-
Notifications
You must be signed in to change notification settings - Fork 16
Expand file tree
/
Copy pathdeny.toml
More file actions
120 lines (107 loc) · 4.99 KB
/
Copy pathdeny.toml
File metadata and controls
120 lines (107 loc) · 4.99 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
# cargo-deny configuration for browser_oxide.
#
# Run locally: cargo deny check
# Run all rules: cargo deny check all
# Update DB: cargo deny check advisories
#
# CI enforces this via the `deny` job in .github/workflows/ci.yml.
#
# Policy summary:
# - Licenses: permissive only (MIT, Apache-2.0, BSD-3, ISC, Zlib, Unicode,
# CDLA-Permissive-2.0). NO AGPL, NO GPL/LGPL. MPL-2.0 is denied EXCEPT two
# cited transitive/optional exceptions (cooked-waker, adblock) carved out
# in [licenses.exceptions] below. Mechanically enforced here.
# - Sources: crates.io only. Reject git/path/registry alternatives.
# - Advisories: fail on any known security vulnerability.
[graph]
all-features = false
no-default-features = false
[output]
feature-depth = 1
# ============================================================================
# Advisories
# ============================================================================
[advisories]
db-urls = ["https://github.com/rustsec/advisory-db"]
yanked = "warn"
# Explicit ignores. Each MUST cite the reason and an expiry-or-reason note.
# All current entries are transitive through `deno_core 0.403 → v8`; we
# cannot drop them without forking the V8 stack. Re-evaluate on every
# deno_core bump.
ignore = [
{ id = "RUSTSEC-2024-0436", reason = "paste 1.0.15: unmaintained proc-macro, pulled in by v8. No drop-in upgrade (pastey is a soft fork). Re-evaluate on next deno_core bump." },
{ id = "RUSTSEC-2025-0141", reason = "bincode 1.3.3: unmaintained, pulled in by deno_core. Not a security issue; the bincode team stopped development. Re-evaluate on next deno_core bump or a community fork." },
# Text-shaping stack. Unlike the entries above these are DIRECT dependencies:
# `rustybuzz` is the HarfBuzz port that `canvas::text::shaper` uses, and it
# pulls `ttf-parser`. Both are "unmaintained" notices, not vulnerabilities —
# no CVE, no unsound API. There is no drop-in replacement for either in the
# pure-Rust shaping ecosystem; the alternative is binding native HarfBuzz,
# which would add a C++ build dependency to every consumer.
{ id = "RUSTSEC-2026-0206", reason = "rustybuzz 0.20.1: unmaintained (2026-07-11). Direct dep — the pure-Rust HarfBuzz port behind canvas text shaping. No maintained pure-Rust equivalent; replacing it means binding native HarfBuzz. Re-evaluate if a fork gains traction." },
{ id = "RUSTSEC-2026-0192", reason = "ttf-parser 0.25.1: unmaintained (2026-06-28). Pulled by rustybuzz (and used directly for font metrics). Tied to the rustybuzz decision above — resolves together with it." },
]
# ============================================================================
# Licenses
# ============================================================================
[licenses]
# Threshold for license-text matching confidence. 0.93 catches near-duplicates
# of the canonical text while still flagging genuinely unusual variants.
confidence-threshold = 0.93
# Allow-list. NO AGPL, NO GPL/LGPL. Permissive only — except for one
# explicit MPL-2.0 exception (cooked-waker) listed below.
allow = [
"MIT",
"Apache-2.0",
"Apache-2.0 WITH LLVM-exception",
"BSD-2-Clause",
"BSD-3-Clause",
"ISC",
"Zlib",
"Unicode-DFS-2016",
"Unicode-3.0",
"CDLA-Permissive-2.0", # webpki-roots ships Mozilla cert data under this
"0BSD",
"BSL-1.0",
"MIT-0",
"CC0-1.0",
]
# Per-crate exceptions. MPL-2.0 is *file-scope* copyleft: only modified
# MPL-licensed source files need to stay MPL. Linking from MIT/Apache
# code is fine and does not infect downstream. Each entry MUST cite the
# reason and the transitive root that pulls it in.
exceptions = [
# cooked-waker is pulled in by deno_core 0.403 → v8. We do not vendor
# or modify it, just link against it. Removing requires forking the
# V8 stack. Re-evaluate on every deno_core bump.
{ name = "cooked-waker", allow = ["MPL-2.0"] },
# adblock is the engine behind the optional `blocker` feature in the
# `net` crate (off by default). Default builds do not pull it.
{ name = "adblock", allow = ["MPL-2.0"] },
]
# Explicit clarifications for crates whose license metadata is ambiguous
# but the actual licensing is clear from upstream.
[[licenses.clarify]]
name = "ring"
expression = "MIT AND ISC AND OpenSSL"
license-files = [{ path = "LICENSE", hash = 0xbd0eed23 }]
# ============================================================================
# Bans
# ============================================================================
[bans]
multiple-versions = "warn"
wildcards = "deny"
highlight = "all"
# Hard-deny copyleft and AGPL even if they sneak in via a clarification.
deny = [
# Add named crates here if they appear with copyleft-only licensing.
]
skip = []
skip-tree = []
# ============================================================================
# Sources
# ============================================================================
[sources]
unknown-registry = "deny"
unknown-git = "deny"
allow-registry = ["https://github.com/rust-lang/crates.io-index"]
allow-git = []