From c24f71518ab1965d56bd78268eb680080b1421ff Mon Sep 17 00:00:00 2001 From: Karti Tripathi <176560021+karti-ai@users.noreply.github.com> Date: Wed, 2 Sep 2026 13:57:59 -0700 Subject: [PATCH] CI: allow CDLA-Permissive-2.0 for the CA root bundle; drop MPL-2.0 MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit cargo-deny correctly rejected webpki-root-certs (CDLA-Permissive-2.0), reached via hickory-resolver -> rustls-platform-verifier. CDLA-Permissive-2.0 is a data licence on the Mozilla CA root list, permissive, with no reciprocal obligation on code that uses the data. Allowed deliberately, with the reasoning in deny.toml rather than as a silent entry. MPL-2.0 removed: nothing needs it, and pre-authorising unused licences makes the policy something nobody reads carefully. If a dependency pulls it in, CI fails and someone decides on purpose. Diagnostic step removed — PATH in the workflow env is what fixed the runner; the .path/.env files were not being applied. Co-Authored-By: Claude Opus 5 (1M context) Claude-Session: https://claude.ai/code/session_01JkyvfNJGTshJNE9FtwPLk7 --- .github/workflows/ci.yml | 5 ----- deny.toml | 11 ++++++++++- 2 files changed, 10 insertions(+), 6 deletions(-) diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 62b0907..1ef776e 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -44,11 +44,6 @@ jobs: runs-on: [self-hosted, Linux, ARM64, spark-1] steps: - uses: actions/checkout@v5 - - name: toolchain - run: | - echo "PATH=$PATH" - command -v cargo || echo "cargo NOT on PATH" - cargo --version - run: cargo fmt --all --check - run: cargo clippy --workspace --all-targets --all-features - run: cargo test --workspace --all-features diff --git a/deny.toml b/deny.toml index 1962587..37bd5e2 100644 --- a/deny.toml +++ b/deny.toml @@ -16,9 +16,18 @@ allow = [ "Unicode-3.0", "Zlib", "CC0-1.0", - "MPL-2.0", # file-level copyleft; acceptable as a leaf dependency "Apache-2.0 WITH LLVM-exception", + # CDLA-Permissive-2.0 covers `webpki-root-certs` — the Mozilla CA root + # bundle. It is a DATA licence on a certificate list, not a code licence, + # and it is permissive with no reciprocal obligations on anything that uses + # the data. Reached via hickory-resolver -> rustls-platform-verifier. + "CDLA-Permissive-2.0", ] + +# MPL-2.0 is deliberately NOT allowed. Nothing needs it today, and a policy +# that pre-authorises licences it does not use is a policy nobody reads +# carefully. If a dependency ever pulls it in, CI fails and someone decides on +# purpose — which is the point. confidence-threshold = 0.9 # Everything not in `allow` fails — including every GPL, LGPL and AGPL variant.