2.3 KiB
Dependency maintenance
Use the committed Cargo.lock. Do not run broad dependency updates as part of unrelated changes. Review runtime compatibility and licensing for each update.
Security audit
cargo install cargo-audit --locked --version 0.22.0
cargo audit --json
The audit fetches the RustSec advisory database and needs network access. Record the tool version and database revision with release evidence. Database download failure is not a clean scan. Review informational warnings as well as errors; unresolved affected vulnerabilities block release. Cargo auditing does not scan Debian packages or fully establish the security of native bundled code.
Reviewed maintenance warning
serde_cbor 0.11.2 has the informational unmaintained advisory
RUSTSEC-2021-0127.
It remains used for persisted repository metadata. Replacing it needs a separate
storage-compatibility review, not an untested codec substitution during release
cleanup. The warning remains visible in audit output; no advisory is ignored.
Operators should protect the state directory from untrusted modification.
License notices
python3 tools/dependency_notices.py --check
# After a reviewed Cargo.lock change:
python3 tools/dependency_notices.py
Requirements: Python 3, Cargo, curl, and HTTPS access to the Cargo registry and
GitHub's raw file service. The tool reads the entire locked dependency graph,
including build-time and other-platform dependencies, and preserves upstream
license and notice text. --check does not modify tracked files.
Some package archives omit their license file. tools/license_supplements.json
records exact upstream commit URLs and SHA-256 checksums, derived from the
package's .cargo_vcs_info.json. Version changes need a new source review;
missing texts or checksum mismatches fail rather than silently omit attribution.
Do not edit original copyright or license wording to match project formatting.
Coverage
With cargo-llvm-cov and the toolchain's llvm-tools-preview component installed:
cargo llvm-cov --locked --all-targets --json --output-path target/coverage.json
Record actual line coverage and tool versions. The release target is 90%. Do not exclude production modules or change the denominator to meet the target.