Files
asepharyana 1cdb82a76f Sync config from arch
- hypr/apps.lua
- hypr/autostart.lua
- hypr/envs.lua
- hypr/hyprland.lua
- hypr/hyprsunset.conf
- hypr/input.lua
- hypr/looknfeel.lua
- hypr/omasettings.lua
- hypr/xdph.conf
- omarchy/branding/about.txt
- omarchy/branding/screensaver.txt
- omarchy/extensions/omarchy-menu.jsonc
- omarchy/hooks/battery-low.d/play-warning-sound.sample
- omarchy/hooks/font-set.d/show-font-notification.sample
- omarchy/hooks/post-boot.d/weather.sample
- omarchy/hooks/post-update.d/install-voxtype.hook
- omarchy/hooks/post-update.d/setup-agent.hook
- omarchy/hooks/post-update.d/setup-fingerprint.hook
- omarchy/hooks/post-update.d/show-update-notification.sample
- omarchy/hooks/pre-refresh-pacman.d/add-custom-repo.sample
- omarchy/hooks/theme-set.d/show-theme-notification.sample
- omarchy/shell.json
- omarchy/shell.toml
- omarchy/theme.name
- omarchy/themes/azure-glow/README.md
- omarchy/themes/azure-glow/alacritty.toml
- omarchy/themes/azure-glow/btop.theme
- omarchy/themes/azure-glow/hyprland.conf
- omarchy/themes/azure-glow/hyprlock.conf
- omarchy/themes/azure-glow/icons.theme
- … 269 more
2026-09-23 15:19:12 +07:00

66 lines
2.6 KiB
TOML

# Dependency policy for the SSH agent helper.
#
# This binary holds decrypted private keys. Its dependency tree was reviewed
# once, deliberately and in writing, in docs/decisions/0001-ssh-agent-dependencies.md;
# this file is what stops that review going stale between releases. Anything
# it rejects is a prompt to think, not a rule to route around.
[graph]
targets = ["x86_64-unknown-linux-gnu"]
# Only what the release actually compiles. Auditing features this build never
# enables produces findings nobody can act on.
all-features = false
[advisories]
# Every RustSec advisory is a build failure, with one documented exception.
yanked = "deny"
ignore = [
# RUSTSEC-2023-0071: Marvin, a timing sidechannel in `rsa`'s private-key
# operations. Unpatched upstream -- there is no fixed release to move to.
#
# Accepted for the reasons recorded in the Task 4 ADR: the attack needs
# accurate timing of many private-key operations from the attacker's own
# observations, and this helper signs only after an explicit human approval
# or inside a short grant, over a same-UID socket. An attacker positioned to
# farm timings from it is already a same-UID process on an unlocked desktop,
# which the threat model does not defend against by design.
#
# Revisit when `rsa` publishes a fix, or if Ed25519-only becomes acceptable.
{ id = "RUSTSEC-2023-0071", reason = "no upstream fix; see docs/decisions/0001-ssh-agent-dependencies.md" },
]
[licenses]
# Permissive only. A copyleft dependency in a binary this repository ships
# would change the plugin's own distribution terms, which is a decision for a
# human rather than a dependency bump.
allow = [
"MIT",
"Apache-2.0",
"Apache-2.0 WITH LLVM-exception",
"BSD-2-Clause",
"BSD-3-Clause",
"ISC",
"Unicode-3.0",
"Zlib",
]
confidence-threshold = 0.9
[bans]
# Duplicate major versions of one crate mean two copies compiled in. For a
# crypto dependency that also means two implementations, one of which nobody
# audited. Warn rather than deny: transitive duplicates are common and often
# outside our control, but they should be visible in the log.
multiple-versions = "warn"
wildcards = "deny"
# Nothing here should reach for the network or spawn processes; both would
# contradict the design's claim that the helper has exactly three inputs.
deny = []
[sources]
# Only crates.io. A git dependency is a moving target that no lockfile review
# can meaningfully cover, and this binary is committed as bytes.
unknown-registry = "deny"
unknown-git = "deny"
allow-registry = ["https://github.com/rust-lang/crates.io-index"]
allow-git = []