# cargo-deny configuration — CRA supply chain policy
#
# Run: cargo deny check
# CI: cargo deny check advisories licenses sources
[]
= true
[]
# Deny any crate with a known security advisory
= "~/.cargo/advisory-db"
[]
# Permissive licenses only — no copyleft in the dependency tree
= [
"MIT",
"Apache-2.0",
"BSD-2-Clause",
"BSD-3-Clause",
"ISC",
"Unicode-3.0",
"Unicode-DFS-2016",
"Zlib",
]
[]
# No duplicate versions of critical crates
= "warn"
= "deny"
[]
# Only allow crates from crates.io
= "deny"
= "deny"
= ["https://github.com/rust-lang/crates.io-index"]
= []