2020-04-16 11:03:28 +00:00
|
|
|
[advisories]
|
2024-08-06 06:05:44 +00:00
|
|
|
version = 2
|
2020-04-16 11:03:28 +00:00
|
|
|
db-path = "~/.cargo/advisory-db"
|
2020-11-20 08:03:52 +00:00
|
|
|
db-urls = ["https://github.com/rustsec/advisory-db"]
|
2020-06-05 09:33:13 +00:00
|
|
|
ignore = [
|
2022-01-12 15:47:47 +00:00
|
|
|
# Waiting for https://github.com/librespot-org/librespot/issues/937
|
|
|
|
"RUSTSEC-2021-0059",
|
|
|
|
"RUSTSEC-2021-0060",
|
|
|
|
"RUSTSEC-2021-0061",
|
2022-08-16 10:24:04 +00:00
|
|
|
# sodiumoxide is deprecated
|
2024-09-10 06:03:58 +00:00
|
|
|
# https://gitlab.freedesktop.org/gstreamer/gst-plugins-rs/-/issues/530
|
2022-08-16 10:24:04 +00:00
|
|
|
"RUSTSEC-2021-0137",
|
2020-06-05 09:33:13 +00:00
|
|
|
]
|
2020-04-16 11:03:28 +00:00
|
|
|
|
|
|
|
[licenses]
|
2024-08-06 06:05:44 +00:00
|
|
|
version = 2
|
2020-04-16 11:03:28 +00:00
|
|
|
allow = [
|
2024-08-06 06:05:44 +00:00
|
|
|
"MIT",
|
|
|
|
"BSD-2-Clause",
|
|
|
|
"BSD-3-Clause",
|
|
|
|
"ISC",
|
|
|
|
"OpenSSL",
|
|
|
|
"Zlib",
|
|
|
|
"Unicode-DFS-2016",
|
|
|
|
"Apache-2.0",
|
|
|
|
"Apache-2.0 WITH LLVM-exception",
|
2023-10-04 16:00:08 +00:00
|
|
|
"MPL-2.0",
|
2020-04-16 11:03:28 +00:00
|
|
|
]
|
|
|
|
confidence-threshold = 0.8
|
|
|
|
|
2021-12-09 10:04:11 +00:00
|
|
|
[[licenses.clarify]]
|
2022-06-21 06:44:57 +00:00
|
|
|
name = "ring"
|
2021-12-09 10:04:11 +00:00
|
|
|
version = "*"
|
2022-06-21 06:44:57 +00:00
|
|
|
expression = "OpenSSL"
|
2021-12-09 10:04:11 +00:00
|
|
|
license-files = [
|
2022-06-21 06:44:57 +00:00
|
|
|
{ path = "LICENSE", hash = 0xbd0eed23 }
|
2021-12-09 10:04:11 +00:00
|
|
|
]
|
|
|
|
|
2023-10-02 06:29:39 +00:00
|
|
|
# Allow AGPL3 from dssim-core, which is optionally used in gst-plugin-videofx
|
|
|
|
[[licenses.exceptions]]
|
|
|
|
allow = ["AGPL-3.0"]
|
|
|
|
name = "dssim-core"
|
|
|
|
version = "3.2"
|
|
|
|
|
2023-10-04 16:00:08 +00:00
|
|
|
# Allow LGPL 2.1 for the threadshare plugin as it includes some LGPL code
|
|
|
|
[[licenses.exceptions]]
|
|
|
|
allow = ["LGPL-2.1"]
|
|
|
|
name = "gst-plugin-threadshare"
|
|
|
|
|
2020-04-16 11:03:28 +00:00
|
|
|
[bans]
|
2020-04-28 10:16:08 +00:00
|
|
|
multiple-versions = "deny"
|
2020-04-16 11:03:28 +00:00
|
|
|
highlight = "all"
|
2020-08-10 06:51:52 +00:00
|
|
|
wildcards = "allow"
|
2020-04-16 11:03:28 +00:00
|
|
|
|
2021-09-11 05:45:25 +00:00
|
|
|
# ignore duplicated crc dependency because ffv1 depends on an old version
|
|
|
|
# https://github.com/rust-av/ffv1/issues/21
|
|
|
|
[[bans.skip]]
|
|
