# cargo-deny configuration: `cargo deny check` (licenses, advisories, bans,
# sources) runs as the `deny` job in .forgejo/workflows/ci.yml.
[]
= 2
# RustSec advisories against any dependency in the graph fail the build.
= "deny"
[]
= 2
# MIT/Apache-2.0 covers the bulk of the Rust ecosystem; the rest are the
# common permissive licenses pulled in by rustls, tokio, reqwest and
# wiremock's trees. Anything new shows up as a CI failure with the exact
# license name to review and add deliberately.
= [
"MIT",
"Apache-2.0",
"Apache-2.0 WITH LLVM-exception",
"BSD-3-Clause",
"ISC",
"Unicode-3.0",
"CDLA-Permissive-2.0",
]
[]
# Multiple versions of the same crate are common in large graphs; warn so
# new duplicates are visible without failing every unrelated PR.
= "warn"
= "deny"
[]
= "warn"
= "warn"
= ["https://github.com/rust-lang/crates.io-index"]