Initial IronStorage project structure
This commit is contained in:
59
DEPENDENCIES.md
Normal file
59
DEPENDENCIES.md
Normal file
@@ -0,0 +1,59 @@
|
||||
# Dependency and license review
|
||||
|
||||
Reviewed 2026-08-09. The project license remains intentionally unset until the
|
||||
GPG compatibility spike is complete.
|
||||
|
||||
## License direction
|
||||
|
||||
The preferred implementation stack permits IronStorage itself to use
|
||||
`MIT OR Apache-2.0`. That is the provisional choice, not yet a final license.
|
||||
|
||||
The current direct dependencies are:
|
||||
|
||||
| Crate | Purpose | License |
|
||||
| --- | --- | --- |
|
||||
| [clap 4.6](https://crates.io/crates/clap/4.6.4) | CLI parsing | MIT OR Apache-2.0 |
|
||||
| [crossterm 0.29](https://crates.io/crates/crossterm/0.29.0) | Terminal I/O | MIT |
|
||||
| [Ratatui 0.30](https://crates.io/crates/ratatui/0.30.2) | TUI | MIT |
|
||||
| [Iced 0.14](https://crates.io/crates/iced/0.14.0) | Desktop UI | MIT |
|
||||
| [UniFFI 0.32](https://crates.io/crates/uniffi/0.32.0) | Swift bridge | MPL-2.0 |
|
||||
|
||||
The activated transitive graph has no dependency that forces a GPL or LGPL
|
||||
license choice. UniFFI and its support crates are the only mandatory copyleft
|
||||
dependencies; MPL-2.0 is file-level copyleft and permits a larger work under a
|
||||
different license, subject to its notice and source-availability requirements.
|
||||
|
||||
`pass` is GPL-2.0-or-later and `pass-otp` is GPL-3.0. Treat their documentation
|
||||
and observable behavior as compatibility requirements, but do not copy their
|
||||
source or tests into IronStorage. Any such reuse requires a fresh license
|
||||
decision.
|
||||
|
||||
## Storage implementation candidates
|
||||
|
||||
| Slice | Candidate | License | Decision |
|
||||
| --- | --- | --- | --- |
|
||||
| GPG-compatible packets, encryption, and transferable keys | [`pgp` 0.20](https://crates.io/crates/pgp/0.20.0) | MIT OR Apache-2.0 | Preferred; pure Rust, including its default Rust bzip2 backend. Prove interoperability with GPG-produced fixtures first. |
|
||||
| Alternative GPG implementation | [`sequoia-openpgp` 2.4](https://crates.io/crates/sequoia-openpgp/2.4.1) | LGPL-2.0-or-later | Hold in reserve. Its default Nettle backend is native; its Rust backend exists, but the LGPL adds distribution work we can avoid. |
|
||||
| GnuPG integration | [`gpgme` 0.11](https://crates.io/crates/gpgme/0.11.0) | LGPL-2.1 | Reject: native GPGME/GnuPG integration and GPG engine processes violate the portability and no-process requirements. |
|
||||
| Local Git plus HTTPS fetch/push | [`gix` 0.86](https://crates.io/crates/gix/0.86.0) | MIT OR Apache-2.0 | Preferred with default features off and `blocking-http-transport-reqwest-rust-tls`; accept HTTPS remotes only and supply credentials directly. |
|
||||
| Git FFI fallback | [`git2` 0.21](https://crates.io/crates/git2/0.21.0) | MIT OR Apache-2.0 | Reject for now; it links libgit2 and is unnecessary for the HTTPS-only scope. |
|
||||
| Server/application credentials | [`keyring-core` 1.0](https://crates.io/crates/keyring-core/1.0.0), [`apple-native-keyring-store`](https://crates.io/crates/apple-native-keyring-store/1.0.2), [`windows-native-keyring-store`](https://crates.io/crates/windows-native-keyring-store/1.1.0), [`zbus-secret-service-keyring-store`](https://crates.io/crates/zbus-secret-service-keyring-store/1.0.0) | MIT OR Apache-2.0 | Preferred per-platform stores. The Apple protected store supports iOS/macOS protected data and biometric access. Use the Linux store's Rust crypto feature. |
|
||||
| Secret values in memory | [`secrecy` 0.10](https://crates.io/crates/secrecy/0.10.3), [`zeroize` 1.9](https://crates.io/crates/zeroize/1.9.0) | MIT OR Apache-2.0 | Preferred wrappers; still avoid unnecessary copies and logging. |
|
||||
| Password generation | [`rand`](https://crates.io/crates/rand) | MIT OR Apache-2.0 | Preferred using the operating-system CSPRNG. |
|
||||
| TOTP and HOTP | [`hmac`](https://crates.io/crates/hmac), [`sha1`](https://crates.io/crates/sha1), [`sha2`](https://crates.io/crates/sha2), [`data-encoding`](https://crates.io/crates/data-encoding), [`url`](https://crates.io/crates/url) | MIT or MIT OR Apache-2.0 | Preferred small implementation with RFC test vectors. `totp-rs` is MIT but rejects HOTP URIs, so it cannot cover all of `pass-otp`. |
|
||||
| QR output and desktop image input | [`qrcode` 0.14](https://crates.io/crates/qrcode/0.14.1), [`rqrr` 0.10](https://crates.io/crates/rqrr/0.10.1) | MIT OR Apache-2.0; second crate also includes ISC | Suitable. Apple camera scanning should use AVFoundation and pass only the decoded URI to Rust. |
|
||||
| Atomic file replacement | standard library, then [`tempfile`](https://crates.io/crates/tempfile) if needed | MIT OR Apache-2.0 | Start with the standard library; add `tempfile` only when the first safe-write implementation needs it. |
|
||||
|
||||
With this path, the central crate needs no third-party native GPG, Git, OTP, or
|
||||
QR library. Apple Security/LocalAuthentication, Windows Credential Manager,
|
||||
Linux Secret Service, and Apple camera APIs remain operating-system boundaries.
|
||||
|
||||
## Release gate
|
||||
|
||||
Before choosing and adding the project license:
|
||||
|
||||
1. Prove `pgp` can decrypt, encrypt, re-encrypt, and round-trip representative
|
||||
GPG files and exported keys from real `pass` stores.
|
||||
2. Lock the storage dependencies and run a full transitive license audit.
|
||||
3. Confirm the required notices/source offers for MPL-2.0 dependencies in every
|
||||
distributed app package.
|
||||
Reference in New Issue
Block a user