-
Notifications
You must be signed in to change notification settings - Fork 3.7k
Expand file tree
/
Copy pathdeny.toml
More file actions
95 lines (89 loc) · 3.68 KB
/
Copy pathdeny.toml
File metadata and controls
95 lines (89 loc) · 3.68 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
# Configuration documentation:
# https://embarkstudios.github.io/cargo-deny/index.html
[advisories]
version = 2
yanked = "deny"
ignore = [
# paste crate is no longer maintained, but it is past 1.0
# Keep this here until our transisent dependencies no longer
# need it
"RUSTSEC-2024-0436",
# rustls-pemfile is unmaintained but still used as a transitive dependency
# from object_store. We've removed our direct dependency and migrated to
# rustls-pki-types. Remove once object_store updates.
"RUSTSEC-2025-0134",
# bincode is unmaintained but does not have any known issues;
# there are multiple replacements at this time but there isn't
# yet a clear choice
"RUSTSEC-2025-0141",
# quick-xml < 0.41.0 two DoS advisories: unbounded namespace-declaration
# allocation in NsReader (0195) and quadratic-time attribute duplicate check
# (0194). Pulled in transitively at two versions with no upgrade path yet:
# object_store (latest 0.14.0) pins quick-xml ^0.40.1 and inferno (latest
# 0.12.6, via pprof) pins ^0.39 — neither reaches the patched 0.41.0. Remove
# once object_store and pprof/inferno move to quick-xml >= 0.41.
"RUSTSEC-2026-0194",
"RUSTSEC-2026-0195",
# rustls-webpki 0.102.8 CRL distribution point matching bug; low impact
# (requires CA compromise). Stuck on 0.102.x via wasmtime's rustls 0.22.x
# dep in datafusion-udf-wasm. Upstream also ignores this advisory.
"RUSTSEC-2026-0049",
# rustls-webpki 0.102.8 wildcard name-constraint bug; stuck on 0.102.x via
# wasmtime's rustls 0.22.x dep in datafusion-udf-wasm. Upstream fix pulls in
# newer DataFusion/wasmtime and is not yet compatible with this repo.
"RUSTSEC-2026-0099",
# rustls-webpki 0.102.8 URI name-constraint bug; same transitive 0.102.x path
# via datafusion-udf-wasm/wasmtime/rustls 0.22.x, with the same current
# incompatibility on the available upstream fix path.
"RUSTSEC-2026-0098",
# rustls-webpki CRL parsing reachable panic; only 0.103.13+ and 0.104.0-alpha.7+
# ship the fix. The 0.103.x transitive is patched via the Cargo.toml pin bump,
# but the 0.102.x transitive is still stuck via datafusion-udf-wasm/wasmtime/
# rustls 0.22.x with no patched 0.102.x release available. We don't configure
# CRLs anywhere in this repo, so the panic is unreachable in practice on that
# remaining 0.102.x path.
"RUSTSEC-2026-0104",
]
git-fetch-with-cli = true
[licenses]
version = 2
unused-allowed-license = "warn"
allow = [
"Apache-2.0",
"Apache-2.0 WITH LLVM-exception",
"BSD-2-Clause",
"BSD-3-Clause",
"bzip2-1.0.6",
"BSL-1.0",
"CC0-1.0",
"CDLA-Permissive-2.0",
"ISC",
"MIT",
"Unicode-3.0",
"Zlib",
]
[[licenses.clarify]]
name = "ring"
expression = "BSD-4-Clause AND ISC AND MIT AND OpenSSL"
license-files = [
# https://github.com/briansmith/ring/blob/95948b3977013aed16db92ae32e6b8384496a740/LICENSE
{ path = "LICENSE", hash = 0xbd0eed23 },
]
[sources.allow-org]
github = ["influxdata"]
[bans]
multiple-versions = "allow"
deny = [
# We are using rustls as the TLS implementation, so we shouldn't be linking
# in OpenSSL too.
#
# If you're hitting this, you might want to take a look at what new
# dependencies you have introduced and check if there's a way to depend on
# rustls instead of OpenSSL (tip: check the crate's feature flags).
{ name = "openssl-sys" },
# We've decided to use the `humantime` crate to parse and generate friendly time formats; use
# that rather than chrono-english.
{ name = "chrono-english" },
# Use stdlib ( https://doc.rust-lang.org/stable/std/io/trait.IsTerminal.html )
{ name = "atty" },
]