gst-plugins-rs/deny.toml

167 lines
4 KiB
TOML
Raw Normal View History

[advisories]
db-path = "~/.cargo/advisory-db"
2020-11-20 08:03:52 +00:00
db-urls = ["https://github.com/rustsec/advisory-db"]
vulnerability = "deny"
unmaintained = "warn"
notice = "warn"
2020-06-05 09:33:13 +00:00
ignore = [
2022-01-12 15:47:47 +00:00
# Waiting for https://github.com/librespot-org/librespot/issues/937
"RUSTSEC-2021-0059",
"RUSTSEC-2021-0060",
"RUSTSEC-2021-0061",
2022-06-06 08:58:46 +00:00
# https://github.com/chronotope/chrono/issues/499
"RUSTSEC-2020-0071",
2022-08-16 10:24:04 +00:00
# sodiumoxide is deprecated
"RUSTSEC-2021-0137",
2022-10-25 07:54:29 +00:00
# https://gitlab.freedesktop.org/gstreamer/gst-plugins-rs/-/issues/256
"RUSTSEC-2022-0048",
2020-06-05 09:33:13 +00:00
]
[licenses]
unlicensed = "deny"
allow = [
"Apache-2.0",
]
deny = [
"GPL-1.0",
"GPL-2.0",
"GPL-3.0",
"AGPL-1.0",
"AGPL-3.0",
]
copyleft = "allow"
allow-osi-fsf-free = "either"
confidence-threshold = 0.8
[[licenses.clarify]]
2022-06-21 06:44:57 +00:00
name = "ring"
version = "*"
2022-06-21 06:44:57 +00:00
expression = "OpenSSL"
license-files = [
2022-06-21 06:44:57 +00:00
{ path = "LICENSE", hash = 0xbd0eed23 }
]
[bans]
multiple-versions = "deny"
highlight = "all"
2020-08-10 06:51:52 +00:00
wildcards = "allow"
# ignore duplicated deps because of chrono, cookie, cookie_store, hyper,
# hyperx, reqwest depending on old time
# https://github.com/chronotope/chrono/issues/400
# https://github.com/pfernie/cookie_store/issues/11
# https://github.com/hyperium/hyper/pull/2139
# https://github.com/dekellum/hyperx/issues/21
# https://github.com/seanmonstar/reqwest/issues/934
[[bans.skip]]
name = "time"
version = "0.1"
2021-06-08 05:52:31 +00:00
# ignore duplicated rustc_version dependency because rav1e depends on an old version
[[bans.skip]]
name = "rustc_version"
version = "0.3"
[[bans.skip]]
name = "semver"
version = "0.11"
2022-10-25 07:54:29 +00:00
# ignore duplicated system-deps dependency because rav1e depends on an old version
2021-08-26 06:24:54 +00:00
[[bans.skip]]
2021-09-01 05:58:59 +00:00
name = "system-deps"
version = "3"
[[bans.skip]]
name = "version-compare"
version = "0.0"
2021-09-01 05:58:59 +00:00
[[bans.skip]]
name = "cfg-expr"
2021-11-17 08:16:18 +00:00
version = "0.7"
2021-08-26 06:24:54 +00:00
2021-09-11 05:45:25 +00:00
# ignore duplicated crc dependency because ffv1 depends on an old version
# https://github.com/rust-av/ffv1/issues/21
[[bans.skip]]
name = "crc"
version = "1.8"
2021-12-18 08:08:48 +00:00
# ignore duplicated heck dependency because various crates depend on an old version
[[bans.skip]]
name = "heck"
version = "0.3"
2022-02-12 10:40:00 +00:00
# ignore duplicated sha-1/digest/block-buffer dependencies because librespot depends on an old version
[[bans.skip]]
name = "block-buffer"
version = "0.9"
[[bans.skip]]
name = "digest"
version = "0.9"
[[bans.skip]]
name = "sha-1"
version = "0.9"
# ignore duplicated wasi dependency because various crates depends on an old version
[[bans.skip]]
name = "wasi"
version = "0.10"
2022-07-11 15:30:54 +00:00
# ignore duplicated spin dependency because various crates depend on an old version
[[bans.skip]]
name = "spin"
version = "0.5"
2022-10-25 07:54:29 +00:00
# Various crates depend on older versions of the windows crates
[[bans.skip]]
name = "windows-sys"
version = "0.36"
[[bans.skip]]
name = "windows_aarch64_msvc"
version = "0.36"
[[bans.skip]]
name = "windows_i686_gnu"
version = "0.36"
[[bans.skip]]
name = "windows_i686_msvc"
version = "0.36"
[[bans.skip]]
name = "windows_x86_64_gnu"
version = "0.36"
[[bans.skip]]
name = "windows_x86_64_msvc"
version = "0.36"
# Various crates depend on older miniz_oxide
# https://github.com/rust-lang/backtrace-rs/pull/483
# https://github.com/rust-lang/flate2-rs/pull/317
# https://github.com/image-rs/image-png/pull/355
[[bans.skip]]
name = "miniz_oxide"
version = "0.5"
# cookie_store depends on older idna
# https://github.com/pfernie/cookie_store/commit/b9c710f45550c5c8997f18a83e6fcc5998cf1726
[[bans.skip]]
name = "idna"
version = "0.2"
# image_hasher depends on an alpha version of base64
[[bans.skip]]
name = "base64"
version = "0.20.0-alpha.1"
2022-11-09 07:15:55 +00:00
# async-io / async-channel depend on an old version of concurrent-queue
# https://github.com/smol-rs/async-channel/pull/50
# https://github.com/smol-rs/async-io/pull/99
[[bans.skip]]
name = "concurrent-queue"
version = "1"
[sources]
unknown-registry = "deny"
unknown-git = "deny"
allow-git = [
"https://gitlab.freedesktop.org/gstreamer/gstreamer-rs",
2021-05-14 07:47:52 +00:00
"https://github.com/gtk-rs/gtk-rs-core",
"https://github.com/gtk-rs/gtk4-rs",
2021-09-10 06:20:31 +00:00
"https://github.com/rust-av/ffv1",
"https://github.com/rust-av/flavors",
]