-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathCargo.toml
More file actions
65 lines (61 loc) · 2.92 KB
/
Copy pathCargo.toml
File metadata and controls
65 lines (61 loc) · 2.92 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
[workspace]
resolver = "2"
members = ["crates/enccore", "crates/git-remote-enc"]
[workspace.package]
version = "0.2.0"
edition = "2024"
authors = [
"Vincent Vanackere <vvanackere@wallix.com>",
"WALLIX",
]
license = "Apache-2.0"
repository = "https://github.com/wallix/git-remote-enc"
homepage = "https://github.com/wallix/git-remote-enc"
description = "git remote helper storing an end-to-end encrypted repository inside an ordinary git repository (GitLab, GitHub, any host)"
# Smaller, faster, more deterministic release binaries: cross-crate inlining +
# dead-code elimination (thin LTO, one codegen unit) and symbol stripping.
[profile.release]
strip = true
lto = "thin"
codegen-units = 1
# Deny-lints applied to every workspace member (each crate opts in with
# `[lints] workspace = true`). Tests relax them at the crate root with
# `#![cfg_attr(test, allow(...))]`, never here.
[workspace.lints.clippy]
unwrap_used = "deny"
expect_used = "deny"
panic = "deny"
indexing_slicing = "deny"
arithmetic_side_effects = "deny"
# Single source of truth for dependency versions. Members reference these with
# `<dep>.workspace = true` and add only the per-crate features they need.
[workspace.dependencies]
anyhow = "1"
# The age file format (X25519 recipients, ChaCha20-Poly1305 STREAM payload)
# for every ciphertext the helper stores: the manifest, encrypted to the
# participants, and each pack, encrypted to a fresh per-pack key. The `ssh`
# feature accepts ssh-ed25519 public keys as recipients and OpenSSH private
# keys as identities (it also pulls in `rsa`; ssh-rsa keys are refused before
# they reach it), so a participant is identified by the SSH key
# they already use with the hosting service. Reimplementing the format is
# correctness-critical; the crate is the reference implementation.
age = { version = "0.12", default-features = false, features = ["ssh"] }
# OpenSSH key parsing (including passphrase-encrypted private keys) and SSH
# signatures (`ssh-keygen -Y sign` format) for manifest authentication, so the
# same SSH key both decrypts and signs. Pure Rust, musl-static friendly.
ssh-key = { version = "0.6", default-features = false, features = ["ed25519", "encryption", "std"] }
# SHA-256 names the encrypted packs in the manifest and keys the per-remote
# local state directory. No stdlib hash. The 0.10 line underlies age and ssh-key
# and works with `hmac`.
sha2 = "0.10"
# HMAC-SHA256 authenticating the local trust state. Already in the tree
# through age (HKDF); a MAC is not something to maintain by hand.
hmac = "0.12"
# Wiping secrets (pack keys, the decrypted manifest, passphrases, derived keys)
# from memory on drop. Already in the tree through age and ssh-key, which use it
# for their own key types.
zeroize = "1"
# Reading a key passphrase from /dev/tty with echo disabled needs termios,
# which std does not expose. stdout is git's protocol channel, so the prompt
# must go to the tty, which this crate does by default.
rpassword = "7"