radicle-node: mark insecure

Following their disclosure, we should mark all seeding radicle packages
as insecure.

This can only be potentially lifted on the next major (breaking)
release, as per the disclosure.

(cherry picked from commit c082683d1c)
This commit is contained in:
Alexander Foremny
2026-09-24 10:53:00 +02:00
committed by github-actions[bot]
parent 23361ad810
commit dffc539de1

View File

@@ -173,5 +173,9 @@ rustPlatform.buildRustPackage (finalAttrs: {
platforms = lib.platforms.unix;
teams = [ lib.teams.radicle ];
mainProgram = "rad";
knownVulnerabilities = [
# https://radicle.dev/2026/09/23/disclosure-of-vulnerability-in-network-protocol
"Private repositories are insecure: traffic between nodes is not encrypted and not authenticated."
];
};
})