7.2 KiB
Dependency and license review
Reviewed 2026-08-09. The OpenPGP backend decision is complete. The project license remains intentionally unset pending the full transitive license audit and packaging review described below.
License direction
The preferred implementation stack permits IronStorage itself to use
MIT OR Apache-2.0. That is the provisional choice, not yet a final license.
The current direct dependencies are:
| Crate | Purpose | License |
|---|---|---|
| cap-std 4.0, cap-tempfile 4.0 | Capability-scoped filesystem access and atomic temporary files | Apache-2.0 WITH LLVM-exception OR Apache-2.0 OR MIT |
| clap 4.6 | CLI parsing | MIT OR Apache-2.0 |
| crossterm 0.29 | Terminal I/O | MIT |
| Ratatui 0.30 | TUI | MIT |
| Iced 0.14 | Desktop UI | MIT |
| gix 0.86, gix-config 0.59 | Embedded Git objects, index, references, fetch, and merge | MIT OR Apache-2.0 |
| reqwest 0.13 | HTTPS smart-Git transport with Rustls | MIT OR Apache-2.0 |
| flate2 1.1, sha1 0.10 | Git pack compression and checksums | MIT OR Apache-2.0 |
| pgp 0.20 | Embedded OpenPGP key import, encryption, decryption, and signatures | MIT OR Apache-2.0 |
| rand 0.8 | Operating-system-backed cryptographic randomness for OpenPGP operations | MIT OR Apache-2.0 |
| regex 1.13 | Linear-time byte-oriented decrypted grep matching | MIT OR Apache-2.0 |
| tempfile 3 | Permission-restricted CLI editor session directories and cleanup | MIT OR Apache-2.0 |
| Serde 1, TOML 0.9, shlex 1.3, url 2.5 | Strict configuration and command values | MIT OR Apache-2.0 |
| UniFFI 0.32 | Swift bridge | MPL-2.0 |
| zeroize 1.9 | Clear decrypted bytes on drop | MIT OR Apache-2.0 |
The activated transitive graph has no dependency that forces a GPL or LGPL license choice. UniFFI and its support crates are the only mandatory copyleft dependencies; MPL-2.0 is file-level copyleft and permits a larger work under a different license, subject to its notice and source-availability requirements.
pass is GPL-2.0-or-later and pass-otp is GPL-3.0. Treat their documentation
and observable behavior as compatibility requirements, but do not copy their
source or tests into IronStorage. Any such reuse requires a fresh license
decision.
Storage implementation candidates
| Slice | Candidate | License | Decision |
|---|---|---|---|
| GPG-compatible packets, encryption, and transferable keys | pgp 0.20 |
MIT OR Apache-2.0 | Selected with default features disabled. The fixture harness proves armored/binary protected key import, packet validation, GPG-compatible decryption, multi-recipient encryption, and detached signatures without native libraries or processes. |
| Alternative GPG implementation | sequoia-openpgp 2.4 |
LGPL-2.0-or-later | Hold in reserve. Its default Nettle backend is native; its Rust backend exists, but the LGPL adds distribution work we can avoid. |
| GnuPG integration | gpgme 0.11 |
LGPL-2.1 | Reject: native GPGME/GnuPG integration and GPG engine processes violate the portability and no-process requirements. |
| Local Git plus HTTPS fetch/push | gix 0.86 |
MIT OR Apache-2.0 | Selected with default features off and blocking-http-transport-reqwest-rust-tls; accept HTTPS remotes only, supply credentials directly, and use the storage-owned receive-pack implementation for push. |
| Git FFI fallback | git2 0.21 |
MIT OR Apache-2.0 | Reject for now; it links libgit2 and is unnecessary for the HTTPS-only scope. |
| Server/application credentials | keyring-core 1.0, apple-native-keyring-store 1.0, windows-native-keyring-store 1.1, zbus-secret-service-keyring-store 1.0 |
MIT OR Apache-2.0 | Selected behind target-specific dependencies. Apple supports legacy Keychain plus protected-data user presence, Windows uses Credential Manager, and Linux uses Secret Service with the Tokio/Rust-crypto feature. |
| Secret values in memory | secrecy 0.10, zeroize 1.9 |
MIT OR Apache-2.0 | zeroize selected for the storage-owned redacted byte type; consider secrecy only when typed exposure controls add value. |
| Password generation | rand |
MIT OR Apache-2.0 | Preferred using the operating-system CSPRNG. |
| TOTP and HOTP | hmac, sha1, sha2, data-encoding, url |
MIT or MIT OR Apache-2.0 | Preferred small implementation with RFC test vectors. totp-rs is MIT but rejects HOTP URIs, so it cannot cover all of pass-otp. |
| QR output and desktop image input | qrcode 0.14, rqrr 0.10 |
MIT OR Apache-2.0; second crate also includes ISC | Suitable. Apple camera scanning should use AVFoundation and pass only the decoded URI to Rust. |
| Atomic file replacement and scoped filesystem access | cap-std 4.0, cap-tempfile 4.0 |
Apache-2.0 WITH LLVM-exception OR Apache-2.0 OR MIT | Selected. Directory capabilities prevent vault escape; temporary files are anonymous where supported and are synced before atomic replacement. |
With this path, the central crate needs no third-party native GPG, Git, OTP, or QR library. Apple Security/LocalAuthentication, Windows Credential Manager, Linux Secret Service, and Apple camera APIs remain operating-system boundaries.
Release gate
Before choosing and adding the project license:
- Lock the storage dependencies and run a full transitive license audit.
- Confirm the required notices/source offers for MPL-2.0 dependencies in every distributed app package.
The checked-in compatibility suite completes the earlier OpenPGP backend gate:
pgp imports protected armored and binary exports, decrypts every GnuPG-audited
fixture, emits independently decryptable single- and multi-recipient messages,
and verifies the detached recipient signatures.