CI: allow CDLA-Permissive-2.0 for the CA root bundle; drop MPL-2.0

cargo-deny correctly rejected webpki-root-certs (CDLA-Permissive-2.0),
reached via hickory-resolver -> rustls-platform-verifier. CDLA-Permissive-2.0
is a data licence on the Mozilla CA root list, permissive, with no
reciprocal obligation on code that uses the data. Allowed deliberately, with
the reasoning in deny.toml rather than as a silent entry.

MPL-2.0 removed: nothing needs it, and pre-authorising unused licences makes
the policy something nobody reads carefully. If a dependency pulls it in,
CI fails and someone decides on purpose.

Diagnostic step removed — PATH in the workflow env is what fixed the runner;
the .path/.env files were not being applied.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01JkyvfNJGTshJNE9FtwPLk7
This commit is contained in:
Karti Tripathi
2026-09-02 13:57:59 -07:00
co-authored by Claude Opus 5
parent bb8f32ee61
commit c24f71518a
2 changed files with 10 additions and 6 deletions
-5
View File
@@ -44,11 +44,6 @@ jobs:
runs-on: [self-hosted, Linux, ARM64, spark-1]
steps:
- uses: actions/checkout@v5
- name: toolchain
run: |
echo "PATH=$PATH"
command -v cargo || echo "cargo NOT on PATH"
cargo --version
- run: cargo fmt --all --check
- run: cargo clippy --workspace --all-targets --all-features
- run: cargo test --workspace --all-features