personal memory agent

feat(release): harden Rust policy baseline master

Require cargo-deny 0.20.2 through the release preflight helper and use it from the Rust dependency gates instead of the presence-only Makefile guard. Run dependency policy locked/offline, split RustSec refresh from the offline advisory check, and run a fresh audit before release artifact construction. Model the supported Rust target graph in deny.toml, deny unknown git sources, and add a workspace unsafe_code = "forbid" lint inherited by all five core crates. Document the target evidence matrix and make CI print only the evidence classes it actually establishes. No lockfile, toolchain, rust-version, or application behavior changes.


+310 -6
13 changed files