Repository navigation
Expand file tree
/
Copy pathCargo.toml
More file actions
93 lines (87 loc) · 4.1 KB
/
Copy pathCargo.toml
File metadata and controls
93 lines (87 loc) · 4.1 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
[package]
name = "beady-eye"
version = "0.25.0"
edition = "2021"
rust-version = "1.88"
description = "One unblinking eye over all your beads trackers. Shows the trees of work and the agents on them, wakes an agent when a bead it waits on changes, and settles pull-request waits from GitHub."
repository = "https://github.com/CodeForBreakfast/beady-eye"
license = "Apache-2.0"
readme = "README.md"
keywords = ["beads", "herdr", "agents", "tui"]
categories = ["command-line-utilities", "development-tools"]
# An allowlist, not an exclude list. A published version cannot be withdrawn —
# a yank still serves the files — so a file that reaches the tarball is public
# for good. Anything a consumer of the crate does not need stays out.
#
# Every pattern is anchored. Cargo matches these the way gitignore does, so an
# unanchored "README.md" also selects .beads/README.md.
#
# The README's pictures are deliberately absent. Cargo sends the README's text
# in the publish request and crates.io never opens the tarball to render it, so
# an image reaches a reader over the network whatever this list says: crates.io
# rewrites the relative path to `<repository>/raw/HEAD/<path>`. Adding the files
# here would grow the tarball and change nothing. What it does mean is that
# every published version's README points at whatever stands at those paths on
# the default branch, so an image the README names cannot be moved or deleted
# without breaking the front page of releases already out.
include = [
"/src/**",
"/Cargo.toml",
"/Cargo.lock",
"/README.md",
"/LICENSE",
]
[lib]
name = "beady_eye"
path = "src/lib.rs"
[[bin]]
name = "bdi"
path = "src/main.rs"
[dependencies]
anyhow = "1.0.104"
base64 = "0.23.1"
chrono = { version = "0.4.45", default-features = false, features = ["std", "clock", "serde"] }
clap = { version = "4.6.6", features = ["derive"] }
# The signature GitHub puts on each webhook delivery is an HMAC-SHA256 of its
# body, and nothing in `std` computes one. RustCrypto's pair, which move
# together because both are built on one version of `digest`, and
# `verify_slice` compares in constant time.
hmac = "0.13.0"
# `bdi gates --listen` takes GitHub's webhook deliveries over HTTP. The request
# head is parsed by this, a parser with no dependencies of its own, and
# everything else is std's `TcpListener`, so every limit on what a request may
# cost before its signature is checked is one this code sets. tiny_http 0.12
# cannot be used here: dropping a request whose body is unread drains it, with a
# buffer as large as the length the sender declared.
httparse = "1.10.1"
# Which user this run is, which nothing in `std` will say and the socket's way
# down has to be judged against. It is also the pty a test drives bdi through,
# which is what it was here for while it was a dev-dependency. Named for the
# same reason signal-hook is: the crate is compiled either way as signal-hook's
# own, and one reached only through another crate's tree is not one this code
# may `use`.
libc = "0.2.189"
pulldown-cmark = { version = "0.13.4", default-features = false }
ratatui = "0.30.2"
# A badge's `match` is a pattern out of a config file, and nothing in `std`
# will match one. The `-lite` build is the same linear-time engine without the
# unicode tables or the SIMD searchers, which a config file's patterns do not
# reach for, and it costs a fraction of the build.
regex-lite = "0.1.9"
serde = { version = "1.0.229", features = ["derive", "rc"] }
serde_json = { version = "1.0.151", features = ["raw_value"] }
sha2 = "0.11.0"
# Named directly, though crossterm already compiles it for its own resize
# plumbing: a crate reached only through another crate's tree is not one
# this code may `use`, and would go the day crossterm changed its mind.
signal-hook = "0.4.4"
toml = "1.1.5"
[features]
# What `tests/` reaches that bdi does not. Cargo builds dev-dependencies only
# for the targets that compile tests, so the package depending on itself here
# is what turns this on for `cargo test` and leaves `cargo build` narrow. See
# src/lib.rs.
testing = []
[dev-dependencies]
beady-eye = { path = ".", features = ["testing"] }
pretty_assertions = "1.4.1"