# cargo-deny configuration. # # This crate is GPLv3 (it shares a licence with the JRay Jellyfin plugin), and it # is a long-lived network service whose main risks are hostile input and operator # friction (§8). So two checks matter most here: # # - `advisories` — a public-facing service must not ship known-vulnerable # dependencies. # - `licenses` — GPLv3 is compatible with permissive licences, but *not* with # everything. A copyleft-incompatible dependency arriving transitively would # be a licensing problem discovered far too late. # # Run with `cargo deny check`. [graph] # Check the targets an operator actually deploys. §8 ships a single static binary # (musl target), so both glibc and musl Linux are in scope. targets = [ "x86_64-unknown-linux-gnu", "x86_64-unknown-linux-musl", "aarch64-unknown-linux-gnu", "aarch64-unknown-linux-musl", ] all-features = true [advisories] version = 2 # Fail on any RustSec advisory. Unmaintained crates are a warning rather than an # error: `sled` was rejected in §8 partly on maintenance grounds, so the signal is # worth surfacing, but it should not break a build on its own. yanked = "deny" unmaintained = "workspace" ignore = [] [licenses] version = 2 # Permissive licences, all GPLv3-compatible. Deliberately a closed allow-list # rather than a deny-list: a licence nobody vetted should stop the build, in the # same spirit as §6's "no additional fields anywhere". # # Kept to licences actually present in the tree, so `cargo deny` stays quiet in # CI and an added allowance is a visible decision. Adding a dependency that needs # a new licence should be a deliberate edit here. allow = [ "Apache-2.0", "MIT", "BSD-2-Clause", "BSD-3-Clause", "ISC", "Zlib", "Unicode-3.0", # `webpki-roots` — Mozilla's trusted CA certificate set. This is a *data* # licence, not a code licence, which is why it is not on the usual permissive # list: the crate ships certificates rather than logic. CDLA-Permissive-2.0 # imposes no copyleft and no attribution burden on a binary that embeds it, so # it is compatible with distributing this server under GPLv3. # # It arrives via reqwest's rustls stack, which §8's single static musl binary # depends on (bundling roots is what lets the binary verify TLS without a # system trust store). "CDLA-Permissive-2.0", # This crate's own licence. "GPL-3.0-or-later", ] confidence-threshold = 0.9 # `ring` ships a bespoke licence file that no SPDX expression describes; it is # a permissive OpenSSL/ISC-style licence and is GPL-compatible. Clarify it rather # than widening the allow-list. [[licenses.clarify]] crate = "ring" expression = "MIT AND ISC AND OpenSSL" license-files = [{ path = "LICENSE", hash = 0xbd0eed23 }] [bans] multiple-versions = "warn" wildcards = "deny" # Nothing is banned outright yet. The obvious future entries are alternative TLS # stacks: reqwest is pinned to rustls (`default-features = false`) so that a # static musl binary needs no system OpenSSL, and an accidental openssl-sys # dependency would silently break that deployment story. deny = [] skip = [] skip-tree = [] [sources] unknown-registry = "deny" unknown-git = "deny" # Only crates.io. A git dependency in a service that hobbyist operators build # from source is a supply-chain and reproducibility problem. allow-registry = ["https://github.com/rust-lang/crates.io-index"] allow-git = []