Files
openmail/Cargo.toml
T
Karti TripathiandClaude Opus 5 4b6f08e170 Drop mail-auth's 'generate' feature: removes RUSTSEC-2023-0071
cargo-deny's advisory check caught the rsa crate (RUSTSEC-2023-0071, the
Marvin Attack — private-key recovery through a timing sidechannel that is
observable over the network, with no fixed version available).

Root cause was ours: enabling mail-auth's 'generate' feature, which exists
to create DKIM keypairs and pulls in the pure-Rust rsa implementation. The
default aws-lc-rs backend signs and verifies in constant time, which is what
a service listening on :25 actually needs. Key generation is a one-time
operator action and belongs in tooling (openssl genpkey), not in the daemon.

Fixed by removing the feature rather than by adding an advisory exception —
the reason is recorded inline in Cargo.toml so nobody re-adds it.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01JkyvfNJGTshJNE9FtwPLk7
2026-09-02 14:01:15 -07:00

86 lines
3.3 KiB
TOML

[workspace]
resolver = "3"
members = [
# Tier 1 — standalone, publishable to crates.io. No openmail-* dependencies.
"crates/mail-dane",
"crates/mail-mta-sts",
"crates/mail-dsn",
# Tier 2 — OpenMail mail engine.
"crates/openmail-guard",
"crates/openmail-junk",
"crates/openmail-smtpd",
"crates/openmail-relay",
# Tier 3 — the agent-native layer. The product.
"crates/openmail-core",
"crates/openmail-store",
"crates/openmail-api",
"crates/openmail-mcp",
"crates/openmail",
]
[workspace.package]
version = "0.1.0"
edition = "2024"
rust-version = "1.90"
license = "Apache-2.0"
repository = "https://github.com/karti-ai/openmail"
homepage = "https://openmail.karti.ai"
authors = ["Karti Tripathi"]
[workspace.dependencies]
# --- internal ---
mail-dane = { version = "0.1.0", path = "crates/mail-dane" }
mail-mta-sts = { version = "0.1.0", path = "crates/mail-mta-sts" }
mail-dsn = { version = "0.1.0", path = "crates/mail-dsn" }
openmail-guard = { version = "0.1.0", path = "crates/openmail-guard" }
openmail-junk = { version = "0.1.0", path = "crates/openmail-junk" }
openmail-smtpd = { version = "0.1.0", path = "crates/openmail-smtpd" }
openmail-relay = { version = "0.1.0", path = "crates/openmail-relay" }
openmail-core = { version = "0.1.0", path = "crates/openmail-core" }
openmail-store = { version = "0.1.0", path = "crates/openmail-store" }
openmail-api = { version = "0.1.0", path = "crates/openmail-api" }
openmail-mcp = { version = "0.1.0", path = "crates/openmail-mcp" }
# --- third party (all Apache-2.0 or MIT; see NOTICE) ---
mail-parser = { version = "0.11", features = ["full_encoding"] }
mail-builder = "0.5"
# NO "generate" feature. It pulls in the `rsa` crate, which carries
# RUSTSEC-2023-0071 (Marvin Attack — private-key recovery through a timing
# sidechannel observable over the network) with no fixed version available.
# The default `aws-lc-rs` backend signs and verifies in constant time, which is
# what a network service actually needs. DKIM keypair generation is a one-time
# operator action and belongs in tooling (`openssl genpkey`), not in a daemon
# listening on :25.
mail-auth = { version = "0.12" }
smtp-proto = "0.2"
hickory-resolver = { version = "0.26", features = ["dnssec-ring"] }
tokio = { version = "1", features = ["full"] }
axum = "0.8"
tower-http = { version = "0.6", features = ["trace", "limit"] }
sqlx = { version = "0.8", features = ["runtime-tokio", "postgres", "uuid", "chrono", "json", "migrate"] }
serde = { version = "1", features = ["derive"] }
serde_json = "1"
thiserror = "2"
anyhow = "1"
tracing = "0.1"
tracing-subscriber = { version = "0.3", features = ["env-filter", "json"] }
uuid = { version = "1", features = ["v7", "serde"] }
chrono = { version = "0.4", features = ["serde"] }
clap = { version = "4", features = ["derive", "env"] }
rustls = "0.23"
sha2 = "0.10"
base64 = "0.22"
[workspace.lints.rust]
unsafe_code = "forbid"
[workspace.lints.clippy]
all = { level = "deny", priority = -1 }
pedantic = { level = "warn", priority = -1 }
[profile.release]
lto = "thin"
codegen-units = 1
strip = true