-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathdeny.toml
More file actions
100 lines (95 loc) · 4.98 KB
/
Copy pathdeny.toml
File metadata and controls
100 lines (95 loc) · 4.98 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
# cargo-deny: supply-chain gate for both cargo roots (the firmware workspace and the
# standalone obc-fw-nrf54l board crate). Run from the repo root against each lockfile:
# cargo deny --all-features check
# cargo deny --manifest-path firmware/obc-fw-nrf54l/Cargo.toml --all-features check
# cargo deny --manifest-path apps/obc-desktop/Cargo.toml --all-features check
# Checks advisories (RustSec), licenses, banned crates, and dependency sources.
#
# ONE THING THIS FILE CANNOT SEE, so it is written down here (#907): `geos-src`
# declares MIT — that is the licence of the *wrapper crate*, not of the GEOS C++
# sources it carries, which are **LGPL-2.1**. The desktop app statically links them,
# which is fine (LGPL-2.1 §3 permits GPL-2-or-later, and this project is GPL-3) but
# is not free of obligations: a distributed binary has to come with the licence text
# and the corresponding source. D3 (#908) owns the installers and therefore owns
# putting that in them. Nothing changed about *which* code we link — the dynamic
# build carried the same library — only about it now being inside the artifact.
[graph]
# Resolve every feature so feature-gated deps (debug-link, the sim's eframe stack...) are
# in scope for the license/advisory scan, not just the default set.
all-features = true
[advisories]
# Fail on any known security advisory, and on a crate pinned to a yanked version (the
# lockfile-drift class of bug this whole pipeline guards against). `ignore` stays empty:
# add a specific RustSec id here, with a comment, only when one is triaged as not affecting us.
yanked = "deny"
ignore = [
# quick-xml 0.30 DoS-class issues (quadratic duplicate-attribute check; unbounded
# namespace allocations). Reached only through the desktop sim's Linux accessibility
# stack (eframe -> accesskit -> atspi -> zbus), which parses D-Bus introspection XML
# from the local session bus — never untrusted input — and never ships on the device.
# atspi pins quick-xml ^0.30, so the fixed release isn't reachable without an eframe
# major bump; drop these when the eframe stack next moves.
"RUSTSEC-2026-0194",
"RUSTSEC-2026-0195",
]
# Only fail on *unmaintained* crates we depend on directly — the sim's GUI stack (eframe ->
# egui -> accesskit) drags in deep transitive crates like `paste` (RUSTSEC-2024-0436) we can't
# upgrade. Security *vulnerabilities* are still denied everywhere regardless of this setting.
unmaintained = "workspace"
[licenses]
# Permissive licenses only — everything the dep tree currently resolves to. A new dep under
# a license not listed here fails CI, forcing a deliberate decision rather than silent drift.
allow = [
"MIT",
"Apache-2.0",
"Apache-2.0 WITH LLVM-exception",
"BSD-2-Clause",
"BSD-3-Clause",
"ISC",
"Zlib",
"Unicode-3.0",
"Unlicense",
"0BSD",
"BSL-1.0",
"CC0-1.0",
"MPL-2.0",
]
confidence-threshold = 0.8
# The workspace's own obc-* crates carry no `license` field (never published); skip them.
private = { ignore = true }
# eframe/egui's bundled default fonts ship under the SIL Open Font License plus a non-SPDX
# Ubuntu Font License reference, alongside the usual MIT/Apache dual-license. Scope those two
# to just this crate rather than allowing OFL globally.
exceptions = [
# The host PBF reader and its iterator helpers use the permissive WTFPL.
{ crate = "osmpbfreader", allow = ["WTFPL"] },
{ crate = "par-map", allow = ["WTFPL"] },
{ crate = "pub-iterator-type", allow = ["WTFPL"] },
{ crate = "epaint_default_fonts", allow = ["OFL-1.1", "LicenseRef-UFL-1.0"] },
# Mozilla's CA root store, as data, under the Community Data License Agreement
# (permissive — attribution only, no copyleft on anything that uses it). Reached
# through ureq's rustls in the desktop app (#906), which needs a trust store to
# fetch Geofabrik over TLS. Scoped to the crate rather than allowing CDLA
# globally: this is the only place a *data* licence is appropriate.
{ crate = "webpki-roots", allow = ["CDLA-Permissive-2.0"] },
]
[bans]
# embassy + eframe legitimately pull several versions of small crates (bitflags, syn, ...);
# warn so it's visible without blocking. Nothing is hard-banned yet.
multiple-versions = "warn"
# Ban `version = "*"` on crates.io deps, but allow it for the workspace's own path deps
# (`obc-app = { path = "../obc-app" }`), which cargo models as a wildcard requirement.
wildcards = "deny"
allow-wildcard-paths = true
[sources]
# Every dependency must come from crates.io, with one reviewed exception below — an
# unexpected git or unknown-registry source should fail rather than slip in unreviewed.
unknown-registry = "deny"
unknown-git = "deny"
# nrf-sdc/nrf-mpsl (BLE controller, issue #269): the crates.io releases predate nRF54L support
# and pin embassy-nrf 0.7, so the board crate rev-pins git main (the same rev TrouBLE's nrf54
# example pins — see the crate README's BLE section). Drop when a ≥0.4 release ships.
#
allow-git = [
"https://github.com/alexmoon/nrf-sdc",
]