panda-rpki-oss/docs/dependencies.md
yuyr 591bed90a8
Some checks failed
ci / rust (push) Has been cancelled
ci / docker (push) Has been cancelled
ci / audit (push) Has been cancelled
Harden first-release validation and dependency hygiene
2026-09-10 09:53:45 +08:00

2.3 KiB

Dependency maintenance

Use the committed Cargo.lock. Do not run broad dependency updates as part of unrelated changes. Review runtime compatibility and licensing for each update.

Security audit

cargo install cargo-audit --locked --version 0.22.0
cargo audit --json

The audit fetches the RustSec advisory database and needs network access. Record the tool version and database revision with release evidence. Database download failure is not a clean scan. Review informational warnings as well as errors; unresolved affected vulnerabilities block release. Cargo auditing does not scan Debian packages or fully establish the security of native bundled code.

Reviewed maintenance warning

serde_cbor 0.11.2 has the informational unmaintained advisory RUSTSEC-2021-0127. It remains used for persisted repository metadata. Replacing it needs a separate storage-compatibility review, not an untested codec substitution during release cleanup. The warning remains visible in audit output; no advisory is ignored. Operators should protect the state directory from untrusted modification.

License notices

python3 tools/dependency_notices.py --check
# After a reviewed Cargo.lock change:
python3 tools/dependency_notices.py

Requirements: Python 3, Cargo, curl, and HTTPS access to the Cargo registry and GitHub's raw file service. The tool reads the entire locked dependency graph, including build-time and other-platform dependencies, and preserves upstream license and notice text. --check does not modify tracked files.

Some package archives omit their license file. tools/license_supplements.json records exact upstream commit URLs and SHA-256 checksums, derived from the package's .cargo_vcs_info.json. Version changes need a new source review; missing texts or checksum mismatches fail rather than silently omit attribution. Do not edit original copyright or license wording to match project formatting.

Coverage

With cargo-llvm-cov and the toolchain's llvm-tools-preview component installed:

cargo llvm-cov --locked --all-targets --json --output-path target/coverage.json

Record actual line coverage and tool versions. The release target is 90%. Do not exclude production modules or change the denominator to meet the target.