pub fn load(
explicit_path: Option<&Path>,
default_dir: &Path,
) -> Result<CliConfig, ConfigError>Expand description
Loads CliConfig from explicit_path, or from DEFAULT_CONFIG_FILENAME inside
default_dir when explicit_path is None.
default_dir is the walked root (FR-014 says “at the walked root”, not the process’s own
CWD — spec 062 review S4): deps-cli check /path/to/repo run from elsewhere must still
pick up that repo’s own deps.toml, not silently ignore it because the CLI happened to be
launched from a different directory.
A missing file is only an error when explicit_path was given explicitly (FR-014’s “a
path given via --config” case) — the default-location lookup silently falls back to
CliConfig::default (mirroring plan.md §4’s “default ./deps.toml if present”).
A file that exists but fails to parse is always an error (FR-016): unlike deps-lsp’s
live-reload path, a CLI run has no prior known-good configuration to keep.
Security (F1/F1-follow-up, spec 062 review, P0/P1): a deps.toml found by
auto-discovery (explicit_path: None) comes from the target being scanned, not from an
operator’s own explicit choice — in a git checkout && deps-cli check .-shaped CI job,
that target can be an untrusted PR branch from a fork. Two live-verified attacks follow
from trusting it fully:
- F1:
registries.gitlab_instance_hostis the one hostGITLAB_TOKENis ever attached to, andregistries.workspace_registries = "all"liftsnet_policy’s SSRF gate for loopback/RFC1918/cloud-metadata hosts (credential exfiltration/SSRF). - F1-follow-up:
diagnostics.{mutable_ref_pin,vulnerabilities}_enabled = falseornetwork.offline = truesilently disable the exact check that would have caught a vulnerability the same PR introduces — defeatingcheck’s CI-gating purpose without touching a secret. A PR from a fork can introduce a vulnerable dependency and editdeps.tomlin the same PR to turn off the check that would have caught it.
safe_auto_discovered_policy applies to an auto-discovered file only; an explicitly-given
--config is the operator’s own choice and is trusted as written.
§Errors
Returns ConfigError if the file cannot be read (and was explicitly requested), is
too large, is not valid TOML, or does not match CliConfig’s schema.