collin/anvil · 16222f48
organize Cargo.toml
Collin Richards · 2026-08-25 04:39 UTC · 16222f4845fdaa56261bb793d0a3444b7a7808bc · parent ef6faf54 · browse files
modifiedCargo.toml+41 −35
| ⋯ 32 unchanged lines | |||
| 33 | 33 | # rather than the x25519-dalek wrapper, which would want its own | |
| 34 | 34 | # curve25519-dalek. | |
| 35 | 35 | ||
| 36 | - | anyhow = { version = "1" } | |
| 37 | - | argon2 = { version = "0.5", features = ["std"] } | |
| 38 | - | aes-gcm = { version = "=0.11.0-rc.4" } | |
| 39 | - | curve25519-dalek = { version = "=5.0.0-rc.0" } | |
| 40 | - | async-trait = { version = "0.1" } | |
| 41 | - | axum = { version = "0.8", features = ["ws"] } | |
| 42 | - | axum-extra = { version = "0.10", features = ["cookie"] } | |
| 43 | - | base64 = { version = "0.22" } | |
| 44 | - | bollard = { version = "0.18" } | |
| 45 | - | clap = { version = "4", features = ["derive"] } | |
| 46 | - | futures-util = { version = "0.3" } | |
| 47 | - | hmac = { version = "0.12" } | |
| 48 | - | lru = { version = "0.12" } | |
| 49 | - | gitserver-core = { path = "vendor/gitserver-core" } | |
| 50 | - | gix = { version = "0.84", default-features = false, features = ["sha1", "max-performance-safe", "blob-diff", "revision"] } | |
| 51 | - | gix-pack = { version = "0.71", features = ["sha1"] } | |
| 52 | - | maud = { version = "0.27", features = ["axum"] } | |
| 53 | - | pulldown-cmark = { version = "0.13", default-features = false, features = ["html"] } | |
| 54 | - | flate2 = { version = "1" } | |
| 55 | - | rand = { version = "0.10" } | |
| 56 | 36 | # HTTP client for the CD deploy webhook. No TLS feature on purpose: the deploy | |
| 57 | 37 | # receiver is host-local plaintext HTTP, and enabling rustls would drag in | |
| 58 | 38 | # aws-lc-rs and break the musl cross-compile (see the russh note below). | |
| ⋯ 6 unchanged lines | |||
| 65 | 45 | # talks to whatever anvil you self-host, including one behind a private or | |
| 66 | 46 | # local CA — portless's `.localhost` certificates being the everyday case. The | |
| 67 | 47 | # deploy image installs ca-certificates, so the server side is unaffected. | |
| 68 | - | reqwest = { version = "0.12", default-features = false, features = ["json", "rustls-tls-native-roots-no-provider"] } | |
| 69 | - | rustls = { version = "0.23", default-features = false, features = ["ring", "logging", "std", "tls12"] } | |
| 48 | + | ||
| 70 | 49 | # Used directly only for idempotent schema shims on existing databases; the | |
| 71 | 50 | # version tracks what toasty-driver-sqlite already pulls in. | |
| 72 | - | rusqlite = { version = "0.39" } | |
| 51 | + | ||
| 73 | 52 | # `anvild secret` prompts for an ssh key passphrase / an account password. | |
| 74 | - | rpassword = { version = "7" } | |
| 53 | + | ||
| 75 | 54 | # RS256 verification of OIDC id tokens (docs/oidc.md). ring rather than a JWT | |
| 76 | 55 | # crate: it is already in the tree under rustls, cross-compiles to static musl | |
| 77 | 56 | # (aws-lc-rs, which the maintained JWT crates default to, needs cmake and does | |
| 78 | 57 | # not), and one signature check over `header.payload` is all we need. | |
| 58 | + | ||
| 59 | + | # `default-onig` (C Oniguruma regex engine) over the pure-Rust `default-fancy`: | |
| 60 | + | # several times faster on large files, and zig's cc cross-compiles the C just | |
| 61 | + | # fine for the static musl build (verified via deploy/build.sh's toolchain). | |
| 62 | + | ||
| 63 | + | # ssh — use the `ring` crypto backend instead of the default `aws-lc-rs`: | |
| 64 | + | # ring is far cheaper to compile (no cmake/perl) and cross-compiles cleanly | |
