anvilsign in

collin/anvil

1[workspace]
2resolver = "2"
3members = [
4 "crates/*",
5 "vendor/gitserver-core",
6]
7
8[workspace.package]
9version = "0.0.0"
10edition = "2024"
11license = "MIT OR Apache-2.0"
12repository = "https://github.com/richardscollin/anvil"
13rust-version = "1.98.0"
14
15[workspace.dependencies]
16# Internal crates
17anvil-core = { path = "crates/anvil-core" }
18anvil-ci = { path = "crates/anvil-ci" }
19anvil-docker = { path = "crates/anvil-docker" }
20anvil-job = { path = "crates/anvil-job" }
21anvil-agent = { path = "crates/anvil-agent" }
22anvil-git = { path = "crates/anvil-git" }
23anvil-web = { path = "crates/anvil-web" }
24anvil-ssh = { path = "crates/anvil-ssh" }
25
26# Repo secrets (docs/secrets.md): sealed to users' ssh-ed25519 keys with
27# X25519 + HKDF-SHA256 + AES-256-GCM. AES-GCM rather than ChaCha20-Poly1305
28# because the *browser* is the encryptor and WebCrypto has no ChaCha.
29# Both track whatever russh is on, because cargo unifies each onto a single
30# version tree-wide: these used to be `=`-pinned to pre-releases for that
31# reason, and russh 0.63 moving to the final releases is what let the pins go.
32# Bumping either ahead of russh puts them back. X25519 comes from
33# `MontgomeryPoint::mul_clamped` rather than the x25519-dalek wrapper, which
34# would want its own curve25519-dalek.
35
36# HTTP client for the CD deploy webhook. No TLS feature on purpose: the deploy
37# receiver is host-local plaintext HTTP, and enabling rustls would drag in
38# aws-lc-rs and break the musl cross-compile (see the russh note below).
39# TLS via rustls with the *ring* provider only (`-no-provider` + an explicit
40# rustls/ring dep): aws-lc-rs needs cmake and breaks the zig musl
41# cross-compile, ring does not. anvil-git installs the provider at use time.
42# Used for the CD deploy webhook (anvil-ci) and HTTPS push mirroring
43# (anvil-git).
44# Native (system) roots rather than the bundled webpki set: `anvild secret`
45# talks to whatever anvil you self-host, including one behind a private or
46# local CA — portless's `.localhost` certificates being the everyday case. The
47# deploy image installs ca-certificates, so the server side is unaffected.
48# reqwest 0.13 folded the old `rustls-tls-native-roots-no-provider` into
49# `rustls-no-provider`, which verifies against the platform trust store —
50# same intent, one feature.
51
52# Used directly only for idempotent schema shims on existing databases; the
53# version tracks what toasty-driver-sqlite already pulls in.
54
55# `anvild secret` prompts for an ssh key passphrase / an account password.
56
57# RS256 verification of OIDC id tokens (docs/oidc.md). ring rather than a JWT
58# crate: it is already in the tree under rustls, cross-compiles to static musl
59# (aws-lc-rs, which the maintained JWT crates default to, needs cmake and does
60# not), and one signature check over `header.payload` is all we need.
61
62# `default-onig` (C Oniguruma regex engine) over the pure-Rust `default-fancy`:
63# several times faster on large files, and zig's cc cross-compiles the C just
64# fine for the static musl build (verified via deploy/build.sh's toolchain).
65
66# ssh — use the `ring` crypto backend instead of the default `aws-lc-rs`:
67# ring is far cheaper to compile (no cmake/perl) and cross-compiles cleanly
68# (zigbuild/musl), which matters for building images for the low-RAM VPS.
69
70# ssh-key parsing/fingerprinting, shared by anvil-core (storage) and anvil-ssh
71# (auth). Pinned to match russh's transitive ssh-key so fingerprints agree.
72
73aes-gcm = { version = "0.11.1" }
74anyhow = { version = "1" }
75argon2 = { version = "0.5", features = ["std"] }
76async-trait = { version = "0.1" }
77axum = { version = "0.8", features = ["ws"] }
78axum-extra = { version = "0.12.6", features = ["cookie"] }
79base64 = { version = "0.23.1" }
80bollard = { version = "0.21.1" }
81clap = { version = "4", features = ["derive"] }
82curve25519-dalek = { version = "5.0.0" }
83flate2 = { version = "1" }
84futures-util = { version = "0.3" }
85gitserver-core = { path = "vendor/gitserver-core" }
86gix = { version = "0.84", default-features = false, features = ["sha1", "max-performance-safe", "blob-diff", "revision"] }
87gix-pack = { version = "0.71", features = ["sha1"] }
88hmac = { version = "0.13.0" }
89lru = { version = "0.18.2" }
90maud = { version = "0.27", features = ["axum"] }
91pulldown-cmark = { version = "0.13", default-features = false, features = ["html"] }
92rand = { version = "0.10" }
93reqwest = { version = "0.13.4", default-features = false, features = ["form", "json", "rustls-no-provider"] }
94ring = { version = "0.17" }
95rpassword = { version = "7" }
96rusqlite = { version = "0.40.2" }
97russh = { version = "0.63.1", default-features = false, features = ["flate2", "ring", "rsa"] }
98rustls = { version = "0.23", default-features = false, features = ["ring", "logging", "std", "tls12"] }
99serde = { version = "1", features = ["derive"] }
100serde_json = { version = "1" }
101serde_yaml = { version = "0.9" }
102sha2 = { version = "0.11.0" }
103similar = { version = "3.2.0" }
104ssh-key = { version = "0.7.0-rc.11" }
105syntect = { version = "5", default-features = false, features = ["default-onig"] }
106tar = { version = "0.4" }
107thiserror = { version = "2" }
108time = { version = "0.3", features = ["serde", "formatting"] }
109toasty = { version = "0.10.0", features = ["sqlite"] }
110tokio = { version = "1", features = ["full"] }
111tokio-util = { version = "0.7", features = ["io"] }
112toml = { version = "1.1.4" }
113tower = { version = "0.5" }
114tower-http = { version = "0.7.0", features = ["trace", "fs"] }
115tracing = { version = "0.1" }
116tracing-subscriber = { version = "0.3", features = ["env-filter"] }