Three gates in this repository were decorative, and each was discovered by being wrong rather than by failing. A crate directory in neither members nor exclude is silently not built, which is how lumbridge-devices shipped 1,127 lines that had never compiled. scripts/workspace-guard.sh refuses that state, and asserts the gpui source and version out of Cargo.lock rather than the manifest, because a manifest states an intent while the lockfile states what would actually be compiled -- and a caret requirement accepts a version nobody reviewed. It needs no compiler, so it runs first and in the headless job, which unlike the UI job is not continue-on-error and can therefore actually fail a push. deny.toml's source policy had never been executed: ci.sh ran `check licenses` alone, and `check sources` failed immediately on the rev-pinned buzz-sdk. The permitted Git sources are now named one by one and the check runs, so a fourth is a decision rather than an accident. cargo-deny and cargo-nextest being absent was a warning that let a run report green having skipped the licence gate DISTRIBUTION.md depends on. Under LUMBRIDGE_CI_STRICT=1 a missing tool now fails; locally it stays a warning so a contributor is not blocked. skills/lumbridge-development/SKILL.md told every agent that GPUI and Floem live in spikes/ and that no framework may be selected until both pass the hard gates. Decision 0017 settled that a month ago in the opposite direction. The entry point an agent is meant to read was the least accurate document in the repository. Decision 0023 records where the GPUI dependency actually goes. Published gpui has not been released since 2025-10-22, Zed's main still declares 0.2.2 with no bump pending, the platform backends moved to crates that inherit publish = false, gpui's own x11 and wayland features are now empty markers, and 0.2.2 has no accesskit dependency at all -- so "published now, migrate later" was never available. The adapter 0017 promised was never written and the call sites grew from few to 147 against 20 identities, so the adapter is written first, on 0.2.2, before the dependency moves. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01SPYebLiN2w4TqnHUYGdECq
70 lines
2.5 KiB
TOML
70 lines
2.5 KiB
TOML
# License policy for everything Lumbridge ships.
|
|
#
|
|
# Graduating the GPUI shell out of `spikes/` moved several hundred packages from
|
|
# a spike's dependency tree into the product's. `spikes/README.md` called GPUI's
|
|
# license closure "a hard gate" and the scorecard scored it `pending`; this is
|
|
# where that gate is enforced rather than described.
|
|
#
|
|
# cargo install cargo-deny && cargo deny check licenses
|
|
[graph]
|
|
all-features = true
|
|
|
|
[licenses]
|
|
# Permissive, plus two weak-copyleft licenses that are file-level and do not
|
|
# reach Lumbridge's own sources.
|
|
allow = [
|
|
"Apache-2.0",
|
|
"Apache-2.0 WITH LLVM-exception",
|
|
"BSD-2-Clause",
|
|
"BSD-3-Clause",
|
|
"BSL-1.0",
|
|
"CC0-1.0",
|
|
"ISC",
|
|
"MIT",
|
|
"MIT-0",
|
|
"MPL-2.0",
|
|
"Unicode-3.0",
|
|
"Unlicense",
|
|
"Zlib",
|
|
|
|
# Reviewed additions, each reached by exactly one path:
|
|
#
|
|
# CDLA-Permissive-2.0 is webpki-roots, which is Mozilla's CA root store —
|
|
# data, not code, under a permissive data licence with no copyleft and no
|
|
# attribution requirement on downstream distribution. It arrives through
|
|
# ureq, which the Claude usage endpoint needs (decision 0016).
|
|
"CDLA-Permissive-2.0",
|
|
# NCSA is libfuzzer-sys, a permissive BSD/MIT-style licence. It reaches the
|
|
# graph only as rav1e -> ravif -> image -> gpui and only under
|
|
# `all-features`; no shipped build links it. Allowed rather than excluded so
|
|
# the audit stays strict everywhere else.
|
|
"NCSA",
|
|
]
|
|
# A dependency whose license cannot be determined is not a licensing question to
|
|
# settle later; it is a blocker now.
|
|
unused-allowed-license = "allow"
|
|
confidence-threshold = 0.9
|
|
|
|
[bans]
|
|
multiple-versions = "allow"
|
|
|
|
[advisories]
|
|
yanked = "deny"
|
|
|
|
[sources]
|
|
unknown-registry = "deny"
|
|
unknown-git = "deny"
|
|
allow-registry = ["https://github.com/rust-lang/crates.io-index"]
|
|
# Every Git source Lumbridge is allowed to build from, named one by one, so that
|
|
# adding a fourth is a decision rather than an accident. `unknown-git = "deny"`
|
|
# above is what gives this list teeth.
|
|
#
|
|
# Until now this policy was never enforced: `scripts/ci.sh` ran only
|
|
# `cargo deny check licenses`, and running `check sources` failed immediately on
|
|
# buzz-sdk. A gate that has never been executed is not a gate.
|
|
#
|
|
# block/buzz is the upstream Buzz SDK, rev-pinned in crates/lumbridge-buzz.
|
|
# It has no crates.io release; BUZZ_INTEGRATION.md records why we use its signed
|
|
# protocol semantics rather than inventing a dialect.
|
|
allow-git = ["https://github.com/block/buzz"]
|