c99cf54a1f
Bumps the Python binding from pyo3 0.22 / numpy 0.22 to 0.28 / 0.28, which resolves RUSTSEC-2025-0020 — a buffer overflow in `PyString::from_object` that affected every published Python wheel. Migration: - `into_pyarray_bound(py)` → `into_pyarray(py)` (numpy 0.23 dropped the `_bound` transitional suffix; the method now returns `Bound<'py, _>` directly). - `downcast::<PyDict>` → `cast::<PyDict>` (pyo3 renamed the method on `PyAnyMethods`). - Every `#[pyclass]` declares `skip_from_py_object` to opt out of the now-deprecated automatic `FromPyObject` derive for `Clone` types. Indicators are stateful — silently extracting them by value-clone is never the intended FFI semantics. - Workspace clippy gains `unused_self = "allow"` on the python crate only: Python's `__repr__` protocol forces `&self` even for parameter- less indicators where the body does not read state. - `map_err` arms collapsed into a single `PyValueError` arm (clippy::match_same_arms). `deny.toml` no longer suppresses RUSTSEC-2025-0020; `cargo deny check` is green on advisories, bans, licenses and sources without exceptions.
49 lines
1.5 KiB
TOML
49 lines
1.5 KiB
TOML
# cargo-deny configuration — supply-chain checks for the Wickra workspace.
|
|
# Run locally with `cargo deny check`; CI runs the same in the `supply-chain`
|
|
# job (see .github/workflows/ci.yml).
|
|
|
|
[graph]
|
|
all-features = true
|
|
|
|
[advisories]
|
|
# Fail on any security advisory or unmaintained/unsound crate in the tree.
|
|
version = 2
|
|
yanked = "deny"
|
|
|
|
[bans]
|
|
# Catch accidental duplicate versions and wildcard ("*") version requirements.
|
|
multiple-versions = "warn"
|
|
wildcards = "deny"
|
|
# Internal workspace crates are referenced by `path` without a version, which
|
|
# is a legitimate wildcard — only flag wildcards on external registry crates.
|
|
allow-wildcard-paths = true
|
|
|
|
[licenses]
|
|
version = 2
|
|
# Licenses permitted for every crate in the dependency graph. Wickra itself is
|
|
# PolyForm-Noncommercial-1.0.0; the rest are the permissive licenses its
|
|
# dependency tree actually uses.
|
|
allow = [
|
|
"PolyForm-Noncommercial-1.0.0",
|
|
"MIT",
|
|
"Apache-2.0",
|
|
"BSD-2-Clause",
|
|
"ISC",
|
|
"Unicode-3.0",
|
|
"BSL-1.0",
|
|
"Zlib",
|
|
"Unlicense",
|
|
]
|
|
# Crates whose SPDX expression carries a license exception (e.g. the LLVM
|
|
# exception on Apache-2.0). The exception is only granted to the named crate.
|
|
exceptions = [
|
|
{ allow = ["Apache-2.0 WITH LLVM-exception"], crate = "target-lexicon" },
|
|
]
|
|
|
|
[sources]
|
|
# Only the canonical crates.io registry is allowed; no git or alternative
|
|
# registries.
|
|
unknown-registry = "deny"
|
|
unknown-git = "deny"
|
|
allow-registry = ["https://github.com/rust-lang/crates.io-index"]
|