Repository navigation
Expand file tree
/
Copy pathCargo.toml
More file actions
136 lines (132 loc) · 6.91 KB
/
Copy pathCargo.toml
File metadata and controls
136 lines (132 loc) · 6.91 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
[package]
name = "trenches"
version = "0.3.6"
edition = "2021"
license = "AGPL-3.0-only"
description = "A terminal trading bot for memecoins on Robinhood Chain and Solana."
repository = "https://github.com/asyncswap/trenches"
homepage = "https://trenches.sh"
authors = ["AsyncSwap Labs, Inc."]
[features]
# Testnets and local nodes. Off in a release: without this they are not
# compiled in at all, so a production binary cannot offer a chain nobody trades.
testnet = []
# Providing liquidity: the `a` and `r` keys, and the position-closing half of
# the sweep. OFF for the first release.
#
# Not because it does not work — because it is a different kind of risk from
# buying and selling a token, and the first release is being scoped to what an
# audit can cover properly. Minting a concentrated position commits funds to a
# range and can be exited at a worse price than it entered; that deserves its
# own review rather than riding in on the back of a swap audit.
#
# It comes back after 1.0, with launching, as one bundle. Until then this
# feature keeps the code compiled and testable while keeping it out of the
# binary people actually trade with — a reviewer should not have to work out
# whether a path is reachable.
liquidity = []
# Coin artwork that is not already a PNG — JPEG, WebP, GIF — decoded and
# re-encoded so the terminal still receives a PNG. OFF for the first release.
#
# Most pump art is JPEG or WebP, so this is the difference between showing a
# third of it and showing nearly all of it. It is off anyway because it means
# decoding bytes a coin's CREATOR chose, inside the process holding the keys.
# In Rust that is a denial-of-service surface rather than a memory-safety one
# — a panic, or a file whose pixel dimensions dwarf its download size — and
# `art::to_png` bounds both before allocating. Off until an audit has looked
# at it: what ships is what was reviewed.
art-formats = ["dep:image"]
# Solana/pump.fun support is OFF by default: the solana crate tree is heavy and
# would slow the EVM-only `cargo build --release` cycle. Build with
# `cargo build --release --features solana` when working on that side.
default = []
solana = [
"dep:solana-pubkey",
"dep:solana-keypair",
"dep:solana-signer",
"dep:solana-instruction",
"dep:solana-message",
"dep:solana-transaction",
"dep:solana-hash",
"dep:solana-system-interface",
"dep:borsh",
"dep:bincode",
"dep:eth-keystore",
]
[dependencies]
# `json-rpc` + `rpc-client` expose the packet/client types the balanced
# transport (src/rpc.rs) is built from; they are already compiled as part of
# the provider stack, the features only un-gate the re-exports.
alloy = { version = "0.8", features = ["full", "node-bindings", "signer-keystore", "signer-mnemonic", "json-rpc", "rpc-client"] }
tokio = { version = "1", features = ["full"] }
# `unstable-rendered-line-info` exposes Paragraph::line_count — the docs
# reader needs the REAL number of laid-out rows to bound its scroll, and only
# the widget's own word-wrapper knows it. "Unstable" means the API may change
# between ratatui versions; the version is pinned, so that's a non-event.
ratatui = { version = "0.29", features = ["unstable-rendered-line-info"] }
crossterm = { version = "0.28", features = ["event-stream"] }
futures = "0.3"
eyre = "0.6"
serde = { version = "1", features = ["derive"] }
serde_json = "1"
reqwest = { version = "0.12", default-features = false, features = ["json", "rustls-tls"] }
# Already in the tree via alloy's transports. Named directly because the
# balanced RPC transport (src/rpc.rs) implements tower::Service so alloy will
# accept it as a drop-in transport.
tower = "0.5"
# Already in the tree via alloy — reused for Solana key derivation (BIP39 seed +
# SLIP-0010 ed25519) and base58, so they cost no extra build time.
bs58 = "0.5"
# Markdown for the in-app docs viewer. Same parser steer's TUI uses; it emits a
# plain event stream, which maps straight onto themed ratatui spans.
pulldown-cmark = { version = "0.9", default-features = false }
coins-bip39 = "0.12"
hmac = "0.12"
sha2 = "0.10"
# Theme engine. `default-features = false` deliberately drops opaline's own
# `ratatui` feature: it pulls ratatui-core 0.1 for ratatui 0.30, and this bot is
# on 0.29. We only need the token tables and map OpalineColor -> Color::Rgb
# ourselves, which is a 3-field struct copy.
# From crates.io, not a path. A path pointing outside the repository builds
# only on a machine that happens to have a sibling checkout — CI has no such
# sibling, and neither does anyone cloning the source, which is now everyone.
opaline = { version = "0.4.1", default-features = false, features = ["builtin-themes"] }
# --- solana (optional, behind the `solana` feature) ---
# Targeted crates rather than the `solana-sdk` umbrella: we only need keys,
# PDAs, instruction/message/transaction building. RPC goes over the `reqwest`
# JSON-RPC client we already use for EVM batch calls.
# `serde` so seen coins and per-coin tape history survive a restart — a
# pasted mint and its trades used to die with the process.
solana-pubkey = { version = "3", features = ["borsh", "curve25519", "serde"], optional = true }
solana-keypair = { version = "3", optional = true }
solana-signer = { version = "3", optional = true }
solana-instruction = { version = "3", optional = true }
solana-message = { version = "3", optional = true }
# `bincode` feature pulls in signing (new_signed_with_payer) + the wire format.
solana-transaction = { version = "3", features = ["bincode"], optional = true }
solana-hash = { version = "3", optional = true }
solana-system-interface = { version = "2", optional = true }
borsh = { version = "1.5", features = ["derive"], optional = true }
# Solana's transaction wire format. Pinned to 1.x — that's what solana-transaction
# itself uses, and 2.x is a different, incompatible API.
bincode = { version = "1.3", optional = true }
# Web3 Secret Storage (scrypt + AES-128-CTR + MAC). Solana's own CLI keeps keys
# in PLAINTEXT json, so we reuse the encrypted format the EVM side already uses
# — one password protects both chains. Both crates are already in the tree via
# alloy, so they add no build time.
eth-keystore = { version = "0.5", optional = true }
rand = "0.8"
# Only the formats coin art actually arrives in, and only behind
# `art-formats`. default-features=false keeps the rest of the decoders — and
# their surface — out of the binary entirely.
image = { version = "0.25", default-features = false, features = ["jpeg", "webp", "gif", "png"], optional = true }
# WebSocket, for pump.fun logsSubscribe (launches are far too rare in the
# signature stream to discover by polling). Already present via alloy-transport-ws.
# Both chains need it now: Solana's log stream and, since discovery moved
# off polling, the EVM launch subscription. No longer optional.
tokio-tungstenite = { version = "0.24", features = ["rustls-tls-webpki-roots"] }
zeroize = "1.9.0"
minisign-verify = "0.2"
[profile.release]
opt-level = 3
lto = true