supply_chain.toml (3511B)
1 schema_version = 1 2 spec_id = "radroots.crates.release.v1" 3 package_version = "0.1.0-alpha" 4 5 [tools] 6 cargo_deny = "0.19.8" 7 cargo_cyclonedx = "0.5.9" 8 cargo_vet = "0.10.2" 9 10 [sbom] 11 format = "json" 12 spec_version = "1.5" 13 target = "all" 14 all_features = true 15 source_date_epoch = 0 16 17 [[advisory_exception]] 18 id = "RUSTSEC-2024-0384" 19 package = "instant" 20 affected_version = "0.1.13" 21 introduced_by = "nostr 0.44.7" 22 classification = "unmaintained" 23 mitigation = "No Radroots public API exposes instant; replace the dependency when upstream Nostr removes it." 24 remove_when = "nostr >=0.45.0 stable" 25 26 [[advisory_exception]] 27 id = "RUSTSEC-2024-0421" 28 package = "idna" 29 affected_version = "0.5.0" 30 introduced_by = "nostr 0.44.7 via url-fork 3.0.1" 31 classification = "vulnerability" 32 mitigation = "radroots_transport_nostr canonicalizes every relay URL with url >=2.5.4 before upstream Nostr receives it." 33 remove_when = "nostr >=0.45.0 stable" 34 35 [[advisory_exception]] 36 id = "RUSTSEC-2026-0243" 37 package = "nostr-relay-pool" 38 affected_version = "0.44.3" 39 introduced_by = "nostr-sdk 0.44.1 and radroots_transport_nostr" 40 classification = "unmaintained" 41 mitigation = "The advisory reports no vulnerability; retain the locked release line only until the governed Nostr 0.45 migration." 42 remove_when = "nostr >=0.45.0 stable" 43 44 [[advisory_exception]] 45 id = "CARGO-YANKED-SPIN-0.9.8" 46 package = "spin" 47 affected_version = "0.9.8" 48 introduced_by = "sqlx 0.9.0 via flume 0.12.0" 49 classification = "yanked" 50 mitigation = "The package has no RustSec vulnerability; the gate rejects every yanked name/version except this exact transitive dependency." 51 remove_when = "sqlx no longer resolves flume 0.12.0 with spin 0.9.8" 52 53 [[git_source]] 54 url = "https://github.com/rust-nostr/nostr.git" 55 revision = "5bba5163eb77107f82c4a8262cf29d7f33a73219" 56 packages = ["nostr", "nostr-relay-builder", "nostr-sdk"] 57 removal_when = "nostr 0.45 stable satisfies Studio compatibility tests" 58 59 [[package]] 60 name = "radroots_core" 61 manifest_path = "crates/core/Cargo.toml" 62 63 [[package]] 64 name = "radroots_identity" 65 manifest_path = "crates/identity/Cargo.toml" 66 67 [[package]] 68 name = "radroots_blossom" 69 manifest_path = "crates/blossom/Cargo.toml" 70 71 [[package]] 72 name = "radroots_protocol" 73 manifest_path = "crates/protocol/Cargo.toml" 74 75 [[package]] 76 name = "radroots_event" 77 manifest_path = "crates/event/Cargo.toml" 78 79 [[package]] 80 name = "radroots_event_codec" 81 manifest_path = "crates/event_codec/Cargo.toml" 82 83 [[package]] 84 name = "radroots_trade" 85 manifest_path = "crates/trade/Cargo.toml" 86 87 [[package]] 88 name = "radroots_signing" 89 manifest_path = "crates/signing/Cargo.toml" 90 91 [[package]] 92 name = "radroots_transport" 93 manifest_path = "crates/transport/Cargo.toml" 94 95 [[package]] 96 name = "radroots_nostr" 97 manifest_path = "crates/nostr/Cargo.toml" 98 99 [[package]] 100 name = "radroots_nostr_connect" 101 manifest_path = "crates/nostr_connect/Cargo.toml" 102 103 [[package]] 104 name = "radroots_secrets" 105 manifest_path = "crates/secrets/Cargo.toml" 106 107 [[package]] 108 name = "radroots_storage" 109 manifest_path = "crates/storage/Cargo.toml" 110 111 [[package]] 112 name = "radroots_storage_sqlite" 113 manifest_path = "crates/storage_sqlite/Cargo.toml" 114 115 [[package]] 116 name = "radroots_transport_nostr" 117 manifest_path = "crates/transport_nostr/Cargo.toml" 118 119 [[package]] 120 name = "radroots_sync" 121 manifest_path = "crates/sync/Cargo.toml" 122 123 [[package]] 124 name = "radroots_geonames" 125 manifest_path = "crates/geonames/Cargo.toml" 126 127 [[package]] 128 name = "radroots_sdk" 129 manifest_path = "crates/sdk/Cargo.toml" 130 131 [[package]] 132 name = "radroots" 133 manifest_path = "crates/radroots/Cargo.toml"