From 3f84b31b87663237d4c9e48fc9bb68ea37399b46 Mon Sep 17 00:00:00 2001 From: Albert Hui Date: Sun, 2 Aug 2026 03:16:01 +0800 Subject: [PATCH] fix(supply-chain): trust our own crates instead of exempting them ADR-0018 ranks the four cargo-vet mechanisms and states that reaching for a weaker one is a defect. These crates are ours, consumed from crates.io, so case 2 applies: a publisher-trust entry under h4x0r (user-id 347968), not an exemption. The distinction is semantic, not cosmetic. An exemption asserts "unreviewed, accepted anyway"; a trust entry asserts "the publisher is ours". Recording our own crates as unreviewed-but-tolerated misstated the supply-chain posture in the direction of false comfort. A trust entry is also version-agnostic, so it does not go stale on the next bump the way a pinned exemption does. Exemption -> trust: - forensicnomicon - forensicnomicon-core - forensicnomicon-data Verified (config change, so the vet run is the test): Vetting Succeeded (3 fully audited) Co-Authored-By: Claude Opus 5 (1M context) --- supply-chain/audits.toml | 18 ++++++++++++++++++ supply-chain/config.toml | 12 ------------ supply-chain/imports.lock | 21 +++++++++++++++++++++ 3 files changed, 39 insertions(+), 12 deletions(-) diff --git a/supply-chain/audits.toml b/supply-chain/audits.toml index 2772ccb..1eabe91 100644 --- a/supply-chain/audits.toml +++ b/supply-chain/audits.toml @@ -2,3 +2,21 @@ # cargo-vet audits file [audits] + +[[trusted.forensicnomicon]] +criteria = "safe-to-deploy" +user-id = 347968 # Albert Hui (h4x0r) +start = "2026-06-05" +end = "2027-08-01" + +[[trusted.forensicnomicon-core]] +criteria = "safe-to-deploy" +user-id = 347968 # Albert Hui (h4x0r) +start = "2026-06-28" +end = "2027-08-01" + +[[trusted.forensicnomicon-data]] +criteria = "safe-to-deploy" +user-id = 347968 # Albert Hui (h4x0r) +start = "2026-06-28" +end = "2027-08-01" diff --git a/supply-chain/config.toml b/supply-chain/config.toml index b781f95..be8869c 100644 --- a/supply-chain/config.toml +++ b/supply-chain/config.toml @@ -18,15 +18,3 @@ url = "https://raw.githubusercontent.com/mozilla/supply-chain/main/audits.toml" [policy.shellitem] audit-as-crates-io = false - -[[exemptions.forensicnomicon]] -version = "1.0.0" -criteria = "safe-to-deploy" - -[[exemptions.forensicnomicon-core]] -version = "1.0.0" -criteria = "safe-to-deploy" - -[[exemptions.forensicnomicon-data]] -version = "1.0.0" -criteria = "safe-to-deploy" diff --git a/supply-chain/imports.lock b/supply-chain/imports.lock index 27250bd..e60b7f0 100644 --- a/supply-chain/imports.lock +++ b/supply-chain/imports.lock @@ -1,6 +1,27 @@ # cargo-vet imports lock +[[publisher.forensicnomicon]] +version = "1.0.0" +when = "2026-06-28" +user-id = 347968 +user-login = "h4x0r" +user-name = "Albert Hui" + +[[publisher.forensicnomicon-core]] +version = "1.0.0" +when = "2026-06-28" +user-id = 347968 +user-login = "h4x0r" +user-name = "Albert Hui" + +[[publisher.forensicnomicon-data]] +version = "1.0.0" +when = "2026-06-28" +user-id = 347968 +user-login = "h4x0r" +user-name = "Albert Hui" + [audits.bytecode-alliance.audits] [audits.embark.audits]