[advisories] db-path = "~/.cargo/advisory-db" db-urls = ["https://github.com/rustsec/advisory-db"] vulnerability = "deny" unmaintained = "warn" notice = "warn" ignore = [ ] [licenses] unlicensed = "deny" allow = [ "Apache-2.0", ] deny = [ "GPL-1.0", "GPL-2.0", "GPL-3.0", "AGPL-1.0", "AGPL-3.0", ] copyleft = "allow" allow-osi-fsf-free = "either" confidence-threshold = 0.8 [bans] multiple-versions = "deny" highlight = "all" wildcards = "allow" # ignore duplicated deps because of mio-named-pipes via mio depending on old # miow # https://github.com/alexcrichton/mio-named-pipes/issues/7 [[bans.skip]] name = "miow" version = "0.2" [[bans.skip]] name = "winapi" version = "0.2" # ignore duplicated deps because of chrono, cookie, cookie_store, hyper, # hyperx, reqwest depending on old time # https://github.com/chronotope/chrono/issues/400 # https://github.com/pfernie/cookie_store/issues/11 # https://github.com/hyperium/hyper/pull/2139 # https://github.com/dekellum/hyperx/issues/21 # https://github.com/seanmonstar/reqwest/issues/934 [[bans.skip]] name = "time" version = "0.1" # ignore duplicated tokio dep because of gst-plugin-threadshare having its own # fork # https://gitlab.freedesktop.org/gstreamer/gst-plugins-rs/-/issues/118 [[bans.skip]] name = "tokio" version = "0.2.13" [[bans.skip]] name = "tokio-macros" # ignore duplicated textwrap dependency because clap depends on an old version # https://github.com/clap-rs/clap/pull/1994 [[bans.skip]] name = "textwrap" version = "0.11" # ignore duplicated miniz_oxide dependency because png/tiff depend on an old version # https://github.com/image-rs/image-tiff/pull/76 # https://github.com/image-rs/image-png/pull/235 [[bans.skip]] name = "miniz_oxide" version = "0.3" # ignore duplicated cfg-if dependency because a few dozen dependencies still # pull in the old version [[bans.skip]] name = "cfg-if" version = "0.1" # ignore duplicated pin-project dependency because a futures, hyper and rusoto # still depend on the old version # https://github.com/rust-lang/futures-rs/commit/8a65340675fdf0ba16997cf507ee6bb27d1dcd15 # https://github.com/hyperium/hyper/commit/02732bef0c1accb441b9b14c07cb2c494234a682 # https://github.com/rusoto/rusoto/pull/1847 [[bans.skip]] name = "pin-project" version = "0.4" [[bans.skip]] name = "pin-project-internal" version = "0.4" # ignore duplicated pin-project-lite dependency because many crates depend on an old version [[bans.skip]] name = "pin-project-lite" version = "0.1" # ignore duplicated nom dependency because cexpr depends on an old version # https://github.com/jethrogb/rust-cexpr/issues/26 [[bans.skip]] name = "nom" version = "5" # ignore duplicated nom dependency because tokio v0.2 depends on an old version [[bans.skip]] name = "bytes" version = "0.5" [[bans.skip]] name = "mio" version = "0.6" # ignore duplicated redox_syscall dependency because parking_lot/dirs-next depends on an old version [[bans.skip]] name = "redox_syscall" version = "0.1" # ignore duplicated rustc_version dependency because various crates depend on an old version [[bans.skip]] name = "rustc_version" version = "0.2" [[bans.skip]] name = "semver" version = "0.9" [[bans.skip]] name = "semver-parser" version = "0.7" # ignore duplicated system-deps dependency because dav1d depends on an old version [[bans.skip]] name = "system-deps" version = "2.0" [sources] unknown-registry = "deny" unknown-git = "deny" allow-git = [ "https://gitlab.freedesktop.org/gstreamer/gstreamer-rs", "https://github.com/gtk-rs/gtk-rs", "https://github.com/fengalin/tokio", "https://github.com/rust-av/flavors", ]