vole-document 0.1.0-alpha.13

Byte-exact procedural document storage: deterministic reconstruction state, typed residuals, and entropy-coded channels that materialize the exact original document bytes.
Documentation
# Dependency policy for VOLE-Document.
#
# The exact core must remain auditable and small. Every dependency is pinned
# exactly in Cargo.toml and locked in Cargo.lock; deviating from this policy is
# a deliberate, reviewed decision.

[graph]
all-features = true

[advisories]
yanked = "deny"
# Vulnerabilities are denied by default in cargo-deny's advisories check.

[licenses]
confidence-threshold = 0.9
# Only licenses actually encountered in the dependency graph. Adding a new
# dependency with a different license requires a reviewed change here.
allow = [
    "MIT",
    "Apache-2.0",
    # `unicode-ident` (a proc-macro dependency of `syn`) is released under the
    # standard Unicode License v3 in addition to MIT/Apache-2.0. Permissive.
    "Unicode-3.0",
    # `preflate-rs` (Phase 6, feature `deflate-replay`) depends on `cabac`,
    # which is LGPL-3.0-or-later. This is a deliberate, documented exception:
    # it is the only copyleft dependency in the graph and it is reachable only
    # through the optional `deflate-replay` feature. See ADR-0014 and the
    # README licensing note for the static-linking consequences.
    "LGPL-3.0-or-later",
]

[bans]
multiple-versions = "warn"
wildcards = "deny"

[sources]
unknown-registry = "deny"
unknown-git = "deny"