Files
IronStorage/DEPENDENCIES.md

9.5 KiB

Dependency and license review

Reviewed 2026-08-09. The OpenPGP backend decision is complete. The project license remains intentionally unset pending the full transitive license audit and packaging review described below.

License direction

The preferred implementation stack permits IronStorage itself to use MIT OR Apache-2.0. That is the provisional choice, not yet a final license.

The current direct dependencies are:

Crate Purpose License
cap-std 4.0, cap-tempfile 4.0 Capability-scoped filesystem access and atomic temporary files Apache-2.0 WITH LLVM-exception OR Apache-2.0 OR MIT
clap 4.6, clap_complete 4.6 CLI parsing and in-process shell completion generation MIT OR Apache-2.0
crossterm 0.29 Terminal I/O MIT
Ratatui 0.30 TUI MIT
Iced 0.14 Desktop UI MIT
muda 0.19 Safe native macOS application menus and standard roles MIT OR Apache-2.0
rfd 0.17, ashpd 0.13 Native macOS/Windows folder picker and Linux XDG portal folder picker MIT
gix 0.86, gix-config 0.59 Embedded Git objects, index, references, fetch, and merge MIT OR Apache-2.0
reqwest 0.13 HTTPS smart-Git transport with Rustls MIT OR Apache-2.0
flate2 1.1, sha1 0.10 Git pack compression and checksums MIT OR Apache-2.0
pgp 0.20 Embedded OpenPGP key import, encryption, decryption, and signatures MIT OR Apache-2.0
keepass 0.13 Pure-Rust KeePass KDBX 3/4 decryption and parsing for direct imports MIT
rand 0.8 Operating-system-backed cryptographic randomness for OpenPGP operations MIT OR Apache-2.0
regex 1.13 Linear-time byte-oriented decrypted grep matching MIT OR Apache-2.0
tempfile 3 Permission-restricted CLI editor session directories and cleanup MIT OR Apache-2.0
Serde 1, TOML 0.9, shlex 1.3, url 2.5 Strict configuration and command values MIT OR Apache-2.0
UniFFI 0.32 Swift bridge MPL-2.0
zeroize 1.9 Clear decrypted bytes on drop MIT OR Apache-2.0

The activated transitive graph has no dependency that forces a GPL or LGPL license choice. UniFFI and its support crates are the only mandatory copyleft dependencies; MPL-2.0 is file-level copyleft and permits a larger work under a different license, subject to its notice and source-availability requirements.

pass is GPL-2.0-or-later and pass-otp is GPL-3.0. Treat their documentation and observable behavior as compatibility requirements, but do not copy their source or tests into IronStorage. Any such reuse requires a fresh license decision.

Storage implementation candidates

Slice Candidate License Decision
GPG-compatible packets, encryption, and transferable keys pgp 0.20 MIT OR Apache-2.0 Selected with default features disabled. The fixture harness proves armored/binary protected key import, packet validation, GPG-compatible decryption, multi-recipient encryption, and detached signatures without native libraries or processes.
Alternative GPG implementation sequoia-openpgp 2.4 LGPL-2.0-or-later Hold in reserve. Its default Nettle backend is native; its Rust backend exists, but the LGPL adds distribution work we can avoid.
GnuPG integration gpgme 0.11 LGPL-2.1 Reject: native GPGME/GnuPG integration and GPG engine processes violate the portability and no-process requirements.
Local Git plus HTTPS fetch/push gix 0.86 MIT OR Apache-2.0 Selected with default features off and blocking-http-transport-reqwest-rust-tls; accept HTTPS remotes only, supply credentials directly, and use the storage-owned receive-pack implementation for push.
Git FFI fallback git2 0.21 MIT OR Apache-2.0 Reject for now; it links libgit2 and is unnecessary for the HTTPS-only scope.
Server/application credentials keyring-core 1.0, apple-native-keyring-store 1.0, windows-native-keyring-store 1.1, zbus-secret-service-keyring-store 1.0 MIT OR Apache-2.0 Selected behind target-specific dependencies. Apple supports legacy Keychain plus protected-data user presence, Windows uses Credential Manager, and Linux uses Secret Service with the Tokio/Rust-crypto feature.
Secret values in memory secrecy 0.10, zeroize 1.9 MIT OR Apache-2.0 zeroize selected for the storage-owned redacted byte type; consider secrecy only when typed exposure controls add value.
Password generation rand MIT OR Apache-2.0 Preferred using the operating-system CSPRNG.
TOTP and HOTP hmac 0.12, sha1 0.10, sha2 0.10, data-encoding 2.11 MIT or MIT OR Apache-2.0 Selected for a small storage-owned implementation with RFC 4226/6238 vectors. Handled URIs retain exact bytes while decoded secrets zeroize; totp-rs rejects HOTP URIs and cannot cover all of pass-otp.
Native desktop clipboard arboard 3.6 MIT OR Apache-2.0 Selected with image support disabled and Wayland data-control enabled. Storage owns timeout, cleanup, and newer-content race policy; the safe adapter provides macOS, Windows, X11, and Wayland text access without helper processes.
Native macOS menu bar muda 0.19 MIT OR Apache-2.0 Selected only on macOS. Its safe NSApp adapter supplies standard roles and accelerators; Linux and Windows use the same action registry through an in-window Iced menu bar, avoiding GTK and Win32 integration dependencies.
Native folder picker rfd 0.17, ashpd 0.13 MIT rfd is selected without default features for safe native macOS and Windows panels. Linux uses ashpd directly over the XDG Desktop Portal so the application never takes rfd's zenity subprocess fallback.
CLI cancellation ctrlc 3.5 MIT OR Apache-2.0 Selected for cross-platform interruption of the blocking clipboard lease. Ctrl-C requests storage cleanup before the CLI returns cancellation.
Hidden CLI input rpassword 7.5 Apache-2.0 Selected for portable terminal input with echo disabled. The CLI immediately moves returned strings into storage-owned zeroizing OTP input objects; it does not own validation or confirmation policy.
QR output and desktop image input qrcode 0.14, rqrr 0.10 MIT OR Apache-2.0; second crate also includes ISC qrcode selected without image features for storage-owned matrices and terminal rendering. rqrr is test-only round-trip verification. Apple camera scanning should use AVFoundation and pass only decoded bytes to Rust.
Atomic file replacement and scoped filesystem access cap-std 4.0, cap-tempfile 4.0 Apache-2.0 WITH LLVM-exception OR Apache-2.0 OR MIT Selected. Directory capabilities prevent vault escape; temporary files are anonymous where supported and are synced before atomic replacement.

With this path, the central crate needs no third-party native GPG, Git, OTP, or QR library. Apple Security/LocalAuthentication, Windows Credential Manager, Linux Secret Service, and Apple camera APIs remain operating-system boundaries.

Release gate

Before choosing and adding the project license:

  1. Lock the storage dependencies and run a full transitive license audit.
  2. Confirm the required notices/source offers for MPL-2.0 dependencies in every distributed app package.

The checked-in compatibility suite completes the earlier OpenPGP backend gate: pgp imports protected armored and binary exports, decrypts every GnuPG-audited fixture, emits independently decryptable single- and multi-recipient messages, and verifies the detached recipient signatures.