Repository navigation
Expand file tree
/
Copy pathdeny.toml
More file actions
98 lines (93 loc) · 4.37 KB
/
Copy pathdeny.toml
File metadata and controls
98 lines (93 loc) · 4.37 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
# cargo-deny configuration — run locally with `cargo deny check all`.
# CI runs the same check in the "Supply chain" job of .github/workflows/ci.yml.
[graph]
all-features = true
[advisories]
# Fail on any crate with a security advisory or an unmaintained warning.
# Add an entry here only with a comment explaining the exposure and the plan.
ignore = []
[licenses]
# Licenses accepted for this crate and its dependencies. Keep GPL-3.0-only for
# the template crate itself and GPL-3.0-or-later for the pinned OpenHuman
# example adapter; the remaining entries cover compatible dependency licenses
# commonly encountered by Rust projects.
allow = [
"Apache-2.0",
"Apache-2.0 WITH LLVM-exception",
"BSD-2-Clause",
"BSD-3-Clause",
"CDLA-Permissive-2.0",
"GPL-3.0-only",
"GPL-3.0-or-later",
"ISC",
"MIT",
"MPL-2.0",
"Unicode-3.0",
"Zlib",
]
confidence-threshold = 0.9
[bans]
# Duplicate versions bloat build times; review them rather than ignoring them.
multiple-versions = "warn"
wildcards = "deny"
# A `version` requirement on a workspace-internal path dependency is a trap: it
# is a caret range, so the first minor bump past `0.1.x` — or any 1.0 release —
# stops resolving, and the release workflow discovers it after the tag is
# pushed. The path is the whole address for a crate that is never published, so
# those entries carry no version and are wildcards by construction.
#
# This exemption is narrow: it applies only to path dependencies on crates whose
# manifest sets `publish = false`. A wildcard on anything from a registry is
# still denied, which is what this check exists for.
allow-wildcard-paths = true
# `openhuman` is a revision-pinned git dependency patched to the recorded
# submodule. Its public manifest uses `workspace = true` for its internal
# crates, which cargo-deny classifies as wildcard dependencies even though the
# resolved graph is fixed by Cargo.lock and assert-openhuman-pin.sh. Skip only
# this exact package's manifest-level wildcard finding; its dependency tree
# remains subject to every ban check.
skip = [
{ name = "openhuman", version = "0.64.10" },
# `tinyjuice` is vendored inside OpenHuman and arrived with the pin bump
# that follows `main`. Its manifest carries no `publish = false`, so
# `allow-wildcard-paths` does not reach it -- cargo-deny reads a published
# crate's internal `{ path = "crates/tinyjuice-bus" }` as a wildcard even
# though nothing resolves through a range: the tree is revision-pinned and
# `assert-openhuman-pin.sh` holds it to the recorded submodule.
#
# Same narrowness as the entry above: this skips one package's
# manifest-level wildcard finding, and its dependency tree stays subject to
# every other ban.
{ name = "tinyjuice", version = "0.6.0" },
]
# Crates that must never enter the dependency graph.
deny = []
[sources]
unknown-registry = "deny"
unknown-git = "deny"
allow-registry = ["https://github.com/rust-lang/crates.io-index"]
# Examples take tinyinference, tinytools, and tinyjevclient as revision-pinned
# git dependencies rather than published versions; nothing under crates/*
# depends on their transports, and `.github/scripts/assert-pure.sh` checks the
# normal/build graph for the pure crates. See AGENTS.md's supply-chain
# boundary.
#
# OpenHuman is the one exception: `openhuman-embed`, `openhuman`, `tinytools`
# and `tinytools-agent` are revision-pinned git dependencies of
# `tinyhivemind-openhuman`, the one library crate that links the harness, per
# `docs/adr/0020-openhuman-embed-is-a-git-dependency-patched-locally.md` and
# `docs/adr/0025-the-driver-names-no-harness.md`. `[patch]` in the root
# `Cargo.toml` redirects those sources onto the `vendor/openhuman` submodule
# this repository already vendors and tests against (the tool crates onto the
# copy nested inside it), so every build here still compiles the vendored
# tree, not a fresh git fetch. `.github/scripts/assert-openhuman-pin.sh`, run
# in the `rust` CI job, reads each `rev` pinned in `Cargo.toml` and the
# submodule commits and fails the build if they disagree — the supply-chain
# guarantee this exemption relies on is that check, not an absence of library
# dependents.
allow-git = [
"https://github.com/tinyhumansai/openhuman",
"https://github.com/tinyhumansai/tinyinference",
"https://github.com/tinyhumansai/tinyjevclient",
"https://github.com/tinyhumansai/tinytools",
]