librewolf-bin: mark with knownVulnerabilities due to lack of maintenance in nixpkgs

This security-critical package is currently not maintained well enough
to be kept as is.
We are currently providing a 4 months old version which is not
acceptable for a browser. PR #464467 created by r-ryantm 3 weeks ago was
not handled by anyone.

See also #416711 for previous discussions.

(cherry picked from commit 1c009d547d)
This commit is contained in:
Thomas Gerbet
2025-12-18 11:35:11 +01:00
committed by github-actions[bot]
parent 4080cb7510
commit 74a058bfd7

View File

@@ -113,5 +113,8 @@ stdenv.mkDerivation {
mainProgram = "librewolf";
hydraPlatforms = [ ];
sourceProvenance = with lib.sourceTypes; [ binaryNativeCode ];
knownVulnerabilities = [
"librewolf-bin lacks maintenance in nixpkgs, consider using an alternative"
];
};
}