CI: allow CDLA-Permissive-2.0 for the CA root bundle; drop MPL-2.0
cargo-deny correctly rejected webpki-root-certs (CDLA-Permissive-2.0), reached via hickory-resolver -> rustls-platform-verifier. CDLA-Permissive-2.0 is a data licence on the Mozilla CA root list, permissive, with no reciprocal obligation on code that uses the data. Allowed deliberately, with the reasoning in deny.toml rather than as a silent entry. MPL-2.0 removed: nothing needs it, and pre-authorising unused licences makes the policy something nobody reads carefully. If a dependency pulls it in, CI fails and someone decides on purpose. Diagnostic step removed — PATH in the workflow env is what fixed the runner; the .path/.env files were not being applied. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01JkyvfNJGTshJNE9FtwPLk7
This commit is contained in:
co-authored by
Claude Opus 5
parent
bb8f32ee61
commit
c24f71518a
@@ -44,11 +44,6 @@ jobs:
|
|||||||
runs-on: [self-hosted, Linux, ARM64, spark-1]
|
runs-on: [self-hosted, Linux, ARM64, spark-1]
|
||||||
steps:
|
steps:
|
||||||
- uses: actions/checkout@v5
|
- uses: actions/checkout@v5
|
||||||
- name: toolchain
|
|
||||||
run: |
|
|
||||||
echo "PATH=$PATH"
|
|
||||||
command -v cargo || echo "cargo NOT on PATH"
|
|
||||||
cargo --version
|
|
||||||
- run: cargo fmt --all --check
|
- run: cargo fmt --all --check
|
||||||
- run: cargo clippy --workspace --all-targets --all-features
|
- run: cargo clippy --workspace --all-targets --all-features
|
||||||
- run: cargo test --workspace --all-features
|
- run: cargo test --workspace --all-features
|
||||||
|
|||||||
@@ -16,9 +16,18 @@ allow = [
|
|||||||
"Unicode-3.0",
|
"Unicode-3.0",
|
||||||
"Zlib",
|
"Zlib",
|
||||||
"CC0-1.0",
|
"CC0-1.0",
|
||||||
"MPL-2.0", # file-level copyleft; acceptable as a leaf dependency
|
|
||||||
"Apache-2.0 WITH LLVM-exception",
|
"Apache-2.0 WITH LLVM-exception",
|
||||||
|
# CDLA-Permissive-2.0 covers `webpki-root-certs` — the Mozilla CA root
|
||||||
|
# bundle. It is a DATA licence on a certificate list, not a code licence,
|
||||||
|
# and it is permissive with no reciprocal obligations on anything that uses
|
||||||
|
# the data. Reached via hickory-resolver -> rustls-platform-verifier.
|
||||||
|
"CDLA-Permissive-2.0",
|
||||||
]
|
]
|
||||||
|
|
||||||
|
# MPL-2.0 is deliberately NOT allowed. Nothing needs it today, and a policy
|
||||||
|
# that pre-authorises licences it does not use is a policy nobody reads
|
||||||
|
# carefully. If a dependency ever pulls it in, CI fails and someone decides on
|
||||||
|
# purpose — which is the point.
|
||||||
confidence-threshold = 0.9
|
confidence-threshold = 0.9
|
||||||
|
|
||||||
# Everything not in `allow` fails — including every GPL, LGPL and AGPL variant.
|
# Everything not in `allow` fails — including every GPL, LGPL and AGPL variant.
|
||||||
|
|||||||
Reference in New Issue
Block a user