Skip to main content

load

Function load 

Source
pub fn load(
    explicit_path: Option<&Path>,
    default_dir: &Path,
) -> Result<CliConfig, ConfigError>
Expand description

Loads CliConfig from explicit_path, or from DEFAULT_CONFIG_FILENAME inside default_dir when explicit_path is None.

default_dir is the walked root (FR-014 says “at the walked root”, not the process’s own CWD — spec 062 review S4): deps-cli check /path/to/repo run from elsewhere must still pick up that repo’s own deps.toml, not silently ignore it because the CLI happened to be launched from a different directory.

A missing file is only an error when explicit_path was given explicitly (FR-014’s “a path given via --config” case) — the default-location lookup silently falls back to CliConfig::default (mirroring plan.md §4’s “default ./deps.toml if present”). A file that exists but fails to parse is always an error (FR-016): unlike deps-lsp’s live-reload path, a CLI run has no prior known-good configuration to keep.

Security (F1/F1-follow-up, spec 062 review, P0/P1): a deps.toml found by auto-discovery (explicit_path: None) comes from the target being scanned, not from an operator’s own explicit choice — in a git checkout && deps-cli check .-shaped CI job, that target can be an untrusted PR branch from a fork. Two live-verified attacks follow from trusting it fully:

  • F1: registries.gitlab_instance_host is the one host GITLAB_TOKEN is ever attached to, and registries.workspace_registries = "all" lifts net_policy’s SSRF gate for loopback/RFC1918/cloud-metadata hosts (credential exfiltration/SSRF).
  • F1-follow-up: diagnostics.{mutable_ref_pin,vulnerabilities}_enabled = false or network.offline = true silently disable the exact check that would have caught a vulnerability the same PR introduces — defeating check’s CI-gating purpose without touching a secret. A PR from a fork can introduce a vulnerable dependency and edit deps.toml in the same PR to turn off the check that would have caught it.

safe_auto_discovered_policy applies to an auto-discovered file only; an explicitly-given --config is the operator’s own choice and is trusted as written.

§Errors

Returns ConfigError if the file cannot be read (and was explicitly requested), is too large, is not valid TOML, or does not match CliConfig’s schema.