2026-08-12 13:38:17 +02:00
# cargo-deny configuration for nxtgauge-backend-rust
# https://embarkstudios.github.io/cargo-deny/
#
# For this private/proprietary workspace we only enforce:
# - advisories (CVEs / RustSec)
# - bans (forbidden crates, duplicate versions)
# License compliance is skipped — our internal crates have no license field.
[ graph ]
targets = [ ]
# ── Advisories (CVEs / RustSec) ──────────────────────────────────────────────
[ advisories ]
version = 2
db-path = "~/.cargo/advisory-db"
db-urls = [ "https://github.com/rustsec/advisory-db" ]
ignore = [
# RUSTSEC-2023-0071 - rsa: Marvin Attack timing side-channel — no upstream fix available.
# Impact: potential RSA key recovery via timing. Low risk: we use RSA only for JWT
# verification (public-key ops), not for decryption. Acknowledged.
"RUSTSEC-2023-0071" ,
# RUSTSEC-2025-0141 - bincode: unmaintained (not a vulnerability, just no active maintainer).
# bincode is used transitively; no replacement available in our dep tree.
"RUSTSEC-2025-0141" ,
2026-08-12 23:30:30 +05:30
# RUSTSEC-2026-0235 - rkyv: out-of-bounds read validating Rc/Arc in archives.
# Pulled in only as an optional dependency of rust_decimal (apps/payments) behind
# its "rkyv" feature, which we never enable (we use `features = ["db-tokio-postgres"]`
# only) — cargo-deny's feature-aware graph already excludes it, so this entry is here
# purely so cargo-audit (which scans the full Cargo.lock, not the activated feature
# graph) can share the same ignore list via .cargo/audit.toml. See that file for detail.
"RUSTSEC-2026-0235" ,
# RUSTSEC-2020-0128, RUSTSEC-2021-0006, RUSTSEC-2023-0040, RUSTSEC-2023-0059:
# crate-name collisions between our own workspace crates (crates/cache "cache" 0.1.0,
# apps/users "users" 0.1.0) and unrelated abandoned crates.io packages of the same
# name+version. cargo-deny's real dependency-graph resolution already doesn't match
# these (they're not in the graph at all), so these entries are no-ops here — kept
# only so this file documents the same accepted-risk list as .cargo/audit.toml, which
# matches by name+version alone and does flag them. See audit.toml for detail.
"RUSTSEC-2020-0128" ,
"RUSTSEC-2021-0006" ,
"RUSTSEC-2023-0040" ,
"RUSTSEC-2023-0059" ,
2026-08-12 13:38:17 +02:00
]
# ── Bans (duplicate deps / forbidden crates) ──────────────────────────────────
[ bans ]
# Warn on multiple versions of the same crate.
multiple-versions = "warn"
# Crates we never want in the dependency tree.
deny = [
# Avoid the old `time` crate (use chrono / time 0.3 instead)
{ name = "time" , version = "=0.1" } ,
]
# ── Licenses (skipped for private workspace) ──────────────────────────────────
# We do not enforce license policy here because:
# - All our own workspace crates are proprietary and unpublished.
# - Third-party license compliance is managed separately.
[ licenses ]
version = 2
allow = [ "MIT" , "Apache-2.0" , "Apache-2.0 WITH LLVM-exception" , "BSD-2-Clause" , "BSD-3-Clause" , "ISC" , "Unicode-3.0" , "Unicode-DFS-2016" , "CC0-1.0" , "Zlib" , "OpenSSL" ]
confidence-threshold = 0.6
[ [ licenses . clarify ] ]
name = "ring"
expression = "MIT AND ISC AND OpenSSL"
license-files = [ { path = "LICENSE" , hash = 0 xbd0eed23 } ]
[ [ licenses . exceptions ] ]
allow = [ "LicenseRef-Private" ]
crate = "auth"
# ── Sources ───────────────────────────────────────────────────────────────────
[ sources ]
unknown-registry = "deny"
unknown-git = "deny"
allow-registry = [ "https://github.com/rust-lang/crates.io-index" ]