# Crypto-critical crates guarded by scripts/check-crypto-vet.sh (issue #322).
#
# Every crate listed here must be covered by a real cargo-vet audit (ours or
# imported) at each version in Cargo.lock -- that is, appear in the
# `vetted_fully` set of `cargo vet --locked --output-format=json`. The
# "move the exemption to the bumped version" path is NOT available for these
# crates. See docs/supply-chain.md "Contributor workflow" and DECISIONS.md
# "#322 supply-chain audit policy".
#
# Format: one crate per line:   <crate> [allow-exempt:<anchor>]
#   (no marker)                       must be fully vetted at every locked version.
#   allow-exempt:#322-pending         re-certification still in progress (#322);
#                                     passes while exempted, FAILS once the crate
#                                     is fully vetted ("stale marker -- remove it").
#                                     #322 is complete: no line uses it any more,
#                                     and a new use needs a DECISIONS.md entry.
#   allow-exempt:DECISIONS#322-<crate>@<version>
#                                     kept exempt under the #322 concern rule;
#                                     the anchor must be exactly 322-<crate> and
#                                     appear as a whole token in DECISIONS.md;
#                                     @<version> is required and pins the one
#                                     exempted version: the guard FAILS if a
#                                     locked-but-unaudited version or a
#                                     config.toml exemption differs from it
#                                     (re-audit, or update the DECISIONS entry
#                                     and the marker); same stale-marker check.
# Any other marker fails the guard. A line whose first non-blank character is
# `#` is a comment, as is anything after whitespace followed by `#`.
#
# This file lives outside supply-chain/ because cargo-vet owns that directory
# and rewrites its files (dropping comments).

# Tier A (#322).
ed25519-dalek
curve25519-dalek
signature
sha2
zeroize           allow-exempt:DECISIONS#322-zeroize@1.9.0
subtle
p256
ecdsa
elliptic-curve
rustls
ring

# Tier B (#339), added as each crate is certified.
# Batch B1:
wnaf
ff
spki
crypto-common
zeroize_derive
ed25519
# Batch B2:
hmac
rfc6979
pkcs8
sec1
primefield
digest
# Batch B3:
untrusted
cpubits
hyper-rustls
group
tokio-rustls
primeorder
# Batch B4:
rand_core
ctutils
webpki-roots
typenum
# Batch B5:
base16ct
base64ct
rustls-pki-types
const-oid
der
curve25519-dalek-derive
# Batch B6:
cpufeatures
block-buffer
cmov
hybrid-array
crypto-bigint
# Batch B7:
getrandom
rustls-webpki
