openpencil/deny.toml
Kayshen-X c54a5facee chore(workspace): cargo-deny 0.18 activation (Phase 1 Task 1.8 Step 6)
- deny.toml: add [graph].targets to limit metadata to native+wasm32
  (avoid Android/iOS edition-2024 deps that fail rustc 1.82 cargo metadata)
- deny.toml: [bans] allow-wildcard-paths = true for workspace path deps
- crates/*/Cargo.toml: add explicit version="0.1.0" alongside path = "..."
  (cargo-deny rejects wildcard-path deps for publishable crates)

cargo-deny 0.16.4 hits a CVSS 4.0 parse error AND lacks edition-2024 cargo
metadata support; bumped to 0.18.9 (installed via stable toolchain). Run
cargo-deny with RUSTUP_TOOLCHAIN=stable so it uses cargo 1.95 for metadata
parsing while project itself still builds on 1.82.

Verified: advisories ok, bans ok, licenses ok, sources ok (exit 0)
on both native and wasm32-unknown-unknown targets.
2026-05-03 23:05:00 +08:00

61 lines
1.5 KiB
TOML
Raw Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

# cargo-deny config — pinned to ≥ 0.16 schema
# Validated via openpencil-docs/superpowers/notes/2026-05-02-cargo-deny-validation.md
[graph]
all-features = false
# 限定到实际发布目标(macOS/Linux/Windows native + wasm32)。
# 不限定的话 cargo-deny 默认尝试所有 target(含 Android/iOS),
# 拉进 jni / android-activity 等 edition-2024 deps,在 rustc 1.82 上 cargo metadata 失败。
targets = [
{ triple = "x86_64-unknown-linux-gnu" },
{ triple = "aarch64-unknown-linux-gnu" },
{ triple = "x86_64-apple-darwin" },
{ triple = "aarch64-apple-darwin" },
{ triple = "x86_64-pc-windows-msvc" },
{ triple = "wasm32-unknown-unknown" },
]
[licenses]
allow = [
"MIT",
"Apache-2.0",
"Apache-2.0 WITH LLVM-exception",
"BSD-2-Clause",
"BSD-3-Clause",
"ISC",
"Unicode-DFS-2016",
"Unicode-3.0",
"CDLA-Permissive-2.0",
"MPL-2.0",
"Zlib",
]
confidence-threshold = 0.93
[advisories]
yanked = "deny"
ignore = []
[bans]
multiple-versions = "warn"
wildcards = "deny"
# 允许 workspace 内部 path 依赖不写 version(标准实践,避免每次 bump 都改两处)。
allow-wildcard-paths = true
deny = [
# WASM bundle 黑名单(kickoff spec §1.2 invariant)
"pen-agent-cli",
"pen-server",
"agent",
"native-tls",
]
[[bans.features]]
crate = "tokio"
deny = ["process", "rt-multi-thread"]
[sources]
unknown-registry = "deny"
unknown-git = "deny"
allow-git = [
"https://github.com/ZSeven-W/agent-rs",
]