spm-cli 0.4.0

Skill package manager — declare AI skills in ai.json, materialize them for Claude/Copilot without polluting your repo.
# deny.toml — cargo-deny configuration
# Docs: https://embarkstudios.github.io/cargo-deny/

[graph]
# The targets to check against (empty = all platforms).
targets = []

[advisories]
# Deny crates with known security vulnerabilities from the RustSec advisory database.
version = 2
ignore = []

[licenses]
version = 2
# Deny any crate that does not match the allow list below.
allow = [
  "MIT",
  "Apache-2.0",
  "Apache-2.0 WITH LLVM-exception",
  "BSD-2-Clause",
  "BSD-3-Clause",
  "ISC",
  "Unicode-3.0",
  "Unicode-DFS-2016",
  "MPL-2.0",
]

[bans]
# Warn on multiple versions of the same crate (prefer deduplication but don't hard-fail).
multiple-versions = "warn"
# Deny wildcard dependencies (e.g. `foo = "*"`).
wildcards = "deny"

[sources]
# Only allow crates from crates.io; reject crates from unknown registries or
# git sources in CI. (Local `path` dependencies are not governed by these keys.)
unknown-registry = "deny"
unknown-git = "deny"
allow-registry = ["https://github.com/rust-lang/crates.io-index"]