Covers advisories (RustSec), license compliance, duplicate detection,
and source allowlist (crates.io only).
License allowlist reflects the full transitive dep tree: MIT, Apache-2.0,
ISC, BSD-*, 0BSD, Unlicense, Zlib, BSL-1.0, MPL-2.0, Unicode-3.0,
LGPL-2.1-or-later (r-efi, Windows-only), CDLA-Permissive-2.0 (webpki-roots).
Three known advisories are ignored:
- RUSTSEC-2023-0071: rsa Marvin Attack, no upstream fix available
- RUSTSEC-2025-0134: rustls-pemfile unmaintained, blocked on rustls upgrade
- RUSTSEC-2026-0049: rustls-webpki CRL bug, fix blocked by rustls 0.21.x chain
Duplicate versions are warned rather than denied — all are transitive.