mirror of
https://github.com/NixOS/nixpkgs.git
synced 2026-09-30 03:39:59 +00:00
radicle-node: mark insecure
Following their disclosure, we should mark all seeding radicle packages
as insecure.
This can only be potentially lifted on the next major (breaking)
release, as per the disclosure.
(cherry picked from commit c082683d1c)
This commit is contained in:
committed by
github-actions[bot]
parent
23361ad810
commit
dffc539de1
@@ -173,5 +173,9 @@ rustPlatform.buildRustPackage (finalAttrs: {
|
||||
platforms = lib.platforms.unix;
|
||||
teams = [ lib.teams.radicle ];
|
||||
mainProgram = "rad";
|
||||
knownVulnerabilities = [
|
||||
# https://radicle.dev/2026/09/23/disclosure-of-vulnerability-in-network-protocol
|
||||
"Private repositories are insecure: traffic between nodes is not encrypted and not authenticated."
|
||||
];
|
||||
};
|
||||
})
|
||||
|
||||
Reference in New Issue
Block a user