mirror of
https://github.com/akitaonrails/ai-memory.git
synced 2026-10-02 03:24:46 +08:00
CI runs cargo-deny with --all-features, while deny.toml set `[graph] all-features = false`. A command-line --all-features overrides the config value, so CI checked the all-features graph while the documented local gate `cargo deny check` (AGENTS.md, CONTRIBUTING.md) checked only the default-features graph. A license or advisory problem reachable only under a non-default feature passed locally and surfaced first in CI. Set `all-features = true` so the documented local command builds the same graph CI enforces. `cargo deny check` stays green after the change (advisories ok, bans ok, licenses ok, sources ok). Every other unflagged invocation (downstream, ad hoc) also widens to all features; if the narrower default-features graph was intentional the right fix is the opposite direction (drop --all-features from CI) and this can be discarded. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_016svpVgSxCEZfEbJomSCbaG
53 lines
1.3 KiB
TOML
53 lines
1.3 KiB
TOML
# cargo-deny configuration.
|
|
# Goal: reject GPL/AGPL transitive deps (license trap that cost cognee #2807)
|
|
# and pin to the official crates.io registry.
|
|
|
|
[graph]
|
|
# CI runs cargo-deny with --all-features (see .github/workflows/ci.yml), so build
|
|
# the same graph here. This keeps the documented local gate `cargo deny check`
|
|
# (AGENTS.md, CONTRIBUTING.md) checking the exact feature set CI enforces, instead
|
|
# of the narrower default-features graph.
|
|
all-features = true
|
|
no-default-features = false
|
|
|
|
[output]
|
|
feature-depth = 1
|
|
|
|
[advisories]
|
|
version = 2
|
|
ignore = [
|
|
# RUSTSEC-2024-0436: `paste` is unmaintained. Compile-time
|
|
# proc-macro helper pulled by the candle ML stack (local
|
|
# embeddings); no runtime code ships from it. Revisit when candle
|
|
# replaces it upstream.
|
|
"RUSTSEC-2024-0436",
|
|
]
|
|
|
|
[licenses]
|
|
version = 2
|
|
allow = [
|
|
"MIT",
|
|
"Apache-2.0",
|
|
"Apache-2.0 WITH LLVM-exception",
|
|
"BSD-2-Clause",
|
|
"BSD-3-Clause",
|
|
"ISC",
|
|
"Unicode-3.0",
|
|
"Zlib",
|
|
"MPL-2.0",
|
|
"CC0-1.0",
|
|
"CDLA-Permissive-2.0",
|
|
]
|
|
confidence-threshold = 0.9
|
|
exceptions = []
|
|
|
|
[bans]
|
|
multiple-versions = "allow"
|
|
wildcards = "deny"
|
|
deny = []
|
|
|
|
[sources]
|
|
unknown-registry = "deny"
|
|
unknown-git = "deny"
|
|
allow-registry = ["https://github.com/rust-lang/crates.io-index"]
|