anvilsign in

collin/anvil

1[workspace]
2resolver = "2"
3members = [
4 "crates/*",
5 "vendor/gitserver-core",
6]
7
8[workspace.package]
9version = "0.0.0"
10edition = "2024"
11license = "MIT OR Apache-2.0"
12repository = "https://github.com/richardscollin/anvil"
13rust-version = "1.95"
14
15[workspace.dependencies]
16# Internal crates
17anvil-core = { path = "crates/anvil-core" }
18anvil-ci = { path = "crates/anvil-ci" }
19anvil-git = { path = "crates/anvil-git" }
20anvil-web = { path = "crates/anvil-web" }
21anvil-ssh = { path = "crates/anvil-ssh" }
22
23anyhow = "1"
24argon2 = { version = "0.5", features = ["std"] }
25# Repo secrets (docs/secrets.md): sealed to users' ssh-ed25519 keys with
26# X25519 + HKDF-SHA256 + AES-256-GCM. AES-GCM rather than ChaCha20-Poly1305
27# because the *browser* is the encryptor and WebCrypto has no ChaCha.
28# Both are pinned to the exact pre-releases already in the lockfile: cargo
29# unifies each onto a single version tree-wide, and asking for the final
30# release instead walks russh (and half of RustCrypto) *backwards* to a set
31# that does not compile. X25519 comes from `MontgomeryPoint::mul_clamped`
32# rather than the x25519-dalek wrapper, which would want its own
33# curve25519-dalek.
34aes-gcm = "=0.11.0-rc.4"
35curve25519-dalek = "=5.0.0-rc.0"
36async-trait = "0.1"
37axum = "0.8"
38axum-extra = { version = "0.10", features = ["cookie"] }
39base64 = "0.22"
40bollard = "0.18"
41clap = { version = "4", features = ["derive"] }
42futures-util = "0.3"
43hmac = "0.12"
44lru = "0.12"
45gitserver-core = { path = "vendor/gitserver-core" }
46gix = { version = "0.84", default-features = false, features = ["sha1", "max-performance-safe", "blob-diff", "revision"] }
47gix-pack = { version = "0.71", features = ["sha1"] }
48maud = { version = "0.27", features = ["axum"] }
49pulldown-cmark = { version = "0.13", default-features = false, features = ["html"] }
50flate2 = "1"
51rand = "0.10"
52# HTTP client for the CD deploy webhook. No TLS feature on purpose: the deploy
53# receiver is host-local plaintext HTTP, and enabling rustls would drag in
54# aws-lc-rs and break the musl cross-compile (see the russh note below).
55# TLS via rustls with the *ring* provider only (`-no-provider` + an explicit
56# rustls/ring dep): aws-lc-rs needs cmake and breaks the zig musl
57# cross-compile, ring does not. anvil-git installs the provider at use time.
58# Used for the CD deploy webhook (anvil-ci) and HTTPS push mirroring
59# (anvil-git).
60# Native (system) roots rather than the bundled webpki set: `anvild secret`
61# talks to whatever anvil you self-host, including one behind a private or
62# local CA — portless's `.localhost` certificates being the everyday case. The
63# deploy image installs ca-certificates, so the server side is unaffected.
64reqwest = { version = "0.12", default-features = false, features = ["json", "rustls-tls-native-roots-no-provider"] }
65rustls = { version = "0.23", default-features = false, features = ["ring", "logging", "std", "tls12"] }
66# Used directly only for idempotent schema shims on existing databases; the
67# version tracks what toasty-driver-sqlite already pulls in.
68rusqlite = "0.39"
69# `anvild secret` prompts for an ssh key passphrase / an account password.
70rpassword = "7"
71# RS256 verification of OIDC id tokens (docs/oidc.md). ring rather than a JWT
72# crate: it is already in the tree under rustls, cross-compiles to static musl
73# (aws-lc-rs, which the maintained JWT crates default to, needs cmake and does
74# not), and one signature check over `header.payload` is all we need.
75ring = "0.17"
76serde = { version = "1", features = ["derive"] }
77serde_json = "1"
78serde_yaml = "0.9"
79sha2 = "0.10"
80similar = "2"
81# `default-onig` (C Oniguruma regex engine) over the pure-Rust `default-fancy`:
82# several times faster on large files, and zig's cc cross-compiles the C just
83# fine for the static musl build (verified via deploy/build.sh's toolchain).
84syntect = { version = "5", default-features = false, features = ["default-onig"] }
85tar = "0.4"
86thiserror = "2"
87time = { version = "0.3", features = ["serde", "formatting"] }
88toasty = { version = "0.7", features = ["sqlite"] }
89tokio = { version = "1", features = ["full"] }
90tokio-util = { version = "0.7", features = ["io"] }
91toml = "0.8"
92tower = "0.5"
93tower-http = { version = "0.6", features = ["trace", "fs"] }
94tracing = "0.1"
95tracing-subscriber = { version = "0.3", features = ["env-filter"] }
96
97# ssh — use the `ring` crypto backend instead of the default `aws-lc-rs`:
98# ring is far cheaper to compile (no cmake/perl) and cross-compiles cleanly
99# (zigbuild/musl), which matters for building images for the low-RAM VPS.
100russh = { version = "0.61", default-features = false, features = ["flate2", "ring", "rsa"] }
101# ssh-key parsing/fingerprinting, shared by anvil-core (storage) and anvil-ssh
102# (auth). Pinned to match russh's transitive ssh-key so fingerprints agree.
103ssh-key = "0.7.0-rc.10"