|
|
name = "crc"
|
|
|
|
version = "1.8"
|
|
|
|
|
2022-12-19 07:54:50 +00:00
|
|
|
# Ignore various duplicated dependencies because librespot depends on an old versions
|
2022-02-12 10:40:00 +00:00
|
|
|
[[bans.skip]]
|
|
|
|
name = "block-buffer"
|
|
|
|
version = "0.9"
|
|
|
|
[[bans.skip]]
|
|
|
|
name = "digest"
|
|
|
|
version = "0.9"
|
|
|
|
[[bans.skip]]
|
|
|
|
name = "sha-1"
|
|
|
|
version = "0.9"
|
2022-12-19 07:54:50 +00:00
|
|
|
[[bans.skip]]
|
|
|
|
name = "hmac"
|
|
|
|
version = "0.11"
|
2024-02-09 08:05:45 +00:00
|
|
|
[[bans.skip]]
|
|
|
|
name = "zerocopy"
|
|
|
|
version = "0.6"
|
2024-04-06 07:49:10 +00:00
|
|
|
[[bans.skip]]
|
2024-08-06 06:10:08 +00:00
|
|
|
name = "zerocopy-derive"
|
|
|
|
version = "0.6"
|
|
|
|
[[bans.skip]]
|
2024-06-17 07:21:37 +00:00
|
|
|
name = "hermit-abi"
|
|
|
|
version = "0.3"
|
2023-06-30 08:12:52 +00:00
|
|
|
|
2023-01-11 08:30:45 +00:00
|
|
|
# Various crates depend on an older version of base64
|
|
|
|
[[bans.skip]]
|
|
|
|
name = "base64"
|
|
|
|
version = "0.13"
|
2024-04-06 07:49:10 +00:00
|
|
|
[[bans.skip]]
|
|
|
|
name = "base64"
|
|
|
|
version = "0.21"
|
2023-01-11 08:30:45 +00:00
|
|
|
|
2023-07-07 06:08:50 +00:00
|
|
|
# Various crates depend on an older version of bitflags
|
|
|
|
[[bans.skip]]
|
|
|
|
name = "bitflags"
|
|
|
|
version = "1.0"
|
|
|
|
|
2023-04-21 09:58:01 +00:00
|
|
|
# tracing-subscriber depends on an older version of regex-syntax
|
|
|
|
[[bans.skip]]
|
|
|
|
name = "regex-syntax"
|
|
|
|
version = "0.6"
|
|
|
|
|
2023-06-09 06:42:10 +00:00
|
|
|
# publicsuffix depends on an older version of idna
|
|
|
|
# https://github.com/rushmorem/publicsuffix/pull/39
|
|
|
|
[[bans.skip]]
|
|
|
|
name = "idna"
|
|
|
|
version = "0.3"
|
|
|
|
|
2023-06-26 11:24:08 +00:00
|
|
|
# Various crates depend on an older version of indexmap / hashbrown
|
|
|
|
[[bans.skip]]
|
|
|
|
name = "indexmap"
|
|
|
|
version = "1.0"
|
2023-06-15 07:16:43 +00:00
|
|
|
[[bans.skip]]
|
2023-06-26 11:24:08 +00:00
|
|
|
name = "hashbrown"
|
|
|
|
version = "0.12"
|
2023-06-15 07:16:43 +00:00
|
|
|
|
2024-06-25 07:58:56 +00:00
|
|
|
# various livekit dependencies depend on an old version of itertools and sync_wrapper
|
2023-06-27 07:58:57 +00:00
|
|
|
[[bans.skip]]
|
|
|
|
name = "itertools"
|
2024-01-14 09:44:16 +00:00
|
|
|
version = "0.11"
|
2024-06-25 07:58:56 +00:00
|
|
|
[[bans.skip]]
|
|
|
|
name = "sync_wrapper"
|
|
|
|
version = "0.1"
|
2023-06-27 07:58:57 +00:00
|
|
|
|
2024-05-20 11:36:39 +00:00
|
|
|
