anvilsign in

collin/anvil

1# Duplicates `clippy::multiple_crate_versions` is allowed to ignore.
2#
3# The lint is on (see `[workspace.lints.clippy]` in Cargo.toml) so that a *new*
4# duplicate has to be argued for. Everything below is a duplicate we cannot
5# remove from here: some other crate in the tree pins the older copy, and the
6# only fix is that crate moving. Each entry says who is holding it, so this
7# list doubles as the "what are we waiting on" record — when a bump makes an
8# entry unnecessary, delete it rather than leaving it to rot.
9#
10# Nothing here is ours to collapse today, with one exception noted below.
11
12allowed-duplicate-crates = [
13 # --- The RustCrypto `digest` 0.10 -> 0.11 seam ------------------------
14 # Half the tree has moved to digest 0.11 (aes-gcm, ssh-key, russh, our own
15 # sha2/hmac) and half has not (gix's sha1, `rsa` 0.9 in anvil-web's tests,
16 # argon2 0.5). Every crate below is simply the same crate on both sides of
17 # that line, and they collapse when the stragglers move — mostly gix.
18 "block-buffer",
19 "const-oid",
20 "cpufeatures",
21 "crypto-common",
22 "digest",
23 "generic-array",
24 "sha1",
25 "sha3",
26
27 # `argon2` is the one duplicate we could remove ourselves: we pin 0.5 and
28 # ssh-key pulls 0.6.0-rc.8. Deliberately not taken — 0.6 is a pre-release
29 # and argon2 is what verifies account passwords. Moving it would also
30 # collapse `blake2` and `password-hash`, which are here only because
31 # argon2 0.5 holds the old copy.
32 "argon2",
33 "blake2",
34 "password-hash",
35
36 # --- Held by direct dependencies of ours ------------------------------
37 "base64", # axum 0.8 is on 0.22; we are on 0.23.
38 "tower-http", # reqwest 0.13 uses 0.6 internally; we are on 0.7.
39 "hashlink", # rusqlite 0.40 moved to 0.12; something older wants 0.11.
40
41 # --- Entirely inside other crates' trees ------------------------------
42 "bitflags", # 1.x lingers under a few transitive crates.
43 "foldhash", # gix-pack's clru vs jaq-json.
44 "getrandom", # 0.2/0.3/0.4 across rand, ring and gix.
45 "hashbrown", # three copies, all within gix's own sub-crates.
46 "r-efi", # a getrandom UEFI backend, one per getrandom major.
47 "rand_core", # tracks the getrandom split above.
48 "syn", # proc-macro crates mid-migration from 2.x to 3.x.
49]