Repository navigation
Expand file tree
/
Copy pathdeny.toml
More file actions
74 lines (66 loc) · 3.94 KB
/
Copy pathdeny.toml
File metadata and controls
74 lines (66 loc) · 3.94 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
# cargo-deny configuration for the dependency-advisory CI gate.
#
# `cargo deny check` fails the build on ANY RustSec advisory
# (vulnerability, unmaintained, unsound, or yanked) unless it is explicitly
# listed in `advisories.ignore` below. This is intentional: silently
# tolerating "just a warning" advisories is how RUSTSEC-2026-0187 (lopdf
# stack overflow via deeply nested PDF objects, reachable through
# extract_document / sessions.rs / registry/execute.rs) sat in Cargo.lock
# with nothing ever gating it in CI.
#
# Accepting an advisory here is a real decision, not a rubber stamp:
# - Every entry MUST have a `reason` naming the crate, why it's not
# currently fixable/exploitable here, and an inline `expires: YYYY-MM-DD`.
# - `scripts/check-advisory-expiry.mjs` (run in CI alongside this check)
# parses that `expires:` marker and FAILS the build once it has passed,
# so an accepted advisory can't be forgotten forever -- cargo-deny itself
# has no native expiry mechanism, so we enforce it out-of-band.
# - When an entry expires, re-run `cargo audit` / `cargo tree -i <crate>`:
# either the upstream crate has a fix (bump it, drop the ignore) or it
# doesn't yet (extend the expiry with a fresh reason).
[graph]
targets = []
[advisories]
ignore = [
# --- Unmaintained crates (no known vulnerability) ---
{ id = "RUSTSEC-2025-0141", reason = "bincode 1.3.3 unmaintained; pulled in by syntect (production, tui-rs syntax highlighting). No upstream fix / maintained fork adopted by syntect yet. expires: 2026-10-23" },
{ id = "RUSTSEC-2025-0057", reason = "fxhash 0.2.1 unmaintained; pulled in transitively via criterion's fxprof-processed-profile (dev-dependency / benchmarks only, not in the shipped binary). expires: 2026-10-23" },
{ id = "RUSTSEC-2024-0384", reason = "instant 0.1.13 unmaintained; pulled in via notify-types behind the optional hot-reload feature (not enabled by default; default = []). expires: 2026-10-23" },
{ id = "RUSTSEC-2024-0436", reason = "paste 1.0.15 unmaintained; proc-macro pulled in by ratatui (production, TUI rendering). No ratatui release has dropped it yet. expires: 2026-10-23" },
{ id = "RUSTSEC-2026-0192", reason = "ttf-parser 0.25.1 unmaintained; pulled in transitively via lopdf 0.42.0 (the fix version for RUSTSEC-2026-0187) via pdf-extract 0.12.0. No known vulnerability; re-check when lopdf/pdf-extract bump their ttf-parser dependency or adopt a maintained fork. expires: 2026-10-23" },
# --- Vulnerabilities without a fixed release ---
{ id = "RUSTSEC-2023-0071", reason = "rsa 0.9.10 (Marvin timing side channel) pulled in by jsonwebtoken 10.4.0 via octocrab 0.54.2 (ambient-agent, production). No fixed rsa release exists; the same advisory is already ignored in products/computer, platform/cerebro and the root workspace cargo-audit step. expires: 2026-10-23" },
# --- Unsound (no known exploitable vulnerability reported here) ---
{ id = "RUSTSEC-2026-0002", reason = "lru 0.12.5: IterMut violates Stacked Borrows (Miri/unsafe-code soundness issue), pulled in by ratatui (production). Not a memory-safety issue under normal (non-Miri) execution; tracked for the next ratatui bump that picks up a fixed lru. expires: 2026-10-23" },
]
[licenses]
allow = [
"MIT",
"Apache-2.0",
"Apache-2.0 WITH LLVM-exception",
"BSD-2-Clause",
"BSD-3-Clause",
"CDLA-Permissive-2.0",
"ISC",
"Unicode-3.0",
"Zlib",
"MPL-2.0",
"CC0-1.0",
]
confidence-threshold = 0.8
# Maestro's dex-loop -> jsonschema -> referencing -> fluent-uri edge uses
# the same MIT-0 crate already accepted by rust/deny.toml and Connectors.
# Keep this product allowance limited to the existing locked version.
exceptions = [
{ crate = "borrow-or-share@=0.2.4", allow = ["MIT-0"] },
]
[licenses.private]
ignore = true
[bans]
multiple-versions = "warn"
wildcards = "allow"
[sources]
unknown-registry = "deny"
unknown-git = "deny"
allow-registry = ["https://github.com/rust-lang/crates.io-index"]
allow-git = []