anvilsign in

collin/anvil · 16222f48

organize Cargo.toml

Collin Richards · 2026-08-25 04:39 UTC · 16222f4845fdaa56261bb793d0a3444b7a7808bc · parent ef6faf54 · browse files

modifiedCargo.toml+41 −35
⋯ 32 unchanged lines
3333 # rather than the x25519-dalek wrapper, which would want its own
3434 # curve25519-dalek.
3535
36-anyhow = { version = "1" }
37-argon2 = { version = "0.5", features = ["std"] }
38-aes-gcm = { version = "=0.11.0-rc.4" }
39-curve25519-dalek = { version = "=5.0.0-rc.0" }
40-async-trait = { version = "0.1" }
41-axum = { version = "0.8", features = ["ws"] }
42-axum-extra = { version = "0.10", features = ["cookie"] }
43-base64 = { version = "0.22" }
44-bollard = { version = "0.18" }
45-clap = { version = "4", features = ["derive"] }
46-futures-util = { version = "0.3" }
47-hmac = { version = "0.12" }
48-lru = { version = "0.12" }
49-gitserver-core = { path = "vendor/gitserver-core" }
50-gix = { version = "0.84", default-features = false, features = ["sha1", "max-performance-safe", "blob-diff", "revision"] }
51-gix-pack = { version = "0.71", features = ["sha1"] }
52-maud = { version = "0.27", features = ["axum"] }
53-pulldown-cmark = { version = "0.13", default-features = false, features = ["html"] }
54-flate2 = { version = "1" }
55-rand = { version = "0.10" }
5636 # HTTP client for the CD deploy webhook. No TLS feature on purpose: the deploy
5737 # receiver is host-local plaintext HTTP, and enabling rustls would drag in
5838 # aws-lc-rs and break the musl cross-compile (see the russh note below).
⋯ 6 unchanged lines
6545 # talks to whatever anvil you self-host, including one behind a private or
6646 # local CA — portless's `.localhost` certificates being the everyday case. The
6747 # deploy image installs ca-certificates, so the server side is unaffected.
68-reqwest = { version = "0.12", default-features = false, features = ["json", "rustls-tls-native-roots-no-provider"] }
69-rustls = { version = "0.23", default-features = false, features = ["ring", "logging", "std", "tls12"] }
48+
7049 # Used directly only for idempotent schema shims on existing databases; the
7150 # version tracks what toasty-driver-sqlite already pulls in.
72-rusqlite = { version = "0.39" }
51+
7352 # `anvild secret` prompts for an ssh key passphrase / an account password.
74-rpassword = { version = "7" }
53+
7554 # RS256 verification of OIDC id tokens (docs/oidc.md). ring rather than a JWT
7655 # crate: it is already in the tree under rustls, cross-compiles to static musl
7756 # (aws-lc-rs, which the maintained JWT crates default to, needs cmake and does
7857 # not), and one signature check over `header.payload` is all we need.
58+
59+# `default-onig` (C Oniguruma regex engine) over the pure-Rust `default-fancy`:
60+# several times faster on large files, and zig's cc cross-compiles the C just
61+# fine for the static musl build (verified via deploy/build.sh's toolchain).
62+
63+# ssh — use the `ring` crypto backend instead of the default `aws-lc-rs`:
64+# ring is far cheaper to compile (no cmake/perl) and cross-compiles cleanly
65+# (zigbuild/musl), which matters for building images for the low-RAM VPS.
66+
67+# ssh-key parsing/fingerprinting, shared by anvil-core (storage) and anvil-ssh
68+# (auth). Pinned to match russh's transitive ssh-key so fingerprints agree.
69+
70+aes-gcm = { version = "=0.11.0-rc.4" }
71+anyhow = { version = "1" }
72+argon2 = { version = "0.5", features = ["std"] }
73+async-trait = { version = "0.1" }
74+axum = { version = "0.8", features = ["ws"] }
75+axum-extra = { version = "0.10", features = ["cookie"] }
76+base64 = { version = "0.22" }
77+bollard = { version = "0.18" }
78+clap = { version = "4", features = ["derive"] }
79+curve25519-dalek = { version = "=5.0.0-rc.0" }
80+flate2 = { version = "1" }
81+futures-util = { version = "0.3" }
82+gitserver-core = { path = "vendor/gitserver-core" }
83+gix = { version = "0.84", default-features = false, features = ["sha1", "max-performance-safe", "blob-diff", "revision"] }
84+gix-pack = { version = "0.71", features = ["sha1"] }
85+hmac = { version = "0.12" }
86+lru = { version = "0.12" }
87+maud = { version = "0.27", features = ["axum"] }
88+pulldown-cmark = { version = "0.13", default-features = false, features = ["html"] }
89+rand = { version = "0.10" }
90+reqwest = { version = "0.12", default-features = false, features = ["json", "rustls-tls-native-roots-no-provider"] }
7991 ring = { version = "0.17" }
92+rpassword = { version = "7" }
93+rusqlite = { version = "0.39" }
94+russh = { version = "0.61", default-features = false, features = ["flate2", "ring", "rsa"] }
95+rustls = { version = "0.23", default-features = false, features = ["ring", "logging", "std", "tls12"] }
8096 serde = { version = "1", features = ["derive"] }
8197 serde_json = { version = "1" }
8298 serde_yaml = { version = "0.9" }
8399 sha2 = { version = "0.10" }
84100 similar = { version = "2" }
85-# `default-onig` (C Oniguruma regex engine) over the pure-Rust `default-fancy`:
86-# several times faster on large files, and zig's cc cross-compiles the C just
87-# fine for the static musl build (verified via deploy/build.sh's toolchain).
101+ssh-key = { version = "0.7.0-rc.10" }
88102 syntect = { version = "5", default-features = false, features = ["default-onig"] }
89103 tar = { version = "0.4" }
90104 thiserror = { version = "2" }
⋯ 6 unchanged lines
97111 tower-http = { version = "0.6", features = ["trace", "fs"] }
98112 tracing = { version = "0.1" }
99113 tracing-subscriber = { version = "0.3", features = ["env-filter"] }
100-
101-# ssh — use the `ring` crypto backend instead of the default `aws-lc-rs`:
102-# ring is far cheaper to compile (no cmake/perl) and cross-compiles cleanly
103-# (zigbuild/musl), which matters for building images for the low-RAM VPS.
104-russh = { version = "0.61", default-features = false, features = ["flate2", "ring", "rsa"] }
105-# ssh-key parsing/fingerprinting, shared by anvil-core (storage) and anvil-ssh
106-# (auth). Pinned to match russh's transitive ssh-key so fingerprints agree.
107-ssh-key = { version = "0.7.0-rc.10" }