Hardware, platform and safety / Offline-first architecture
What goes wrong with “Offline guard test” in a shop, thinking about new dependencies need an allowlist entry?
Built in the repository (checked files or developer tooling, not an app feature) C0231
A test in the packaging crate fails the build if network crates, sockets, URLs, process spawning or URL/token environment variables appear, or if a denied crate enters the lockfile. It passed when we ran the suite. It guards the packaging tool only, not the future app. Plan for: new dependencies need an allowlist entry; applies to the tool, not the app; passing today says nothing about later commits. It exists only as a file in the repository, not as a product feature.
How to read this
The tag above says how real the answer is. Answers describe the plan in the repository and design documents. No app is released. Where an answer touches tax or law, treat it as a theme to verify with a qualified local adviser.