| <!-- markdownlint-disable no-inline-html first-line-heading no-emphasis-as-heading --> |
| |
| <div align="center"> |
| |
| # `β cargo-deny` |
| |
| **Cargo plugin for linting your dependencies** |
| |
| [](https://embark.dev) |
| [](https://discord.gg/Fg4u4VX) |
| [](https://crates.io/crates/cargo-deny) |
| [](https://docs.rs/cargo-deny) |
| [](https://embarkstudios.github.io/cargo-deny/) |
| [](https://blog.rust-lang.org/2023/06/01/Rust-1.70.0.html) |
| [](https://spdx.org/licenses/) |
| [](https://deps.rs/repo/github/EmbarkStudios/cargo-deny) |
| [](https://github.com/EmbarkStudios/cargo-deny/actions?workflow=CI) |
| |
| </div> |
| |
| See the [book π](https://embarkstudios.github.io/cargo-deny/) for in-depth documentation. |
| |
| To run on CI as a GitHub Action, see [`cargo-deny-action`](https://github.com/EmbarkStudios/cargo-deny-action). |
| |
| _Please Note: This is a tool that we use (and like!) and it makes sense to us to release it as open source. However, we canβt take any responsibility for your use of the tool, if it will function correctly or fulfil your needs. No functionality in - or information provided by - cargo-deny constitutes legal advice._ |
| |
| ## [Quickstart](https://embarkstudios.github.io/cargo-deny/) |
| |
| ```bash |
| cargo install --locked cargo-deny && cargo deny init && cargo deny check |
| ``` |
| |
| ## Usage |
| |
| ### [Install](https://embarkstudios.github.io/cargo-deny/cli/index.html) cargo-deny |
| |
| If you want to use `cargo-deny` without having `cargo` installed, build `cargo-deny` with the `standalone` feature. This can be useful in Docker Images. |
| |
| ```bash |
| cargo install --locked cargo-deny |
| |
| # Or, if you're an Arch user |
| pacman -S cargo-deny |
| ``` |
| |
| ### [Initialize](https://embarkstudios.github.io/cargo-deny/cli/init.html) your project |
| |
| ```bash |
| cargo deny init |
| ``` |
| |
| ### [Check](https://embarkstudios.github.io/cargo-deny/cli/check.html) your crates |
| |
| ```bash |
| cargo deny check |
| ``` |
| |
| #### [Licenses](https://embarkstudios.github.io/cargo-deny/checks/licenses/index.html) |
| |
| The licenses check is used to verify that every crate you use has license terms you find acceptable. |
| |
| ```bash |
| cargo deny check licenses |
| ``` |
| |
|  |
| |
| #### [Bans](https://embarkstudios.github.io/cargo-deny/checks/bans/index.html) |
| |
| The bans check is used to deny (or allow) specific crates, as well as detect and handle multiple versions of the same crate. |
| |
| ```bash |
| cargo deny check bans |
| ``` |
| |
|  |
| |
| #### [Advisories](https://embarkstudios.github.io/cargo-deny/checks/advisories/index.html) |
| |
| The advisories check is used to detect issues for crates by looking in an advisory database. |
| |
| ```bash |
| cargo deny check advisories |
| ``` |
| |
|  |
| |
| #### [Sources](https://embarkstudios.github.io/cargo-deny/checks/sources/index.html) |
| |
| The sources check ensures crates only come from sources you trust. |
| |
| ```bash |
| cargo deny check sources |
| ``` |
| |
|  |
| |
| ### Pre-commit hook |
| |
| You can use `cargo-deny` with [pre-commit](https://pre-commit.com). Add it to your local `.pre-commit-config.yaml` as follows: |
| |
| ```yaml |
| - repo: https://github.com/EmbarkStudios/cargo-deny |
| rev: 0.14.16 # choose your preferred tag |
| hooks: |
| - id: cargo-deny |
| args: ["--all-features", "check"] # optionally modify the arguments for cargo-deny (default arguments shown here) |
| ``` |
| |
| ## Contributing |
| |
| [](CODE_OF_CONDUCT.md) |
| |
| We welcome community contributions to this project. |
| |
| Please read our [Contributor Guide](CONTRIBUTING.md) for more information on how to get started. |
| |
| ## License |
| |
| Licensed under either of |
| |
| - Apache License, Version 2.0, ([LICENSE-APACHE](LICENSE-APACHE) or <http://www.apache.org/licenses/LICENSE-2.0>) |
| - MIT license ([LICENSE-MIT](LICENSE-MIT) or <http://opensource.org/licenses/MIT>) |
| |
| at your option. |
| |
| ### Contribution |
| |
| Unless you explicitly state otherwise, any contribution intentionally submitted for inclusion in the work by you, as defined in the Apache-2.0 license, shall be dual licensed as above, without any additional terms or conditions. |