cargo-deny's advisory check caught the rsa crate (RUSTSEC-2023-0071, the Marvin Attack — private-key recovery through a timing sidechannel that is observable over the network, with no fixed version available). Root cause was ours: enabling mail-auth's 'generate' feature, which exists to create DKIM keypairs and pulls in the pure-Rust rsa implementation. The default aws-lc-rs backend signs and verifies in constant time, which is what a service listening on :25 actually needs. Key generation is a one-time operator action and belongs in tooling (openssl genpkey), not in the daemon. Fixed by removing the feature rather than by adding an advisory exception — the reason is recorded inline in Cargo.toml so nobody re-adds it. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01JkyvfNJGTshJNE9FtwPLk7
86 lines
3.3 KiB
TOML
86 lines
3.3 KiB
TOML
[workspace]
|
|
resolver = "3"
|
|
members = [
|
|
# Tier 1 — standalone, publishable to crates.io. No openmail-* dependencies.
|
|
"crates/mail-dane",
|
|
"crates/mail-mta-sts",
|
|
"crates/mail-dsn",
|
|
# Tier 2 — OpenMail mail engine.
|
|
"crates/openmail-guard",
|
|
"crates/openmail-junk",
|
|
"crates/openmail-smtpd",
|
|
"crates/openmail-relay",
|
|
# Tier 3 — the agent-native layer. The product.
|
|
"crates/openmail-core",
|
|
"crates/openmail-store",
|
|
"crates/openmail-api",
|
|
"crates/openmail-mcp",
|
|
"crates/openmail",
|
|
]
|
|
|
|
[workspace.package]
|
|
version = "0.1.0"
|
|
edition = "2024"
|
|
rust-version = "1.90"
|
|
license = "Apache-2.0"
|
|
repository = "https://github.com/karti-ai/openmail"
|
|
homepage = "https://openmail.karti.ai"
|
|
authors = ["Karti Tripathi"]
|
|
|
|
[workspace.dependencies]
|
|
# --- internal ---
|
|
mail-dane = { version = "0.1.0", path = "crates/mail-dane" }
|
|
mail-mta-sts = { version = "0.1.0", path = "crates/mail-mta-sts" }
|
|
mail-dsn = { version = "0.1.0", path = "crates/mail-dsn" }
|
|
openmail-guard = { version = "0.1.0", path = "crates/openmail-guard" }
|
|
openmail-junk = { version = "0.1.0", path = "crates/openmail-junk" }
|
|
openmail-smtpd = { version = "0.1.0", path = "crates/openmail-smtpd" }
|
|
openmail-relay = { version = "0.1.0", path = "crates/openmail-relay" }
|
|
openmail-core = { version = "0.1.0", path = "crates/openmail-core" }
|
|
openmail-store = { version = "0.1.0", path = "crates/openmail-store" }
|
|
openmail-api = { version = "0.1.0", path = "crates/openmail-api" }
|
|
openmail-mcp = { version = "0.1.0", path = "crates/openmail-mcp" }
|
|
|
|
# --- third party (all Apache-2.0 or MIT; see NOTICE) ---
|
|
mail-parser = { version = "0.11", features = ["full_encoding"] }
|
|
mail-builder = "0.5"
|
|
# NO "generate" feature. It pulls in the `rsa` crate, which carries
|
|
# RUSTSEC-2023-0071 (Marvin Attack — private-key recovery through a timing
|
|
# sidechannel observable over the network) with no fixed version available.
|
|
# The default `aws-lc-rs` backend signs and verifies in constant time, which is
|
|
# what a network service actually needs. DKIM keypair generation is a one-time
|
|
# operator action and belongs in tooling (`openssl genpkey`), not in a daemon
|
|
# listening on :25.
|
|
mail-auth = { version = "0.12" }
|
|
smtp-proto = "0.2"
|
|
hickory-resolver = { version = "0.26", features = ["dnssec-ring"] }
|
|
|
|
tokio = { version = "1", features = ["full"] }
|
|
axum = "0.8"
|
|
tower-http = { version = "0.6", features = ["trace", "limit"] }
|
|
sqlx = { version = "0.8", features = ["runtime-tokio", "postgres", "uuid", "chrono", "json", "migrate"] }
|
|
serde = { version = "1", features = ["derive"] }
|
|
serde_json = "1"
|
|
thiserror = "2"
|
|
anyhow = "1"
|
|
tracing = "0.1"
|
|
tracing-subscriber = { version = "0.3", features = ["env-filter", "json"] }
|
|
uuid = { version = "1", features = ["v7", "serde"] }
|
|
chrono = { version = "0.4", features = ["serde"] }
|
|
clap = { version = "4", features = ["derive", "env"] }
|
|
rustls = "0.23"
|
|
sha2 = "0.10"
|
|
base64 = "0.22"
|
|
|
|
[workspace.lints.rust]
|
|
unsafe_code = "forbid"
|
|
|
|
[workspace.lints.clippy]
|
|
all = { level = "deny", priority = -1 }
|
|
pedantic = { level = "warn", priority = -1 }
|
|
|
|
[profile.release]
|
|
lto = "thin"
|
|
codegen-units = 1
|
|
strip = true
|