anvilsign in

collin/anvil

1# Duplicates `clippy::multiple_crate_versions` is allowed to ignore.
2#
3# The lint is on (see `[workspace.lints.clippy]` in Cargo.toml) so a *new*
4# duplicate has to be argued for. Everything below is one we cannot remove from
5# here: another crate in the tree pins the older copy and the only fix is that
6# crate moving. Each entry names who is holding it, so the list doubles as a
7# record of what we are waiting on — when a bump makes an entry unnecessary,
8# delete it rather than leaving it to rot.
9#
10# Five have left that way rather than by being tolerated:
11# argon2, blake2, password-hash taking argon2 0.6, which ssh-key was on
12# base64 holding at 0.22 to match axum, since 0.23
13# added nothing we use
14# tower-http it was declared and never used, so the
15# whole dependency went
16#
17# `rand` is the one that looks collapsible and is not. axum's websockets pull
18# 0.9 and we are on 0.10, which is the base64 situation exactly — except
19# ssh-key rc.11 only accepts an RNG implementing rand_core 0.10's traits, so
20# moving to 0.9 trades the duplicate for a compile error in anvil-ssh. It waits
21# for axum.
22#
23# Note this list is checked against the dev- and build-dependency graph too,
24# not just `cargo tree -e normal`: several entries here are duplicated only
25# once test targets are counted.
26
27allowed-duplicate-crates = [
28 # The RustCrypto `digest` 0.10 -> 0.11 seam. Half the tree has crossed it
29 # (aes-gcm, argon2, ssh-key, russh, our sha2/hmac) and half has not — gix's
30 # sha1, and `rsa` 0.9 in anvil-web's tests. Each crate here is the same
31 # crate on both sides of that line; they collapse together when gix moves.
32 "block-buffer",
33 "const-oid",
34 "cpufeatures",
35 "crypto-common",
36 "digest",
37 "generic-array",
38 "sha1",
39 "sha3",
40
41 # Held apart by our own direct dependencies, with no version suiting both.
42 # See the note on `rand` above.
43 "rand",
44 "rand_core",
45
46 # Entirely inside other crates' trees; nothing we declare picks these.
47 "bitflags", # 1.x lingers under a few transitive crates.
48 "foldhash", # gix-pack's clru vs jaq-json.
49 "getrandom", # 0.2/0.3/0.4 across rand, ring and gix.
50 "hashbrown", # two copies, both within gix's own sub-crates.
51 "hashlink", # rusqlite 0.40 is on 0.12; something older wants 0.11.
52 "r-efi", # a getrandom UEFI backend, one per getrandom major.
53 "syn", # proc-macro crates mid-migration from 2.x to 3.x.
54]