# various rav1e / dssim-core depend on an old version of itertools
|
|
|
|
[[bans.skip]]
|
|
|
|
name = "itertools"
|
|
|
|
version = "0.12"
|
|
|
|
|
2023-07-06 05:55:14 +00:00
|
|
|
# matchers depends on an old version of regex-automata
|
|
|
|
[[bans.skip]]
|
|
|
|
name = "regex-automata"
|
|
|
|
version = "0.1"
|
|
|
|
|
2023-11-17 09:22:47 +00:00
|
|
|
# Various crates depend on old versions of the windows crates
|
|
|
|
[[bans.skip]]
|
|
|
|
name = "windows_x86_64_msvc"
|
|
|
|
version = "0.48"
|
|
|
|
[[bans.skip]]
|
|
|
|
name = "windows_x86_64_gnullvm"
|
|
|
|
version = "0.48"
|
|
|
|
[[bans.skip]]
|
|
|
|
name = "windows_x86_64_gnu"
|
|
|
|
version = "0.48"
|
|
|
|
[[bans.skip]]
|
|
|
|
name = "windows_i686_msvc"
|
|
|
|
version = "0.48"
|
|
|
|
[[bans.skip]]
|
|
|
|
name = "windows_i686_gnu"
|
|
|
|
version = "0.48"
|
|
|
|
[[bans.skip]]
|
|
|
|
name = "windows_aarch64_msvc"
|
|
|
|
version = "0.48"
|
|
|
|
[[bans.skip]]
|
|
|
|
name = "windows_aarch64_gnullvm"
|
|
|
|
version = "0.48"
|
|
|
|
[[bans.skip]]
|
|
|
|
name = "windows-targets"
|
|
|
|
version = "0.48"
|
|
|
|
[[bans.skip]]
|
|
|
|
name = "windows-sys"
|
|
|
|
version = "0.48"
|
|
|
|
|
2023-11-20 08:24:20 +00:00
|
|
|
# Various crates depend on an older version of crypto-bigint
|
|
|
|
[[bans.skip]]
|
|
|
|
name = "crypto-bigint"
|
|
|
|
version = "0.4"
|
|
|
|
|
2023-12-09 10:28:10 +00:00
|
|
|
# livekit-api depends on an older version of tokio-tungstenite
|
|
|
|
[[bans.skip]]
|
|
|
|
name = "tokio-tungstenite"
|
|
|
|
version = "0.20"
|
|
|
|
[[bans.skip]]
|
|
|
|
name = "tungstenite"
|
|
|
|
version = "0.20"
|
|
|
|
|
|
|
|
# Various crates depend on an older version of http
|
|
|
|
[[bans.skip]]
|
|
|
|
name = "http"
|
|
|
|
version = "0.2"
|
|
|
|
|
2024-03-19 15:52:32 +00:00
|
|
|
# Various crates depend on an older version of heck
|
|
|
|
[[bans.skip]]
|
|
|
|
name = "heck"
|
|
|
|
version = "0.4"
|
|
|
|
|
2024-03-24 09:30:30 +00:00
|
|
|
# Various crates depend on an older version of hyper / reqwest / headers / etc
|
|
|
|
[[bans.skip]]
|
|
|
|
name = "hyper"
|
|
|
|
version = "0.14"
|
|
|
|
[[bans.skip]]
|
|
|
|
name = "hyper-tls"
|
|
|
|
version = "0.5"
|
|
|
|
[[bans.skip]]
|
|
|
|
name = "http-body"
|
|
|
|
version = "0.4"
|
|
|
|
[[bans.skip]]
|
|
|
|
name = "headers-core"
|
|
|
|
version = "0.2"
|
|
|
|
[[bans.skip]]
|
|
|
|
name = "headers"
|
|
|
|
version = "0.3"
|
|
|
|
[[bans.skip]]
|
|
|
|
name = "h2"
|
|
|
|
version = "0.3"
|
|
|
|
[[bans.skip]]
|
|
|
|
name = "reqwest"
|
|
|
|
version = "0.11"
|
