diff options
| author | srdusr <[email protected]> | 2026-03-07 00:37:00 +0200 |
|---|---|---|
| committer | srdusr <[email protected]> | 2026-03-07 00:37:00 +0200 |
| commit | 4ffaeda5cf0da756ea05b6d13913ce3d775990d6 (patch) | |
| tree | b17c0b474b9f4a9ad26cf3367183e60aee7e6668 /Cargo.toml | |
| parent | 4ebea6b2cab0a09b65e5b22188af0b4025c2342f (diff) | |
| download | typerpunk-4ffaeda5cf0da756ea05b6d13913ce3d775990d6.tar.gz typerpunk-4ffaeda5cf0da756ea05b6d13913ce3d775990d6.zip | |
Declare hmac, sha2 and subtle at the workspace root
crates/server takes all three with workspace = true for the Stripe
webhook signature check, but the root manifest never defined them, so a
clean checkout did not resolve. They were already in the tree through
argon2; this only names them.
Diffstat (limited to 'Cargo.toml')
| -rwxr-xr-x | Cargo.toml | 5 |
1 files changed, 5 insertions, 0 deletions
@@ -51,6 +51,11 @@ tower-http = { version = "0.5", features = ["cors", "trace", "set-header"] } # with them rsa, which carries RUSTSEC-2023-0071. Only Postgres is used. sqlx = { version = "0.8", default-features = false, features = ["runtime-tokio-rustls", "postgres", "macros", "migrate", "time", "uuid"] } argon2 = "0.5" +# Already in the tree through argon2; declared directly because the Stripe +# webhook signature check needs them by name. +hmac = "0.12" +sha2 = "0.10" +subtle = "2.6" # 0.12 moves to hyper 1.x, which brings h2 0.4 and rustls 0.23 with it. # 0.11 was the sole source of every remaining advisory in the server build: # h2 0.3, rustls-webpki 0.101, rustls-pemfile 1.0 and idna 0.3. |