a dev box's `cargo deny` sees the patched path deps. The
90 # gate caught it on the first build that carried them, which is the gate
91 # working.
92 "https://makenot.work/git/max/quasi.git",
93 # The house font pipeline, rev-pinned (Cargo.toml:261). Caught on
94 # 2026-08-19 by the same mechanism and for the same reason as the quasi
95 # entry above: the dep was added, no Sando build ran while it was there,
96 # and every dev box read it as a path dep through the ~/Code patch.
97 "https://makenot.work/git/max/quasi-type.git",
98 ]
99
100 [licenses]
101 version = 2
102 # Every license family present in the tree today. All permissive/weak-copyleft;
103 # `r-efi`'s LGPL-2.1-or-later is satisfied by its MIT/Apache OR-clause.
104 allow = [
105 "MIT",
106 "MIT-0",
107 "Apache-2.0",
108 "BSD-1-Clause",
109 "BSD-2-Clause",
110 "BSD-3-Clause",
111 "0BSD",
112 "ISC",
113 "BSL-1.0",
114 "Zlib",
115 "MPL-2.0",
116 "CC0-1.0",
117 "Unlicense",
118 "Unicode-3.0",
119 "CDLA-Permissive-2.0",
120 "BlueOak-1.0.0",
121 "bzip2-1.0.6",
122 # cranelift, via yara-x. Apache-2.0 with the LLVM linking exception:
123 # more permissive than bare Apache-2.0, no copyleft obligation.
124 "Apache-2.0 WITH LLVM-exception",
125 ]
126 confidence-threshold = 0.9
127 # First-party product crates carry the product license; allow it for exactly
128 # these, not tree-wide.
129 # The identifier must carry the `LicenseRef-` prefix, because PolyForm is not on
130 # the SPDX list and `license = "PolyForm-Noncommercial-1.0.0"` is not a valid
131 # expression. These exceptions were written without it and so matched nothing —
132 # cargo-deny reported both as `license-exception-not-encountered` while
133 # simultaneously rejecting the crates they were meant to cover.
134 exceptions = [
135 { name = "makenotwork", allow = ["LicenseRef-PolyForm-Noncommercial-1.0.0"] },
136 ]
137