Files
IronStorage/DEPENDENCIES.md
2026-08-09 21:41:31 +00:00

5.8 KiB

Dependency and license review

Reviewed 2026-08-09. The project license remains intentionally unset until the GPG compatibility spike is complete.

License direction

The preferred implementation stack permits IronStorage itself to use MIT OR Apache-2.0. That is the provisional choice, not yet a final license.

The current direct dependencies are:

Crate Purpose License
cap-std 4.0, cap-tempfile 4.0 Capability-scoped filesystem access and atomic temporary files Apache-2.0 WITH LLVM-exception OR Apache-2.0 OR MIT
clap 4.6 CLI parsing MIT OR Apache-2.0
crossterm 0.29 Terminal I/O MIT
Ratatui 0.30 TUI MIT
Iced 0.14 Desktop UI MIT
Serde 1, TOML 0.9, shlex 1.3, url 2.5 Strict configuration and command values MIT OR Apache-2.0
UniFFI 0.32 Swift bridge MPL-2.0
zeroize 1.9 Clear decrypted bytes on drop MIT OR Apache-2.0

The activated transitive graph has no dependency that forces a GPL or LGPL license choice. UniFFI and its support crates are the only mandatory copyleft dependencies; MPL-2.0 is file-level copyleft and permits a larger work under a different license, subject to its notice and source-availability requirements.

pass is GPL-2.0-or-later and pass-otp is GPL-3.0. Treat their documentation and observable behavior as compatibility requirements, but do not copy their source or tests into IronStorage. Any such reuse requires a fresh license decision.

Storage implementation candidates

Slice Candidate License Decision
GPG-compatible packets, encryption, and transferable keys pgp 0.20 MIT OR Apache-2.0 Preferred; pure Rust, including its default Rust bzip2 backend. Prove interoperability with GPG-produced fixtures first.
Alternative GPG implementation sequoia-openpgp 2.4 LGPL-2.0-or-later Hold in reserve. Its default Nettle backend is native; its Rust backend exists, but the LGPL adds distribution work we can avoid.
GnuPG integration gpgme 0.11 LGPL-2.1 Reject: native GPGME/GnuPG integration and GPG engine processes violate the portability and no-process requirements.
Local Git plus HTTPS fetch/push gix 0.86 MIT OR Apache-2.0 Preferred with default features off and blocking-http-transport-reqwest-rust-tls; accept HTTPS remotes only and supply credentials directly.
Git FFI fallback git2 0.21 MIT OR Apache-2.0 Reject for now; it links libgit2 and is unnecessary for the HTTPS-only scope.
Server/application credentials keyring-core 1.0, apple-native-keyring-store, windows-native-keyring-store, zbus-secret-service-keyring-store MIT OR Apache-2.0 Preferred per-platform stores. The Apple protected store supports iOS/macOS protected data and biometric access. Use the Linux store's Rust crypto feature.
Secret values in memory secrecy 0.10, zeroize 1.9 MIT OR Apache-2.0 zeroize selected for the storage-owned redacted byte type; consider secrecy only when typed exposure controls add value.
Password generation rand MIT OR Apache-2.0 Preferred using the operating-system CSPRNG.
TOTP and HOTP hmac, sha1, sha2, data-encoding, url MIT or MIT OR Apache-2.0 Preferred small implementation with RFC test vectors. totp-rs is MIT but rejects HOTP URIs, so it cannot cover all of pass-otp.
QR output and desktop image input qrcode 0.14, rqrr 0.10 MIT OR Apache-2.0; second crate also includes ISC Suitable. Apple camera scanning should use AVFoundation and pass only the decoded URI to Rust.
Atomic file replacement and scoped filesystem access cap-std 4.0, cap-tempfile 4.0 Apache-2.0 WITH LLVM-exception OR Apache-2.0 OR MIT Selected. Directory capabilities prevent vault escape; temporary files are anonymous where supported and are synced before atomic replacement.

With this path, the central crate needs no third-party native GPG, Git, OTP, or QR library. Apple Security/LocalAuthentication, Windows Credential Manager, Linux Secret Service, and Apple camera APIs remain operating-system boundaries.

Release gate

Before choosing and adding the project license:

  1. Prove pgp can decrypt, encrypt, re-encrypt, and round-trip representative GPG files and exported keys from real pass stores.
  2. Lock the storage dependencies and run a full transitive license audit.
  3. Confirm the required notices/source offers for MPL-2.0 dependencies in every distributed app package.