| 65 | + | # (zigbuild/musl), which matters for building images for the low-RAM VPS. | |
| 66 | + | ||
| 67 | + | # ssh-key parsing/fingerprinting, shared by anvil-core (storage) and anvil-ssh | |
| 68 | + | # (auth). Pinned to match russh's transitive ssh-key so fingerprints agree. | |
| 69 | + | ||
| 70 | + | aes-gcm = { version = "=0.11.0-rc.4" } | |
| 71 | + | anyhow = { version = "1" } | |
| 72 | + | argon2 = { version = "0.5", features = ["std"] } | |
| 73 | + | async-trait = { version = "0.1" } | |
| 74 | + | axum = { version = "0.8", features = ["ws"] } | |
| 75 | + | axum-extra = { version = "0.10", features = ["cookie"] } | |
| 76 | + | base64 = { version = "0.22" } | |
| 77 | + | bollard = { version = "0.18" } | |
| 78 | + | clap = { version = "4", features = ["derive"] } | |
| 79 | + | curve25519-dalek = { version = "=5.0.0-rc.0" } | |
| 80 | + | flate2 = { version = "1" } | |
| 81 | + | futures-util = { version = "0.3" } | |
| 82 | + | gitserver-core = { path = "vendor/gitserver-core" } | |
| 83 | + | gix = { version = "0.84", default-features = false, features = ["sha1", "max-performance-safe", "blob-diff", "revision"] } | |
| 84 | + | gix-pack = { version = "0.71", features = ["sha1"] } | |
| 85 | + | hmac = { version = "0.12" } | |
| 86 | + | lru = { version = "0.12" } | |
| 87 | + | maud = { version = "0.27", features = ["axum"] } | |
| 88 | + | pulldown-cmark = { version = "0.13", default-features = false, features = ["html"] } | |
| 89 | + | rand = { version = "0.10" } | |
| 90 | + | reqwest = { version = "0.12", default-features = false, features = ["json", "rustls-tls-native-roots-no-provider"] } | |
| 79 | 91 | ring = { version = "0.17" } | |
| 92 | + | rpassword = { version = "7" } | |
| 93 | + | rusqlite = { version = "0.39" } | |
| 94 | + | russh = { version = "0.61", default-features = false, features = ["flate2", "ring", "rsa"] } | |
| 95 | + | rustls = { version = "0.23", default-features = false, features = ["ring", "logging", "std", "tls12"] } | |
| 80 | 96 | serde = { version = "1", features = ["derive"] } | |
| 81 | 97 | serde_json = { version = "1" } | |
| 82 | 98 | serde_yaml = { version = "0.9" } | |
| 83 | 99 | sha2 = { version = "0.10" } | |
| 84 | 100 | similar = { version = "2" } | |
| 85 | - | # `default-onig` (C Oniguruma regex engine) over the pure-Rust `default-fancy`: | |
| 86 | - | # several times faster on large files, and zig's cc cross-compiles the C just | |
| 87 | - | # fine for the static musl build (verified via deploy/build.sh's toolchain). | |
| 101 | + | ssh-key = { version = "0.7.0-rc.10" } | |
| 88 | 102 | syntect = { version = "5", default-features = false, features = ["default-onig"] } | |
| 89 | 103 | tar = { version = "0.4" } | |
| 90 | 104 | thiserror = { version = "2" } | |
| ⋯ 6 unchanged lines | |||
| 97 | 111 | tower-http = { version = "0.6", features = ["trace", "fs"] } | |
| 98 | 112 | tracing = { version = "0.1" } | |
| 99 | 113 | tracing-subscriber = { version = "0.3", features = ["env-filter"] } | |
| 100 | - | ||
| 101 | - | # ssh — use the `ring` crypto backend instead of the default `aws-lc-rs`: | |
| 102 | - | # ring is far cheaper to compile (no cmake/perl) and cross-compiles cleanly | |
| 103 | - | # (zigbuild/musl), which matters for building images for the low-RAM VPS. | |
| 104 | - | russh = { version = "0.61", default-features = false, features = ["flate2", "ring", "rsa"] } | |
| 105 | - | # ssh-key parsing/fingerprinting, shared by anvil-core (storage) and anvil-ssh | |
| 106 | - | # (auth). Pinned to match russh's transitive ssh-key so fingerprints agree. | |
| 107 | - | ssh-key = { version = "0.7.0-rc.10" } | |