1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
# cargo-deny configuration.
# https://embarkstudios.github.io/cargo-deny/
#
# No advisory waivers: this crate's graph is lean enough to carry none.
# If one becomes necessary, copy the monorepo's waiver discipline โ
# advisory ID, the reaching chain, and a dated sunset condition.
[]
= ["https://github.com/rustsec/advisory-db"]
= "deny"
[]
= [
"MIT",
"MIT-0",
"Apache-2.0",
"Apache-2.0 WITH LLVM-exception",
"BSD-2-Clause",
"BSD-3-Clause",
"ISC",
"Unicode-DFS-2016",
"Unicode-3.0",
"Zlib",
"CC0-1.0",
"MPL-2.0",
"0BSD",
# Community Data License โ used by webpki-root-certs (via reqwest's
# rustls platform verifier) under the `remote-sinks` feature. Same
# allowance the monorepo carries for webpki-roots.
"CDLA-Permissive-2.0",
]
= 0.8
[]
= "warn"
= "deny"
# The enforceable "framework-free" statement (extraction playbook ยง2.2):
# this crate must never depend back on the tool, and never regress onto
# the workspace-banned crates.
= [
{ = "rust-tool-base" },
{ = "rtb-cli-bin" },
# anyhow is banned from library code (thiserror + miette are the
# error surface); cucumber pulls it as a dev-only transitive, which
# matches the workspace policy "anyhow in tests is acceptable".
# prost-derive (a proc-macro, build-time only โ never linked into
# the shipped library) pulls it under the `remote-sinks` OTLP
# stack; per `cargo tree -i anyhow --all-features` those are the
# only two reaching chains.
{ = "anyhow", = ["cucumber", "prost-derive"] },
{ = "openssl-sys" },
{ = "native-tls" },
]
[]
= "deny"
= "deny"
= ["https://github.com/rust-lang/crates.io-index"]