# Crypto-critical crates guarded by scripts/check-crypto-vet.sh (issue #322).
#
# Every crate listed here must be covered by a real cargo-vet audit (ours or
# imported) at each version in Cargo.lock -- that is, appear in the
# `vetted_fully` set of `cargo vet --locked --output-format=json`. The
# "move the exemption to the bumped version" path is NOT available for these
# crates. See docs/supply-chain.md "Contributor workflow" and DECISIONS.md
# "#322 supply-chain audit policy".
#
# Format: one crate per line:   <crate> [allow-exempt:<anchor>]
#   (no marker)                       must be fully vetted at every locked version.
#   allow-exempt:#322-pending         re-certification still in progress (#322);
#                                     passes while exempted, FAILS once the crate
#                                     is fully vetted ("stale marker -- remove it").
#                                     #322 is complete: no line uses it any more,
#                                     and a new use needs a DECISIONS.md entry.
#   allow-exempt:DECISIONS#322-<crate>@<version>
#                                     kept exempt under the #322 concern rule;
#                                     the anchor must be exactly 322-<crate> and
#                                     appear as a whole token in DECISIONS.md;
#                                     @<version> is required and pins the one
#                                     exempted version: the guard FAILS if a
#                                     locked-but-unaudited version or a
#                                     config.toml exemption differs from it
#                                     (re-audit, or update the DECISIONS entry
#                                     and the marker); same stale-marker check.
# Any other marker fails the guard. A line whose first non-blank character is
# `#` is a comment, as is anything after whitespace followed by `#`.
#
# This file lives outside supply-chain/ because cargo-vet owns that directory
# and rewrites its files (dropping comments).

# Tier A (#322).
ed25519-dalek
curve25519-dalek
signature
sha2
zeroize           allow-exempt:DECISIONS#322-zeroize@1.9.0
subtle
p256
ecdsa
elliptic-curve
rustls
ring
