# cargo-deny configuration for dotmax
# Enforces license policy, detects security vulnerabilities, prevents duplicates
[]
= [
# paste 1.0.15 is unmaintained but still functional
# ratatui v0.29.0 depends on it transitively, widely used in ecosystem
"RUSTSEC-2024-0436",
]
[]
# Allow permissive licenses (compatible with MIT OR Apache-2.0)
= [
"MIT",
"Apache-2.0",
"Apache-2.0 WITH LLVM-exception",
"BSD-2-Clause",
"BSD-3-Clause",
"ISC",
"Unlicense",
"Unicode-DFS-2016",
"Unicode-3.0",
"0BSD",
"Zlib",
"BSL-1.0",
]
= 0.8
[]
# Warn about multiple versions of same crate (common in Rust ecosystem)
= "warn"
[]
# All crates must come from crates.io
= "deny"
= "deny"