2024-04-06 07:49:10 +00:00
|
|
|
[[bans.skip]]
|
|
|
|
name = "rustls-pemfile"
|
|
|
|
version = "1.0"
|
|
|
|
[[bans.skip]]
|
|
|
|
name = "winreg"
|
|
|
|
version = "0.50"
|
2024-08-27 18:10:48 +00:00
|
|
|
[[bans.skip]]
|
|
|
|
name = "system-configuration"
|
|
|
|
version = "0.5"
|
|
|
|
[[bans.skip]]
|
|
|
|
name = "system-configuration-sys"
|
|
|
|
version = "0.5"
|
2024-03-24 09:30:30 +00:00
|
|
|
|
2024-05-10 06:41:19 +00:00
|
|
|
# The AWS SDK uses old versions of rustls and related crates
|
|
|
|
[[bans.skip]]
|
|
|
|
name = "rustls"
|
|
|
|
version = "0.21"
|
|
|
|
[[bans.skip]]
|
|
|
|
name = "rustls-native-certs"
|
|
|
|
version = "0.6"
|
|
|
|
[[bans.skip]]
|
|
|
|
name = "rustls-webpki"
|
|
|
|
version = "0.101"
|
|
|
|
|
2024-06-06 06:08:19 +00:00
|
|
|
# warp depends on an older version of tokio-tungstenite
|
|
|
|
[[bans.skip]]
|
|
|
|
name = "tokio-tungstenite"
|
|
|
|
version = "0.21"
|
|
|
|
[[bans.skip]]
|
|
|
|
name = "tungstenite"
|
|
|
|
version = "0.21"
|
|
|
|
|
2024-06-21 06:11:53 +00:00
|
|
|
# various crates depend on an older version of system-deps
|
|
|
|
[[bans.skip]]
|
|
|
|
name = "system-deps"
|
|
|
|
version = "6"
|
|
|
|
|
2024-08-06 06:10:08 +00:00
|
|
|
# various crates depend on an older version of windows-sys
|
|
|
|
[[bans.skip]]
|
|
|
|
name = "windows-sys"
|
|
|
|
version = "0.52"
|
|
|
|
|
|
|
|
# derived-into-owned (via pcap-file) depends on old syn / quote
|
|
|
|
[[bans.skip]]
|
|
|
|
name = "syn"
|
|
|
|
version = "0.11"
|
|
|
|
[[bans.skip]]
|
|
|
|
name = "quote"
|
|
|
|
version = "0.3"
|
|
|
|
|
2024-08-27 18:10:48 +00:00
|
|
|
# dav1d depends on old system-deps which depends on old cfg-expr
|
|
|
|
[[bans.skip]]
|
|
|
|
name = "cfg-expr"
|
|
|
|
version = "0.15"
|
|
|
|
|
|
|
|
# tokio-rustls via warp depends on old rustls
|
|
|
|
[[bans.skip]]
|
|
|
|
name = "rustls"
|
|
|
|
version = "0.22"
|
|
|
|
|
|
|
|
# aws-smithy-runtime depends on old tokio-rustls
|
|
|
|
[[bans.skip]]
|
|
|
|
name = "tokio-rustls"
|
|
|
|
version = "0.24"
|
|
|
|
|
2020-04-16 11:03:28 +00:00
|
|
|
[sources]
|
|
|
|
unknown-registry = "deny"
|
|
|
|
unknown-git = "deny"
|
|
|
|
allow-git = [
|
|
|
|
"https://gitlab.freedesktop.org/gstreamer/gstreamer-rs",
|
2021-05-14 07:47:52 +00:00
|
|
|
"https://github.com/gtk-rs/gtk-rs-core",
|
2021-10-14 07:03:17 +00:00
|
|
|
"https://github.com/gtk-rs/gtk4-rs",
|
2021-09-10 06:20:31 +00:00
|
|
|
"https://github.com/rust-av/ffv1",
|
2020-04-16 11:03:28 +00:00
|
|
|
"https://github.com/rust-av/flavors",
|
|
|
|
]
|