fork of radicle with Git LFS support, backed by IPFS
Go to file
Fintan Halpenny 5b6ae0ac4a Update radicle-surf to 0.27.1
This version resolves the vulnerability from the `tar-rs` transitive
dependency.

`cargo deny check` output:
```
error[vulnerability]: tar-rs incorrectly ignores PAX size headers if header size is nonzero
    ┌─ /home/fintohaps/Developer/heartwood/Cargo.lock:362:1
    │
362 │ tar 0.4.44 registry+https://github.com/rust-lang/crates.io-index
    │ ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━ security vulnerability detected
    │
    ├ ID: RUSTSEC-2026-0068
    ├ Advisory: https://rustsec.org/advisories/RUSTSEC-2026-0068
    ├ Versions 0.4.44 and below of tar-rs have conditional logic that skips the PAX
      size header in cases where the base header size is nonzero.
      
      As part of [CVE-2025-62518][astral-cve], the [astral-tokio-tar]
      project was changed to correctly honor PAX size headers in the case where it
      was different from the base header. This is almost the inverse of the
      astral-tokio-tar issue.
      
      Any discrepancy in how tar parsers honor file size can be used to create
      archives that appear differently when unpacked by different archivers. In this
      case, the tar-rs (Rust tar) crate is an outlier in checking for the header size
      — other tar parsers (including e.g. Go [`archive/tar`][go-tar]) unconditionally
      use the PAX size override. This can affect anything that uses the tar crate to
      parse archives and expects to have a consistent view with other parsers.
      
      This issue has been fixed in version 0.4.45.
      
      [astral-cve]: https://www.cve.org/CVERecord?id=CVE-2025-62518
      [astral-tokio-tar]: https://github.com/astral-sh/tokio-tar
      [go-tar]: https://pkg.go.dev/archive/tar
    ├ Solution: Upgrade to >=0.4.45 (try `cargo update -p tar`)
    ├ tar v0.4.44
      └── (build) radicle-surf v0.27.0
          └── radicle-cli v0.19.0
              └── radicle-remote-helper v0.15.0
```
2026-04-02 14:46:41 +01:00
.cargo fetch: upgrade gix crates 2024-05-17 13:27:18 +02:00
.config nix: switch to use nix flakes 2023-12-13 12:25:12 +01:00
.github windows: Add installer build 2026-02-16 08:33:58 +00:00
.radicle ci: Activate all features when building docs 2025-11-03 11:30:43 +01:00
build build: Pin Zig to 0.13.0 2026-02-19 21:02:22 +01:00
crates protocol: Use pastey fork 2026-04-02 14:46:41 +01:00
debian chore(debian/changelog): update package version to match upstream 2025-07-23 11:34:20 +02:00
scripts cli/self: Stop printing information about the node 2025-09-04 17:12:19 +03:00
systemd systemd: remove redundant lines from system unit 2026-02-10 11:06:05 +00:00
windows windows: Add installer build 2026-02-16 08:33:58 +00:00
.codespellrc hooks: Enable typos, fix reported errors 2026-02-17 11:35:28 +00:00
.dockerignore build: Add "upload" build step 2024-04-29 10:47:03 +02:00
.env.seed seed: Update default tracking policy for seed 2023-04-17 21:16:56 +02:00
.envrc chore: use watch_file in .envrc 2025-05-15 14:54:13 +02:00
.git-blame-ignore-revs git: Ignore parent from blame 2025-10-17 13:00:20 +02:00
.gitignore repo: Move workspace crates into `crates` subdirectory 2025-06-09 15:09:21 +02:00
.gitsigners Add Lorenz Leutgeb to `.gitsigners` 2025-04-17 14:33:36 +02:00
.rustfmt.toml rust/edition/fmt: 2021 → 2024 2026-03-30 16:57:51 +02:00
.typos.toml hooks: Enable typos, fix reported errors 2026-02-17 11:35:28 +00:00
ARCHITECTURE.md docs: link to protocol guide 2024-04-03 15:32:26 +02:00
CHANGELOG.md cli/patch: Show Commit Ranges of Revisions 2026-04-02 14:08:44 +01:00
CONTRIBUTING.md doc: Mention handling of "radicle.xyz" 2025-09-04 16:44:05 +03:00
Cargo.lock Update radicle-surf to 0.27.1 2026-04-02 14:46:41 +01:00
Cargo.toml Update radicle-surf to 0.27.1 2026-04-02 14:46:41 +01:00
DCO Add licenses and contributor information 2022-11-16 12:26:12 +01:00
HACKING.md docs: Add a note on running isolated nodes 2024-09-12 17:56:21 +02:00
LICENSE-APACHE Add licenses and contributor information 2022-11-16 12:26:12 +01:00
LICENSE-MIT Add licenses and contributor information 2022-11-16 12:26:12 +01:00
README.md docs: fix installation instructions in README.md 2025-07-20 15:33:12 +00:00
RELEASE.md RELEASE: start at rc.1 2026-02-13 13:34:11 +01:00
VERSIONING.md build: Add "upload" build step 2024-04-29 10:47:03 +02:00
build.rs hooks: Enable typos, fix reported errors 2026-02-17 11:35:28 +00:00
deny.toml cargo(deny): allow Zlib 2025-12-08 16:43:50 +00:00
flake.lock nix: update to 25.11 2026-02-18 09:50:16 +00:00
flake.nix nix: update to 25.11 2026-02-18 09:50:16 +00:00
git-remote-rad.1.adoc Add rudimentary Debian packaging for binaries 2023-11-01 12:56:35 +01:00
rad-id.1.adoc cli: test canonical tags 2025-07-16 16:54:43 +02:00
rad-patch.1.adoc chore: Fix spelling errors with codespell 2025-11-01 12:11:02 +01:00
rad.1.adoc chore: Fix spelling errors with codespell 2025-11-01 12:11:02 +01:00
radicle-node.1.adoc docs: Update manual pages to 1.0.0 2024-04-22 14:37:19 +02:00
rust-toolchain.toml workspace/rust: 1.88 → 1.90 2025-10-17 12:56:43 +02:00

