# cargo-deny configuration. # # Without this file the cargo-deny GitHub action uses an empty license # allow-list and rejects every crate. The allow-list below covers the # permissive licenses present in the dependency tree. [advisories] version = 2 # Keep in step with .github/workflows/audit.yml. Everything patchable is # fixed in Cargo.lock (1.6.3: h2 0.4.19, rustls 0.23.45, lru 0.18, # prometheus 0.14 -> protobuf 3.7). What remains comes only through pgrx 0.17 # and cannot be fixed here; revisit when pgrx updates. ignore = [ "RUSTSEC-2024-0436", # paste unmaintained (informational); proc-macro via pgrx-tests 0.17 "RUSTSEC-2021-0127", # serde_cbor unmaintained (informational); via pgrx 0.17 "RUSTSEC-2026-0215", # smallstr unmaintained (informational); CLI-only, via linefeed 0.6 -> mortal 0.2 REPL line editor ] [licenses] version = 2 allow = [ "Apache-2.0", "MIT", "ISC", "BSD-2-Clause", "BSD-3-Clause", "BSL-1.0", "Unicode-3.0", "Unlicense", "Zlib", "MPL-2.0", # vendored gc/gc_derive (file-level copyleft) + option-ext; compatible in an Apache-2.0 repo "CC0-1.0", # constant_time_eq (public-domain-equivalent) "WTFPL", # terminfo, via the CLI's terminal handling (permissive) "CDLA-Permissive-2.0", # webpki-roots CA data (permissive), via the DuckDB extension deps ] # Crates whose only license alternatives are copyleft are accepted via the # permissive arm of their OR expression; cargo-deny picks the allowed one. confidence-threshold = 0.8 [bans] multiple-versions = "allow" wildcards = "allow" [sources] unknown-registry = "deny" unknown-git = "allow" allow-registry = ["https://github.com/rust-lang/crates.io-index"]