README.md

❤️🪵

Radicle Heartwood Protocol & Stack

Heartwood is the third iteration of the Radicle Protocol, a powerful peer-to-peer code collaboration and publishing stack. The repository contains a full implementation of Heartwood, complete with a user-friendly command-line interface (rad) and network daemon (radicle-node).

Radicle was designed to be a secure, decentralized and powerful alternative to code forges such as GitHub and GitLab that preserves user sovereignty and freedom.

See the Radicle home page for general information, and the Zulip chat to talk to the project.

See the Protocol Guide for an in-depth description of how Radicle works.

Installation

Requirements

  • Linux or Unix based operating system.
  • Git 2.34 or later
  • OpenSSH 9.1 or later with ssh-agent

📀 From binaries

Requires curl and tar.

Run the following command to install the latest binary release:

curl -sSf https://radicle.xyz/install | sh

Or visit our download page.

📦 From source

Requires the Rust toolchain.

You can install the Radicle stack from source, by running the following commands from inside this repository:

cargo install --path crates/radicle-cli --force --locked --root ~/.radicle
cargo install --path crates/radicle-node --force --locked --root ~/.radicle
cargo install --path crates/radicle-remote-helper --force --locked --root ~/.radicle

Or directly from our seed node:

cargo install --force --locked --root ~/.radicle \
    --git https://seed.radicle.xyz/z3gqcJUoA1n9HaHKufZs5FCSGazv5.git \
    crates/radicle-cli crates/radicle-node crates/radicle-remote-helper

Running

Systemd unit files are provided for the node under the /systemd folder. They can be used as a starting point for further customization.

For running in debug mode, see HACKING.md.

Feedback

If you have feedback, feel free to create issues using rad issue, join our Zulip, or email feedback@radicle.xyz. Emails sent to this address are automatically posted to our public #feedback channel on Zulip, revealing the From header (which usually contains your name and email address). This allows us to discuss your feedback on Zulip, and, if necessary, respond to you via email.

Contributing

See CONTRIBUTING.md and HACKING.md for an introduction to contributing to Radicle.

License

Radicle is distributed under the terms of both the MIT license and the Apache License (Version 2.0).

See LICENSE-APACHE and LICENSE-MIT for details.